Last updated: June 2026
Security & Trust
ibanchecker.cash processes sensitive financial identifiers. This page explains the architectural decisions we made to keep your data, and your usersβ data, safe.
Zero IBAN Retention
The checker and the free tools check IBANs in your browser, so they never reach us. API requests, including the playground on our API docs, are validated in memory at Cloudflare's edge and discarded with the response. No IBAN is ever written to our disks, databases or log files; the homepage keeps your last ten checks only in your own browser.
Edge-Only Processing
Every validation request is handled by Cloudflare Workers running at the nearest PoP, typically within 50ms. Data never travels to a centralised origin server.
Cloudflare Workers security model βAPI Key Security
API keys are randomly generated tokens. Authentication records store a SHA-256 hash of the key, not the key itself, in Cloudflare KV (encrypted at rest). Keys travel only over TLS, never appear in logs, and can be rotated or revoked instantly from the dashboard.
TLS 1.3 Everywhere
All connections to ibanchecker.cash are TLS 1.3 with HSTS. HTTP is permanently redirected to HTTPS.
Cloudflare DDoS & WAF
ibanchecker.cash is protected by Cloudflare's enterprise-grade DDoS mitigation and Web Application Firewall (WAF) across 300+ PoPs.
Cloudflare DDoS protection βCard Data Never Reaches Us
Card details are entered on a checkout page hosted by Polar, our merchant of record, which is built on Stripe. Stripe is a PCI DSS Level 1 certified processor. No raw card data ever passes through ibanchecker.cash.
Stripe security βWhat Data We Process vs. What We Never Touch
| Data | Status |
|---|---|
| IBAN strings submitted for validation | Never stored, discarded immediately after response |
| API outcome statistics (valid or which check failed, country code) | Kept three months in aggregate form, no IBAN, IP address or key |
| API keys | The record that authenticates requests holds only a SHA-256 hash (Cloudflare KV, encrypted at rest); your dashboard keeps the key so you can copy it; instantly revocable |
| Email address (API key holders) | Stored, used for account management |
| Card numbers / payment data | Handled by Polar and its processor, never seen by ibanchecker.cash |
| User browsing behaviour | Not tracked, cookieless analytics only |
Edge Runtime Architecture
ibanchecker.cash runs on Cloudflare Workers, a V8-isolated, serverless edge runtime. Each request is isolated to a single worker invocation. There is no shared memory between requests, no persistent process state, and no disk I/O. Validation results are computed in memory and returned over TLS. Nothing is written.
Cloudflare D1 (SQLite at edge) and KV are used only for API key authentication and usage counters, never for IBAN content.
Built on Cloudflare
We deliberately run no origin servers of our own. The entire platform (compute, storage, TLS termination, DDoS mitigation and the WAF) sits on Cloudflareβs global network across 300+ points of presence. This means there is no single data centre to attack, no long-lived server process to compromise, and no IBAN ever leaves the edge node that handled the request.
Independent assurance of the infrastructure
ibanchecker.cash is not itself SOC 2 or ISO certified. The infrastructure we build on is. Cloudflare maintains independently audited certifications including SOC 2 Type II (Security, Confidentiality and Availability), ISO/IEC 27001:2022, ISO/IEC 27018:2019, C5:2020 (BSI, Germany) and PCI DSS 4.0. We rely on these controls and document them honestly rather than claiming our own.
Responsible Disclosure
If you discover a security vulnerability in ibanchecker.cash, please report it responsibly to security@ibanchecker.cash. We ask that you:
- β’ Give us reasonable time (90 days) to investigate and remediate before public disclosure
- β’ Avoid accessing or modifying user data during research
- β’ Not conduct destructive testing or denial-of-service attacks
We acknowledge all credible reports within 48 hours and aim to remediate critical issues within 7 days.
Legal Documents
Our full legal framework is available for review:
Contact
- Security issues: security@ibanchecker.cash
- Privacy requests: privacy@ibanchecker.cash
- Legal / DPA: legal@ibanchecker.cash