Skip to content
IBANforge
For your data-protection review

Security and trust

Who runs IBANforge, where the API runs, what it keeps and for how long, and what we do not have. Each fact links to the document or the check that proves it.

Checked on October 6, 2026. The contractual documents prevail over this summary.

Operator
Sole proprietorship, Switzerland
API region
Amsterdam (EU)
Submitted IBANs
Not stored
Notice before closing
Six months, paying customers

Who runs IBANforge

IBANforge is a sole proprietorship under Swiss law, run by Claude-Alain Martin.

IBANforge
Claude-Alain Martin
Rue de l'Eglise 23

1045 Ogens

Switzerland
  • Not entered in the commercial register: a Swiss sole proprietorship must register only from CHF 100,000 of annual turnover (art. 931 of the Swiss Code of Obligations).
  • Not registered for Swiss VAT.
  • One person builds and runs the service. There are no employees.
  • Contact: support@ibanforge.com
Legal Notice

Where it runs

Each line can be checked from outside, with the command next to it.

API

Railway, Amsterdam region (Netherlands, EU). Swiss traffic enters through Railway's network edge in Zurich.

Check

curl -sI https://api.ibanforge.com/health | grep -i x-railway-edge

The x-railway-edge header names the edge nearest to you (zrh1 from Switzerland). The Amsterdam region itself is not visible from outside.

Website and dashboard

Vercel. Its functions run in the Frankfurt region (Germany, EU); static pages are served from Vercel's global network.

Check

curl -sI https://ibanforge.com/legal/dpa | grep -i x-vercel-id

In the x-vercel-id header, the part after the first :: is the region where the function ran: fra1 is Frankfurt. The first part is the edge nearest to you.

E-mail, DNS and backups

Infomaniak, Switzerland. A server there also holds the nightly backups of the account state.

Check

dig +short NS ibanforge.com

The name servers are Infomaniak's.

What we keep, and for how long

IBANs you submit for validation
Not stored. Processed in memory to answer the request.
An invalid IBAN
Only its first 4 characters (country code and check digits), with the request metadata, up to 12 months.
Request metadata: path, status, latency, time, user-agent, key prefix
12 months, then deleted automatically. The IP address is kept only as a salted hash.
Edge log of our API host: raw IP address, request path, status, user-agent, time
7 days, kept and deleted by Railway, outside our own logs.
A file uploaded to the file audit
Only its annotated report: 2 hours if unpaid, 24 hours after payment.
Your e-mail address, if you give one
As long as your key exists. Deleted from the live record on request; backups that still hold it age out within 90 days.
Backups of the account state: keys as hashes, e-mail addresses, quotas, credits, purchase records
Every night to a server of Infomaniak in Switzerland, 30 days of copies; monthly copies on a computer of the operator in Switzerland, the last three kept. No IBAN submitted for validation, no request log. The restore is tested.

Send IBANs in the body of a POST request

POST /v1/iban/validate, /v1/iban/batch and /v1/iban/compliance take the IBAN in the JSON body. Never put an IBAN in a URL: the edge log of our host records the request path.

Privacy Policy

Sub-processors

Who processes data for us, where, and on what basis data leaves Switzerland and the EU. Data Privacy Framework entries checked on the official register on October 5, 2026.

Railway Corp.

API hosting and storage

Region
Amsterdam (EU)
Receives submitted IBANs?
Yes, in memory, to answer the request
Transfer basis
EU-US and Swiss-US Data Privacy Framework, active (Railway Corporation)

Vercel Inc.

Website and dashboard; playground submissions are relayed to the API

Region
Functions: Frankfurt (EU). Static pages: global network
Receives submitted IBANs?
Only an IBAN typed into the website's playground
Transfer basis
EU-US and Swiss-US Data Privacy Framework, active (Vercel Inc.)

Stripe Payments Europe

Card payments

Region
EU
Receives submitted IBANs?
No
Transfer basis
Established in the EU. Its US affiliate Stripe, LLC: EU-US and Swiss-US Data Privacy Framework, active

Coinbase (CDP facilitator)

USDC settlement of x402 payments; the x402.org facilitator is the fallback

Region
US
Receives submitted IBANs?
No
Transfer basis
EU-US and Swiss-US Data Privacy Framework, active (Coinbase, Inc.)

Infomaniak Network SA

Transactional and support e-mail; nightly backup of the account state

Region
Switzerland
Receives submitted IBANs?
Only an IBAN you write in an e-mail to us
Transfer basis
Switzerland: adequacy decision of the European Commission

GitHub Inc.

Public source code and CI, no customer data

Region
US
Receives submitted IBANs?
No
Transfer basis
EU-US and Swiss-US Data Privacy Framework, active (GitHub)

Anthropic PBC

AI-assisted drafting of replies to e-mails, started by the operator

Region
US
Receives submitted IBANs?
The API never sends it one; only an IBAN you write in an e-mail to us
Transfer basis
Not certified under the Data Privacy Framework. Standard contractual clauses of Anthropic's Data Processing Addendum

A new sub-processor is announced at least 30 days before it receives personal data, by e-mail to the address of each active key and in the changelog; under the DPA you may object.

The same list, with the same bases, is Annex II of the data processing agreement. DPA

Transfers from the EU

IBANforge is established in Switzerland. The European Commission recognises Switzerland as providing an adequate level of protection (Decision 2000/518/EC) and confirmed it in its review of 15 January 2024: personal data can be transferred from the EU to us without standard contractual clauses.

For US sub-processors certified under them, transfers rely on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) and, from Switzerland, on the Swiss-US Data Privacy Framework, in force since 15 September 2024.

Security

Every pull request runs the automated tests in GitHub Actions (API, website, SDKs) and boots the production container, and so does every change the operator pushes to the main branch. The automated data refreshes publish without that suite and run their own checks first: the BIC, Czech and Italian refreshes run the API tests and compare the new data with the previous data; the weekly compliance refresh checks that the coverage the API announces matches the new lists.

CI runs

The code is public, under the MIT licence: anyone can read how an IBAN is handled.

Source code

API keys are stored as SHA-256 hashes. A newly issued key is also held once for retrieval, then erased on first retrieval or after 7 days at the latest.

All traffic is encrypted. Current clients negotiate TLS 1.3, plain HTTP is redirected to HTTPS, and both hosts send HSTS.

To report a vulnerability, write to support@ibanforge.com with SECURITY in the subject. The same channel is in the security.txt file of both hosts (RFC 9116) and in our security policy.

Dependabot watches the dependencies and opens security updates as public pull requests.

Availability, said plainly

The status page publishes the API's success rate over 7 and 30 days, computed from our server-side request log.

Status page

Editor/OEM subscriptions carry a written SLA: 99.5% availability per calendar month, with service credits.

SLA

An external probe, on a server at Infomaniak in Switzerland, calls the API and the website every minute and alerts the operator. Its results are not published.

The API runs as a single instance with a persistent volume, in one region. Each update, including the automatic data refreshes, restarts it, and requests that arrive during the switch wait or fail. Railway documents this for any service with a volume; we have observed switches lasting from under a minute to almost five minutes. The status page cannot count those requests, because they never reach the API.

Railway documentation

Where the data comes from

Where a national register is consulted, the answer comes from it and names it, with its date: the Deutsche Bundesbank for Germany, SIX BankMaster for Switzerland and Liechtenstein, the national banks of Austria, Belgium, the Czech Republic and Slovakia, among others. Elsewhere a composite BIC map answers, and the response says it is not authoritative.

Where a publisher sets conditions, they are honoured in the response itself; the publishers who gave us written permission are listed on the sources page.

About two thirds of our BIC directory rows come from a public copy of the SWIFT directory whose data dates from January 2018 and is no longer updated. We say so on the sources page and in the API's health endpoint; where a national register answers, it takes precedence.

If IBANforge stopped

Every paying customer (Pro subscribers, holders of credit packs, Editor/OEM customers) is told at least six months before the service stops, by e-mail and in the Terms, and no renewal is charged for the month in which it stops. For a free key, the notice before we end it is at least 30 days.

Terms of Service, §3 and §9

The code is published under the MIT licence, and the validation core is a separate MIT package on npm (ibanforge).

The API's code can run on your own servers. The data files of the repository keep their publishers' terms (NOTICE file), and the data we may serve but not redistribute, such as the Austrian, Belgian and San Marino registers, is not in the repository: a copy run elsewhere answers "not consulted" for it.

NOTICE file

What we do not have

  • No ISO 27001 or SOC 2 certification.
  • No team: one person builds and runs the service.
  • No second region and no standby instance (see Availability).

The measures on this page are what we do instead, and each one can be checked.

The documents

The DPA is pre-signed; a countersigned PDF is available on request at support@ibanforge.com. It provides for audits, including an inspection, once per calendar year at most and on 30 days' notice, where the documents are not sufficient.