R13
Sign inGet started
Security & trust

Built lawfully, hosted in the EU, run on public data

Route13 aggregates public corporate data from official government registries and serves it from EU-based, self-managed infrastructure. No data resellers, no scraped tier-3 portals, no surprise bills. Here is exactly how it works.

Official registry sources only

Every field comes from a government or government-mandated registry — INSEE & Tribunal de Commerce (France), BCE/KBO (Belgium), Companies House (UK), and the national registries of Germany, Poland, Czechia, Norway, Estonia and Finland. We do not buy from third-party data brokers and we do not scrape tier-3 portals. The full map of sources, per country, is on the Data sources page.

Only public corporate data

We handle company-level financials and the names and roles of registered legal representatives — the information the source registry has itself published. Personal data about company officers is processed under GDPR Art. 6(1)(f) (legitimate interest), limited to what registries publish and excluding anyone who has opted out of public diffusion. No special-category data. Full detail in our Privacy Policy.

EU-hosted, self-managed infrastructure

All primary storage and authentication run on our own servers in the EU (Hetzner, Falkenstein, Germany) — a self-managed PostgreSQL database, not a third-party BaaS. Payments are handled by Stripe (Dublin, IE). Data stays in the EU; where a subprocessor touches request metadata (e.g. Cloudflare edges) it is covered by SCCs and EU-US Data Privacy Framework certification.

Encryption & network protection

  • TLS 1.3 for all external traffic (encryption in transit).
  • Full-disk encryption at rest on the database volume.
  • Cloudflare WAF, DDoS absorption and rate limiting at the network edge.
  • Per-endpoint rate limits on the public API and lead forms.
  • Daily encrypted, off-site backups retained 30 days.

API keys & account isolation

API keys are shown once at creation and stored only as a SHA-256 hash — we never keep the raw key. Every request is validated server-side and scoped to your account and the countries your plan covers. Search is free and rate-limited; unlocking a full record costs 1 credit and stays unlocked for you forever. See the API docs and OpenAPI spec.

Transparent, no-surprise billing

Credits are a shared balance across web and API: search never charges, only unlocking a new company does — and once unlocked it is free forever. You can cancel any time from your dashboard; your plan stays active until the end of the billing period and companies you have already unlocked remain accessible. Pricing is per-country with no metered call quotas — see Pricing.

Your GDPR rights

Access, rectification, objection and erasure requests are handled at [email protected]. Our DPIA, RoPA, TIA and LIA are maintained internally and available on request. Read the Privacy Policy and Terms.
Found a vulnerability or have a security question? Contact us.