API specialist kit · ECZ-ID API
ECZ-ID API Enterprise Security Review & Customer Assurance Kit
Turn API ownership, control and security evidence into an enterprise-review pack.
A buyer-facing assurance product for API providers that repeatedly answer questions about ownership, authentication, change control, evidence and operational boundaries.
- Type
- Digital product
- Price
- Not restated on this site; TrustOps publishes the current price and availability
- Acquired and paid in
- TrustOps
- Operated in · proved by
- Dashboard · Resolver
The problem
Why it matters.
Before an enterprise integrates an API, its security and procurement teams ask the same things: who operates it, which surfaces are in scope, how callers authenticate, how changes are controlled, what evidence exists and what the provider will not do. Providers answer from scratch for every customer, in a different spreadsheet each time, and deals wait on it.
Built for
- API vendors selling to enterprises with security and procurement review.
- Platform providers whose partners integrate their APIs.
- Enterprise procurement and security teams who want one consistent API assurance record.
What changes
- Faster customer security review
- Reusable API evidence
- Clearer ownership and control narrative
What you receive
Concrete deliverables, not a vague trust score.
- API identity and ownership evidence
- Security-control review prompts
- Operational and change evidence
- Customer assurance pack
- Operator
- Organisation, Business Passport tier and the API's ECZ-ID
- Scope
- The bound OpenAPI description, base URLs and environments
- Access
- How callers authenticate and are authorised — as you describe it
- Change
- Versioning, change control and incident contact
- Evidence
- Supporting evidence, with LedgerCore receipts where held
- Gaps
- Open questions an API reviewer will raise, stated plainly
Illustrative structure. The pack is assembled from the evidence you hold about the API; the Resolver remains the live proof.
How it works
A short path from need to something usable.
Define the API surface.
Collect identity and control evidence.
Resolve gaps.
Produce the customer pack.
How it relates to your Passport
The kit builds on the free API Passport: one identity for the API, its OpenAPI description and documentation bound to it, the operator on the record. It organises the evidence a reviewer needs around that identity and points them to the Resolver for current proof. A Verified or Assured Business Passport strengthens the organisation behind it; LedgerCore keeps decisive evidence in an append-only history.
Use cases
- Answering an enterprise customer's API security questionnaire from one maintained pack.
- Giving a partner's integration team the ownership and scope of an API before they build.
- Preparing an API for a regulated customer's supplier review, alongside DORA evidence.
- Keeping the same assurance story when the API moves to a new base URL or gateway.
Tiers and price
Price and availability
Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. This site does not restate this product's price; TrustOps publishes its current tiers, price and availability, and shows them before anything is bought.
How it is arranged
TrustOps acquires
TrustOps publishes the tiers and holds payment and entitlement whenever it is offered.
Dashboard operates
Once you hold it, it appears in your Dashboard, where you operate it.
Resolver proves
Public facts stay on the Resolver; holding it never changes what a record proves.
Privacy, security and evidence
What is collected, published and kept.
- You choose what goes into the pack and what, if anything, is published.
- Authentication and control descriptions come from you; the kit does not probe your API or your callers' environments.
- The pack points to the Resolver for current state; it never freezes a record into a certificate.
Boundaries
The claims stop here.
- The kit organises review evidence; it is not a penetration test or security certification.
- Control descriptions are yours. The kit does not test, scan or attest your API's security.
- Nothing in the pack changes what the Resolver record proves; payment is not proof.
Integrations and questions
Works with what you already run.
- Your OpenAPI description, with info.x-ecz-id, and your developer documentation.
- The bindings recorded against the API's ECZ-ID.
- A Verified or Assured Business Passport for supplier assurance.
- LedgerCore receipts, SBOM evidence and DORA evidence where you hold them.
- Will this pass my customer's security review?
- It makes review faster and more consistent. It does not guarantee approval, and it is not a penetration test or a certification.
- Does it replace our OAuth, IAM or gateway documentation?
- No. It references how callers authenticate and are authorised, as you describe it. Those systems stay exactly as they are.
- Do I need a paid Business Passport tier first?
- No. Your organisation's ECZ-ID Business Passport — Declared — FREE is enough to start; Verified or Assured strengthens the supplier evidence when a reviewer needs it.
- Where is it configured, and what does it cost?
- In TrustOps, which owns acquisition, payment, fulfilment and entitlement. Any price on this site is read from the TrustOps projection, and TrustOps shows whether it can complete a purchase today.
Related
- CounterpartyDCI — Digital Counterparty InfrastructureMake a digital counterparty easier for people and machines to identify, inspect and re-check.Read more
- Regulated financeDORA ICT-vendor evidencePrepare reusable ICT-vendor evidence for customers operating under DORA.Read more
- Workflow bundleECZ-ID AI Platform Assurance BundleGive buyers one coherent assurance view across an AI platform.Read more
Keep the identity free. Everything above it is optional.
Your API Passport stays free. ECZ-ID API Enterprise Security Review & Customer Assurance Kit sits above it; TrustOps shows its current state.
