Merchant sandbox and data notice
Version: 2026-10-09 · Operator: Gridzen Limited · Contact: open@gridzen.ai
Current service scope
This beta provides accounts, API keys, simulated verifications, records, and usage management. Identity flows use the official Didit sandbox; phone flows use Twilio adapter mocks. All results are for software integration testing only. They do not verify real people and must not be used to approve account opening, payments, or other real transactions.
Do not submit real identity numbers, phone numbers, bank details, identity documents, or face images. Do not bypass quotas, register accounts in bulk, or attempt to access another merchant's data. No credit card is required and no billable queries or charges are initiated. Production capabilities, currency, pricing, paid-service terms, and production merchant checks are not yet available.
Data we process
Your registration email and company name identify your account and are encrypted on GridZen servers. Passwords use a one-way password hash; only hashes of API keys, session tokens, and recovery codes are stored. You must verify email ownership before registration. Email verification does not verify business identity or authority.
Verification records contain the test scenario, timestamps, redacted statuses, and provider sandbox session identifiers. Didit receives random session references and simulation scenarios. This console does not send registration emails, company names, or real identity data to Didit. Phone simulations do not call the external Twilio API.
Retention and deletion
Detailed verification records are retained for 30 days; security activity for 90 days. Test usage and idempotency references remain until account deletion to prevent duplicate requests and quota resets. Sessions last up to 8 hours. API keys expire after 90 days and can be revoked earlier. Short-term security limits use hashed IP addresses, retained for at most 24 hours.
You can delete individual detailed records or permanently delete your account and local GridZen account data by confirming your password in settings. This does not delete simulated sessions held by Didit. Contact the email above about provider-side data. This beta has no interface for uploading real identity documents.
Account recovery
Registration requires email verification. Reset your password using an email code or backup recovery code. Emails are sent from the existing GridZen business mailbox through Microsoft Graph; the email provider processes recipient addresses and verification messages. Codes expire after 10 minutes, work once, and lock after 5 incorrect attempts. Sending is rate-limited. We store only a keyed hash of each code and retain verification request records for at most 24 hours. Recovery codes are shown once; keep yours in a password manager, because anyone holding it can reset your password. Recovery, verification of a legacy account, or a password change revokes old sessions and API keys. Never put credentials in public code or chats.
Service availability
This free test service may change, pause, or remove expired records. No production service-level commitment is provided. Follow the published sandbox quotas and scope. Future paid services require separately defined terms and pricing; sandbox registration does not subscribe you to a paid service.
Back to console