Skip to content
ECZ-IDAPI

API specialist kit · ECZ-ID API

ECZ-ID API Enterprise Security Review & Customer Assurance Kit

Turn API ownership, control and security evidence into an enterprise-review pack.

A buyer-facing assurance product for API providers that repeatedly answer questions about ownership, authentication, change control, evidence and operational boundaries.

Type
Digital product
Price
Not restated on this site; TrustOps publishes the current price and availability
Acquired and paid in
TrustOps
Operated in · proved by
Dashboard · Resolver

The problem

Why it matters.

Before an enterprise integrates an API, its security and procurement teams ask the same things: who operates it, which surfaces are in scope, how callers authenticate, how changes are controlled, what evidence exists and what the provider will not do. Providers answer from scratch for every customer, in a different spreadsheet each time, and deals wait on it.

Built for

  • API vendors selling to enterprises with security and procurement review.
  • Platform providers whose partners integrate their APIs.
  • Enterprise procurement and security teams who want one consistent API assurance record.

What changes

  • Faster customer security review
  • Reusable API evidence
  • Clearer ownership and control narrative

What you receive

Concrete deliverables, not a vague trust score.

  • API identity and ownership evidence
  • Security-control review prompts
  • Operational and change evidence
  • Customer assurance pack
The customer assurance pack
Operator
Organisation, Business Passport tier and the API's ECZ-ID
Scope
The bound OpenAPI description, base URLs and environments
Access
How callers authenticate and are authorised — as you describe it
Change
Versioning, change control and incident contact
Evidence
Supporting evidence, with LedgerCore receipts where held
Gaps
Open questions an API reviewer will raise, stated plainly

Illustrative structure. The pack is assembled from the evidence you hold about the API; the Resolver remains the live proof.

How it works

A short path from need to something usable.

  1. Define the API surface.

  2. Collect identity and control evidence.

  3. Resolve gaps.

  4. Produce the customer pack.

How it relates to your Passport

The kit builds on the free API Passport: one identity for the API, its OpenAPI description and documentation bound to it, the operator on the record. It organises the evidence a reviewer needs around that identity and points them to the Resolver for current proof. A Verified or Assured Business Passport strengthens the organisation behind it; LedgerCore keeps decisive evidence in an append-only history.

Use cases

  • Answering an enterprise customer's API security questionnaire from one maintained pack.
  • Giving a partner's integration team the ownership and scope of an API before they build.
  • Preparing an API for a regulated customer's supplier review, alongside DORA evidence.
  • Keeping the same assurance story when the API moves to a new base URL or gateway.

Tiers and price

Price and availability

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. This site does not restate this product's price; TrustOps publishes its current tiers, price and availability, and shows them before anything is bought.

How it is arranged

  1. TrustOps acquires

    TrustOps publishes the tiers and holds payment and entitlement whenever it is offered.

  2. Dashboard operates

    Once you hold it, it appears in your Dashboard, where you operate it.

  3. Resolver proves

    Public facts stay on the Resolver; holding it never changes what a record proves.

Privacy, security and evidence

What is collected, published and kept.

  • You choose what goes into the pack and what, if anything, is published.
  • Authentication and control descriptions come from you; the kit does not probe your API or your callers' environments.
  • The pack points to the Resolver for current state; it never freezes a record into a certificate.

Boundaries

The claims stop here.

  • The kit organises review evidence; it is not a penetration test or security certification.
  • Control descriptions are yours. The kit does not test, scan or attest your API's security.
  • Nothing in the pack changes what the Resolver record proves; payment is not proof.

Integrations and questions

Works with what you already run.

  • Your OpenAPI description, with info.x-ecz-id, and your developer documentation.
  • The bindings recorded against the API's ECZ-ID.
  • A Verified or Assured Business Passport for supplier assurance.
  • LedgerCore receipts, SBOM evidence and DORA evidence where you hold them.
Will this pass my customer's security review?
It makes review faster and more consistent. It does not guarantee approval, and it is not a penetration test or a certification.
Does it replace our OAuth, IAM or gateway documentation?
No. It references how callers authenticate and are authorised, as you describe it. Those systems stay exactly as they are.
Do I need a paid Business Passport tier first?
No. Your organisation's ECZ-ID Business Passport — Declared — FREE is enough to start; Verified or Assured strengthens the supplier evidence when a reviewer needs it.
Where is it configured, and what does it cost?
In TrustOps, which owns acquisition, payment, fulfilment and entitlement. Any price on this site is read from the TrustOps projection, and TrustOps shows whether it can complete a purchase today.