Security and data handling

Protect Roots credentials and end-customer data in your integration.

Protect Roots credentials and end-customer data throughout your integration.

See API availability for the published production security contract.

Protect credentials

Store API-key secrets and user credentials in a secret manager. Restrict access to the service or person that needs the secret.

Use separate credentials for each environment and application. Rotate a credential by deploying a replacement before you revoke the active credential.

Do not place secrets in source code, browser applications, support tickets, chat messages, or application logs.

Protect customer data

Roots integrations can process personal, business, payment, and compliance information. Collect only the data required for the workflow you are performing.

Use access controls so only authorized people and services can view sensitive data. Redact sensitive data from logs, monitoring tools, and error reports.

At a minimum, do not log:

  • Passwords or API-key secrets.
  • Full bank-account numbers.
  • Identity documents or document contents.
  • Sensitive personal information unless your secure audit process requires it.

Use secure transport

Use HTTPS for calls to the Roots UAT API:

https://api.uat.roots.finance

Validate certificates with your standard HTTP client behavior. Do not disable TLS certificate validation.

Prepare incident handling

If you suspect that a credential is exposed:

  1. Deploy a replacement credential.
  2. Revoke the exposed API key.
  3. Review access and application logs for unexpected use.
  4. Record the incident according to your security process.
  5. Contact Roots through your approved support channel when the exposure can affect an active integration.

Target schema — confirm in API reference

Roots has not published public commitments for data residency, retention, deletion, encryption details, audit-log export, or production security controls. Confirm these requirements with Roots before you process production personal or payment data.

Next steps


Did this page help you?