VERIFIED CONTROLS

Security at WebGo API

This page describes security controls that are implemented in the current WebGo API platform. We do not claim certifications, audits or security programs that have not been independently completed and verified.

✓ Password protection

Account passwords are derived with PBKDF2 using SHA-256, a per-password salt and 100,000 iterations. WebGo does not store the original password for authentication.

✓ API key protection

New API keys are shown in full at creation. Authentication uses a SHA-256 hash of the secret; later account views expose only a partial identifier. Keys can be revoked.

✓ Protected sessions

Web sessions use random tokens whose hashes are stored server-side. Session cookies are marked HttpOnly, Secure and SameSite=Lax and can be invalidated at logout.

✓ Payment separation

Stripe handles card checkout. WebGo verifies signed Stripe webhooks and validates paid amount and currency before activating credits. WebGo stores only limited payment metadata when available, such as brand and last four digits—not full card numbers or CVC.

✓ Phone verification

Supported registration and verification flows use Twilio Verify. Provider credentials remain server-side and are not exposed to the browser.

✓ Usage protection

Credit reservations, hard usage limits, settlement controls and authenticated API access help prevent unauthorized or uncontrolled API consumption. Failed delivery is designed to settle at zero delivered-result credits.

✓ Encrypted transport

Public WebGo API and Customer Center traffic is served over HTTPS. Customers should keep passwords and API keys private, rotate or revoke exposed credentials, and never place secret API keys in public client-side code or repositories.

Security is an ongoing process

No internet service can guarantee absolute security. Features and controls may evolve as WebGo API develops. This page does not represent WebGo API as SOC 2, ISO 27001, PCI DSS certified, independently penetration-tested or covered by a public bug bounty unless WebGo later publishes verified evidence of that status.