VeritomeHelp Center
/

API keys and organisation data export

Create hashed API keys for programmatic access, generate a sealed export of all organisation data, and file a GDPR erasure request.

Updated 08.07.2026

API keys

API keys give scripts and integrations programmatic access to the v1 API (systems, obligations, reports, audit log). API access requires the Growth plan or above, and requests are rate-limited per key.

  1. Go to Settings → API keys & webhooks and create a key with a name and a scope — read-only or read & write (a read-only key is rejected on any mutating endpoint).
  2. The full key (starting with ak_) is shown exactly once. Only a SHA-256 hash is stored at rest, so copy it before closing the dialog.
  3. Send it as a bearer token in the Authorization header of API requests.

You can rotate a key (a new secret, same entry) or revoke it from the same list, which also shows each key's prefix and last-used time. Creation, rotation and revocation are all audit-logged.

Export all data

From Settings → Data, privacy & residency, an Admin can click Generate export to download a complete machine-readable bundle of the organisation's data — systems, classifications, obligations, incidents and the audit trail. The bundle is built server-side, stored in object storage, and returned as a short-lived signed download link together with a SHA-256 fingerprint so recipients can verify the bundle was not altered after generation. This supports GDPR Art. 15 access requests.

Delete organisation (GDPR erasure)

On the same page, Delete organisation files a GDPR Art. 17 right-to-erasure request rather than deleting inline: type your organisation's exact name to confirm, and the page then shows Erasure request pending with the filing date and statutory one-month due date. The Veritome operator fulfils the request on an audited path; contact support to cancel while it is pending.

Need to act on this?Open Veritome