Security and trust
Who runs IBANforge, where the API runs, what it keeps and for how long, and what we do not have. Each fact links to the document or the check that proves it.
Checked on October 6, 2026. The contractual documents prevail over this summary.
- Operator
- Sole proprietorship, Switzerland
- API region
- Amsterdam (EU)
- Submitted IBANs
- Not stored
- Notice before closing
- Six months, paying customers
Who runs IBANforge
IBANforge is a sole proprietorship under Swiss law, run by Claude-Alain Martin.
IBANforgeClaude-Alain Martin
Rue de l'Eglise 23
1045 Ogens
Switzerland
- Not entered in the commercial register: a Swiss sole proprietorship must register only from CHF 100,000 of annual turnover (art. 931 of the Swiss Code of Obligations).
- Not registered for Swiss VAT.
- One person builds and runs the service. There are no employees.
- Contact: support@ibanforge.com
Where it runs
Each line can be checked from outside, with the command next to it.
API
Railway, Amsterdam region (Netherlands, EU). Swiss traffic enters through Railway's network edge in Zurich.
Check
curl -sI https://api.ibanforge.com/health | grep -i x-railway-edgeThe x-railway-edge header names the edge nearest to you (zrh1 from Switzerland). The Amsterdam region itself is not visible from outside.
Website and dashboard
Vercel. Its functions run in the Frankfurt region (Germany, EU); static pages are served from Vercel's global network.
Check
curl -sI https://ibanforge.com/legal/dpa | grep -i x-vercel-idIn the x-vercel-id header, the part after the first :: is the region where the function ran: fra1 is Frankfurt. The first part is the edge nearest to you.
E-mail, DNS and backups
Infomaniak, Switzerland. A server there also holds the nightly backups of the account state.
Check
dig +short NS ibanforge.comThe name servers are Infomaniak's.
What we keep, and for how long
- IBANs you submit for validation
- Not stored. Processed in memory to answer the request.
- An invalid IBAN
- Only its first 4 characters (country code and check digits), with the request metadata, up to 12 months.
- Request metadata: path, status, latency, time, user-agent, key prefix
- 12 months, then deleted automatically. The IP address is kept only as a salted hash.
- Edge log of our API host: raw IP address, request path, status, user-agent, time
- 7 days, kept and deleted by Railway, outside our own logs.
- A file uploaded to the file audit
- Only its annotated report: 2 hours if unpaid, 24 hours after payment.
- Your e-mail address, if you give one
- As long as your key exists. Deleted from the live record on request; backups that still hold it age out within 90 days.
- Backups of the account state: keys as hashes, e-mail addresses, quotas, credits, purchase records
- Every night to a server of Infomaniak in Switzerland, 30 days of copies; monthly copies on a computer of the operator in Switzerland, the last three kept. No IBAN submitted for validation, no request log. The restore is tested.
Send IBANs in the body of a POST request
POST /v1/iban/validate, /v1/iban/batch and /v1/iban/compliance take the IBAN in the JSON body. Never put an IBAN in a URL: the edge log of our host records the request path.
Sub-processors
Who processes data for us, where, and on what basis data leaves Switzerland and the EU. Data Privacy Framework entries checked on the official register on October 5, 2026.
Railway Corp.
API hosting and storage
- Region
- Amsterdam (EU)
- Receives submitted IBANs?
- Yes, in memory, to answer the request
- Transfer basis
- EU-US and Swiss-US Data Privacy Framework, active (Railway Corporation)
Vercel Inc.
Website and dashboard; playground submissions are relayed to the API
- Region
- Functions: Frankfurt (EU). Static pages: global network
- Receives submitted IBANs?
- Only an IBAN typed into the website's playground
- Transfer basis
- EU-US and Swiss-US Data Privacy Framework, active (Vercel Inc.)
Stripe Payments Europe
Card payments
- Region
- EU
- Receives submitted IBANs?
- No
- Transfer basis
- Established in the EU. Its US affiliate Stripe, LLC: EU-US and Swiss-US Data Privacy Framework, active
Coinbase (CDP facilitator)
USDC settlement of x402 payments; the x402.org facilitator is the fallback
- Region
- US
- Receives submitted IBANs?
- No
- Transfer basis
- EU-US and Swiss-US Data Privacy Framework, active (Coinbase, Inc.)
Infomaniak Network SA
Transactional and support e-mail; nightly backup of the account state
- Region
- Switzerland
- Receives submitted IBANs?
- Only an IBAN you write in an e-mail to us
- Transfer basis
- Switzerland: adequacy decision of the European Commission
GitHub Inc.
Public source code and CI, no customer data
- Region
- US
- Receives submitted IBANs?
- No
- Transfer basis
- EU-US and Swiss-US Data Privacy Framework, active (GitHub)
Anthropic PBC
AI-assisted drafting of replies to e-mails, started by the operator
- Region
- US
- Receives submitted IBANs?
- The API never sends it one; only an IBAN you write in an e-mail to us
- Transfer basis
- Not certified under the Data Privacy Framework. Standard contractual clauses of Anthropic's Data Processing Addendum
| Sub-processor | Role | Region | Receives submitted IBANs? | Transfer basis |
|---|---|---|---|---|
| Railway Corp. | API hosting and storage | Amsterdam (EU) | Yes, in memory, to answer the request | EU-US and Swiss-US Data Privacy Framework, active (Railway Corporation)Register entry |
| Vercel Inc. | Website and dashboard; playground submissions are relayed to the API | Functions: Frankfurt (EU). Static pages: global network | Only an IBAN typed into the website's playground | EU-US and Swiss-US Data Privacy Framework, active (Vercel Inc.)Register entry |
| Stripe Payments Europe | Card payments | EU | No | Established in the EU. Its US affiliate Stripe, LLC: EU-US and Swiss-US Data Privacy Framework, activeRegister entry |
| Coinbase (CDP facilitator) | USDC settlement of x402 payments; the x402.org facilitator is the fallback | US | No | EU-US and Swiss-US Data Privacy Framework, active (Coinbase, Inc.)Register entry |
| Infomaniak Network SA | Transactional and support e-mail; nightly backup of the account state | Switzerland | Only an IBAN you write in an e-mail to us | Switzerland: adequacy decision of the European CommissionDocument |
| GitHub Inc. | Public source code and CI, no customer data | US | No | EU-US and Swiss-US Data Privacy Framework, active (GitHub)Register entry |
| Anthropic PBC | AI-assisted drafting of replies to e-mails, started by the operator | US | The API never sends it one; only an IBAN you write in an e-mail to us | Not certified under the Data Privacy Framework. Standard contractual clauses of Anthropic's Data Processing AddendumDocument |
A new sub-processor is announced at least 30 days before it receives personal data, by e-mail to the address of each active key and in the changelog; under the DPA you may object.
The same list, with the same bases, is Annex II of the data processing agreement. DPA
Transfers from the EU
IBANforge is established in Switzerland. The European Commission recognises Switzerland as providing an adequate level of protection (Decision 2000/518/EC) and confirmed it in its review of 15 January 2024: personal data can be transferred from the EU to us without standard contractual clauses.
For US sub-processors certified under them, transfers rely on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) and, from Switzerland, on the Swiss-US Data Privacy Framework, in force since 15 September 2024.
Security
Every pull request runs the automated tests in GitHub Actions (API, website, SDKs) and boots the production container, and so does every change the operator pushes to the main branch. The automated data refreshes publish without that suite and run their own checks first: the BIC, Czech and Italian refreshes run the API tests and compare the new data with the previous data; the weekly compliance refresh checks that the coverage the API announces matches the new lists.
CI runsThe code is public, under the MIT licence: anyone can read how an IBAN is handled.
Source codeAPI keys are stored as SHA-256 hashes. A newly issued key is also held once for retrieval, then erased on first retrieval or after 7 days at the latest.
All traffic is encrypted. Current clients negotiate TLS 1.3, plain HTTP is redirected to HTTPS, and both hosts send HSTS.
To report a vulnerability, write to support@ibanforge.com with SECURITY in the subject. The same channel is in the security.txt file of both hosts (RFC 9116) and in our security policy.
Dependabot watches the dependencies and opens security updates as public pull requests.
Availability, said plainly
The status page publishes the API's success rate over 7 and 30 days, computed from our server-side request log.
Status pageEditor/OEM subscriptions carry a written SLA: 99.5% availability per calendar month, with service credits.
SLAAn external probe, on a server at Infomaniak in Switzerland, calls the API and the website every minute and alerts the operator. Its results are not published.
The API runs as a single instance with a persistent volume, in one region. Each update, including the automatic data refreshes, restarts it, and requests that arrive during the switch wait or fail. Railway documents this for any service with a volume; we have observed switches lasting from under a minute to almost five minutes. The status page cannot count those requests, because they never reach the API.
Railway documentationWhere the data comes from
Where a national register is consulted, the answer comes from it and names it, with its date: the Deutsche Bundesbank for Germany, SIX BankMaster for Switzerland and Liechtenstein, the national banks of Austria, Belgium, the Czech Republic and Slovakia, among others. Elsewhere a composite BIC map answers, and the response says it is not authoritative.
Where a publisher sets conditions, they are honoured in the response itself; the publishers who gave us written permission are listed on the sources page.
About two thirds of our BIC directory rows come from a public copy of the SWIFT directory whose data dates from January 2018 and is no longer updated. We say so on the sources page and in the API's health endpoint; where a national register answers, it takes precedence.
If IBANforge stopped
Every paying customer (Pro subscribers, holders of credit packs, Editor/OEM customers) is told at least six months before the service stops, by e-mail and in the Terms, and no renewal is charged for the month in which it stops. For a free key, the notice before we end it is at least 30 days.
Terms of Service, §3 and §9The code is published under the MIT licence, and the validation core is a separate MIT package on npm (ibanforge).
The API's code can run on your own servers. The data files of the repository keep their publishers' terms (NOTICE file), and the data we may serve but not redistribute, such as the Austrian, Belgian and San Marino registers, is not in the repository: a copy run elsewhere answers "not consulted" for it.
NOTICE fileWhat we do not have
- No ISO 27001 or SOC 2 certification.
- No team: one person builds and runs the service.
- No second region and no standby instance (see Availability).
The measures on this page are what we do instead, and each one can be checked.
The documents
The DPA is pre-signed; a countersigned PDF is available on request at support@ibanforge.com. It provides for audits, including an inspection, once per calendar year at most and on 30 days' notice, where the documents are not sufficient.