API TO AGENTS · NEOVAL GMBH

Designed around clear boundaries.

API to Agents separates untrusted documentation, automated analysis, deterministic commercial rules, and verified payment. This overview describes the Phase 1 design and does not claim an independent certification.

No customer credentials in the audit

The free assessment does not request API keys, passwords, OAuth client secrets, database credentials, or real customer data. Documentation is treated as untrusted input. Supported uploads are size-limited, parsed locally, and screened for apparent secrets before analysis.

Safe document ingestion

Public URL ingestion validates DNS and public network addresses for every request and redirect. Requests connect only to a validated address, use HTTPS, and have strict time and size limits. Raw uploaded documentation is stored privately and is not exposed as a public download.

Verified access and payment

Email activation is required before audit access. Quotes come from deterministic versioned code. Only a signature-verified Stripe webhook can confirm payment. Dashboard links are single-use, expire quickly, and require a confirmation action so email scanners do not consume them.

Infrastructure and operations

Application services use Google Cloud/Firebase infrastructure in European regions, with separate runtime identities and restricted secrets. The audit worker requires authenticated task delivery. The browser has no direct Firestore access. We use retention controls, bounded provider requests, and operational monitoring.

Report a concern

Email contact@apitoagents.com with a description and safe reproduction steps. Do not include customer credentials or personal records.