Developer Policy

All developers integrating with the INFRA API must read and comply with this policy. Violations may result in immediate suspension of access.

Important Notice: By integrating with this API, you agree to comply with all data access, consent, and security requirements defined below. Failure to comply may result in immediate suspension of access, revocation of credentials, and removal from the platform.

Consent is mandatory for all data access. Applications must not access user data without active consent, attempt to bypass consent flows, or cache and reuse expired consent tokens.

On consent revocation:

  • All access must stop immediately
  • Tokens must be treated as invalid
  • No further API requests should be made on behalf of the user

2. Data Usage Restrictions#

Applications must only use data for the purpose explicitly approved by the user.

Applications must not:

  • Resell user data
  • Share data with third parties without consent
  • Use data for profiling beyond approved scope
  • Store data longer than necessary

3. Data Storage Policy#

Storage of raw identity documents is strongly restricted. Applications should prefer verification status over raw documents and minimize stored personal data.

For sensitive data:

  • Access requires explicit approval and trusted developer status
  • Storage must follow secure handling practices

4. Revocation Handling (CRITICAL)#

Upon receiving a consent_revoked event, applications must:

  • Immediately stop processing user data
  • Disable user-specific features relying on that data
  • Treat previously obtained data as non-current

Applications may retain data only if required for legal or operational purposes and it is no longer actively processed.

5. Account Deletion Enforcement#

Upon receiving a user_deleted event, applications must:

  • Permanently delete all user-related data
  • Remove all stored identity information
  • Confirm deletion where applicable

This action is mandatory and non-optional.

6. Token and Security Rules#

Applications must:

  • Securely store API keys and tokens
  • Never expose credentials client-side
  • Implement server-side verification

Applications must not:

  • Hardcode secrets in public code
  • Transmit tokens over insecure channels
  • Reuse expired tokens

7. Webhook Compliance#

Applications must:

  • Verify webhook signatures
  • Process webhook events reliably
  • Handle retries and idempotency

Ignoring these events is non-compliance:

  • consent_revoked
  • user_deleted

8. Abuse and Misuse#

The following behaviors are strictly prohibited:

  • Excessive or automated consent requests
  • Scraping or bulk data extraction
  • Attempting to infer data beyond granted scope
  • Simulating user actions

9. Trusted Developer Requirements#

Access to sensitive claims is restricted. Applications must undergo review before accessing sensitive data, justify data usage, and maintain compliance standards. Approval may be revoked at any time.

10. Rate Limiting and Access Control#

Applications must respect rate limits. Excessive requests may result in:

  • Temporary throttling
  • API suspension
  • Permanent access removal

11. Compliance and Enforcement#

We reserve the right to audit application behavior, monitor usage patterns, and suspend or revoke access without prior notice.

12. Data Validity Disclaimer (IMPORTANT)#

Access to data does not imply permanent validity. Applications must:

  • Revalidate data where required
  • Respect expiration timestamps
  • Not rely on stale or outdated information

This page as Markdown: /developer-policy.md · All docs in one file: /llms-full.txt