API TO AGENTS · NEOVAL GMBH
Designed around clear boundaries.
API to Agents separates untrusted documentation, automated analysis, deterministic commercial rules, and verified payment. This overview describes the Phase 1 design and does not claim an independent certification.
No customer credentials in the audit
The free assessment does not request API keys, passwords, OAuth client secrets, database credentials, or real customer data. Documentation is treated as untrusted input. Supported uploads are size-limited, parsed locally, and screened for apparent secrets before analysis.
Safe document ingestion
Public URL ingestion validates DNS and public network addresses for every request and redirect. Requests connect only to a validated address, use HTTPS, and have strict time and size limits. Raw uploaded documentation is stored privately and is not exposed as a public download.
Verified access and payment
Email activation is required before audit access. Quotes come from deterministic versioned code. Only a signature-verified Stripe webhook can confirm payment. Dashboard links are single-use, expire quickly, and require a confirmation action so email scanners do not consume them.
Infrastructure and operations
Application services use Google Cloud/Firebase infrastructure in European regions, with separate runtime identities and restricted secrets. The audit worker requires authenticated task delivery. The browser has no direct Firestore access. We use retention controls, bounded provider requests, and operational monitoring.
Report a concern
Email contact@apitoagents.com with a description and safe reproduction steps. Do not include customer credentials or personal records.