Apideck never stores your customers data. Integrations run through a real-time pass-through layer, a zero-storage architecture, so records are processed in memory and delivered straight to your product. No sync, no cache, no third-party data lake to secure.
Source systems
System of record
Real-time pass-through
Your product
No local copy required
Data flows through in real time. Nothing is written to disk on the way.
Zero data retention (ZDR), also called a zero-storage architecture, means integration payloads are processed in memory and never written to disk. When your SaaS or fintech product reads a customer invoice, payment, or employee record through a ZDR integration layer, the record passes through in real time and is delivered straight to your app, with no copy stored on the integration provider infrastructure. At Apideck, ZDR is not a mode you switch on. It is a founding premise of how the platform and infrastructure were designed: the Unify API is a real-time pass-through layer, so third-party customer data is never persisted. If Apideck infrastructure were compromised, there would be no customer data to expose, because none is stored.
Not storing customer data is not just a compliance checkbox. It removes an entire class of risk and makes your integrations faster and simpler at the same time.
Third-party business records are processed in memory and passed straight through. Nothing is cached on Apideck infrastructure.
Because there is no cache, every call returns live data from the source system instead of a stale sync.
TLS in transit, encrypted credential storage in Vault, SOC 2 Type II controls around every part of the platform.
SOC 2 Type II and GDPR, with EU hosting by default and data minimization as the default.
The reason Apideck can offer zero data retention is architectural. Most unified APIs copy your customers records into their own datastore. Apideck does not.
Transparency matters more than marketing here. This is exactly what the pass-through layer does and does not retain.
A small number of connectors run on-premises rather than behind a third-party cloud API. QuickBooks Desktop is the one this applies to today. Because the data does not flow through a vendor cloud API, Apideck may need to temporarily store your data as part of the sync process. Anything held that way is transient and exists only to complete the sync, but it is a real exception to pass-through, so the same notice appears on the connector page in the platform before you enable one. Review your data handling requirements before proceeding. Every cloud connector, which is the overwhelming majority of the catalogue, stays fully pass-through.
Guided walkthroughs of the three parts of the platform this page makes claims about: what is stored, where credentials sit, and what the logs keep.
The explicit list of what Apideck stores and what it stores zero of, and why the downstream system stays the source of truth.
Take the architecture tourWhere the OAuth tokens and API keys sit. Apideck stores and refreshes them encrypted, so nothing sensitive lands on your servers.
Take the Vault tourExactly what the request logs keep: the unified call you made, paired with the raw call Apideck made downstream.
Take the logs tourApideck is SOC 2 Type II certified and GDPR-compliant, and hosts in the EU by default. Data minimization is the default, connection credentials are stored encrypted in Vault, and Data Scopes give you field-level control over exactly which customer data your product requests. Because Apideck never holds customer records, your integration layer falls outside the audit boundary for data-at-rest controls, which means fewer systems in scope and simpler security reviews.
Connect your SaaS or fintech product to 200+ providers across 9 unified APIs, with zero data retention as the default.