Reliability & Security
Built to be depended on
Uptime, service commitments, long-term API stability and security — everything a team doing due-diligence needs to know before making fastFOREX API part of their stack, on one page.
Jump to: Infrastructure — Uptime — SLA — Long-term support — Security
The numbers behind the promise.
Infrastructure & performance.
Designed from the ground up for low latency and high-volume throughput — end to end, from our industry data sources through to your application.
Premium hyperscaler hosting
Google Cloud's Premium Network Tier, globally distributed and geo-located. The API is exposed on global anycast IPv4 and IPv6, with DNS on Cloudflare's anycast network.
Built for milliseconds
Minimised network hops and a redundant in-memory data backbone — the smallest possible failure surface, the lowest possible latency. WebSocket streaming uses pass-through load balancers for regional performance.
Serious scale
Around 1.9B data points ingested every week — processed, analysed, scaled out and stored. That pipeline sits behind every rate you fetch.
Resilient at the source
Data aggregated from 100+ FX contributors and multiple crypto venues — no single upstream source can take the feed down.
Uptime.
An FX API is infrastructure — if it isn't up, nothing you build on it is. We treat availability as the product.
A public status page, always on
Live status and incident history at fastforex.instatus.com — real, independent monitoring with alerting and maintenance schedules. Register there for service alerts. No hiding bad days.
Monitored like a customer, not a server
Uptime monitoring is service-specific and full-stack: complete requests including authentication and response validation. If a check passes, a real API call would have too.
Failover at every layer
Multiple layers of cross-region failover run at each layer of the containerised application stack — availability isn't resting on any one region, container or upstream source.
Maintenance when markets sleep
Planned maintenance windows always target market-closed periods, such as weekends — scheduled and announced on the status page in advance.
Exchange rate API uptime & SLA commitments.
Published availability targets and response times — not vague reassurance.
| Plan | Availability target | Support response target |
|---|---|---|
| One · Extra · Premium | 99.95% | Within 12 business hours |
| Commercial | 99.99% | Within 6 business hours |
Support answers 365 days a year. Contact support to discuss Commercial plan terms.
Skin in the game
If we miss the availability target, annual customers receive a discount on their annual renewal. Our uptime record isn't just published — it's priced in.
Transparent by default
Public status history, published data sources and honest documentation. If something breaks, you'll hear it from us, not from your error logs.
No lock-in
Monthly billing, cancel anytime, and top-ups instead of forced tier upgrades. Our commitment is earned monthly, not contracted annually.
Long-term support.
APIs get embedded deep in products and forgotten about — ours is built to still be answering the same calls years later.
We never break anything
Policy, not aspiration: existing endpoints are never changed in breaking ways. Evolution ships as new APIs — versioned paths (/v2/…) or entirely new endpoints, like our Metals API, added alongside the existing FX endpoints rather than changing them.
Serving developers since 2020
In continuous operation since 2020, run by Wham Software Limited, a UK-registered company (no. 13074731) — a stable counterparty, not a venture-funded experiment.
Your history doesn't expire
Over 55 years of historical FX data is core to the product, and your access to it doesn't expire with an API version.
Security.
Market data doesn't need your customers' data — and our design keeps it that way.
Encrypted, always
All API traffic is served exclusively over HTTPS/TLS. There is no unencrypted endpoint to accidentally use. Google Cloud's Premium Network Tier keeps traffic on Google's private backbone — public internet at the last mile only.
Keys you control
Authenticate via the X-API-Key header, keeping keys out of URLs and logs. Create separate live, dev and test keys — rename, rotate or revoke them instantly in the Console.
Minimal data by design
Using the API requires no personal data beyond your signup email. Your requests contain currency codes, not customer information — there's simply very little to protect, and we like it that way.
Payments handled by Paddle
Card details never touch our systems — billing runs through Paddle, a PCI-DSS compliant merchant of record. Full details on our Billing & Payments page.
Certified foundations, aligned policy
Our infrastructure runs on Google Cloud, independently certified for SOC 2 and ISO 27001. On top sits the Wham Software Information Security Policy, aligned with ISO 27001 and SOC 2 — available to customers on request.
Direct lines for the serious stuff
Found a vulnerability? Report it to security@fastforex.io. Need a data processing agreement for your compliance team? Contact dpa@fastforex.io.
Reliability & security — FAQ.
The questions due-diligence teams ask.
Where is fastFOREX API hosted?
Where can I see your live status and incident history?
Will you break my integration with an API change?
What data do you hold about my business?
Do you offer a formal SLA?
Doing due-diligence?
Our support team answers 365 days a year — happy to complete security questionnaires.
Depend on us — starting free.
Get your free API key — full plan access for 7 days, no credit card required.