1. Where the data comes from
We do not hold our own copy of a national registry. Each endpoint forwards your query to the institution or provider that holds the record and returns what comes back. Grouped by issuing body:
| Data category | Source | Country | Verification status | Endpoints |
|---|---|---|---|---|
| Civil identity and CURP validation | RENAPO — Registro Nacional de Población (Secretaría de Gobernación)Official sitePublic institution | Mexico | Confirmed; official source linked | /curp/query_by_curp/curp/verify |
| Tax registration (RFC) | SAT — Servicio de Administración TributariaOfficial sitePublic institution | Mexico | Confirmed; official source linked | /torfc/query_by_curp |
| Social security enrolment and NSS | IMSS — Instituto Mexicano del Seguro SocialOfficial sitePublic institution | Mexico | Confirmed; official source linked | /curp/curp_to_nss/shebao/query_by_curp/imss/query_by_curp/imss/vigencia/basic/imss/vigencia/family |
| Housing credit and worker profile | INFONAVIT — Instituto del Fondo Nacional de la Vivienda para los TrabajadoresOfficial sitePublic institution | Mexico | Confirmed; official source linked | /infonavit/loan/infonavit/profile |
| Retirement savings account | CONSAR / AFORE — Sistema de Ahorro para el RetiroOfficial sitePublic institution | Mexico | Confirmed; official source linked | /afore/account |
| Education and professional licence | SEP — Secretaría de Educación Pública (Registro Nacional de Profesionistas)Official sitePublic institution | Mexico | Confirmed; official source linked | /edu/query_by_curp/sep/query_by_curp |
| State driving licence | Gobierno del Estado de México — licencia de conducirPublic institution | Mexico | Confirmed; no stable public source link | /edomex/licencia |
| Mobile account status | Telcel — Radiomóvil Dipsa, S.A. de C.V.Official siteCommercial holder | Mexico | Confirmed; official source linked | /telcel/account |
| Retirement savings account | AFP ModeloRegulator: Superintendencia de Pensiones Official siteCommercial holder | Chile | Confirmed; regulator linked; holder page not verified | /afp_modelo/profile/afp_modelo/balance/afp_modelo/products/afp_modelo/returns/afp_modelo/profession |
| Social programme classification | SISBÉN — Departamento Nacional de PlaneaciónOfficial sitePublic institution | Colombia | Confirmed; official source linked | /sisben/profile/sisben/classification |
2. Sources still being confirmed Pending confirmation
Two endpoints return personal contact details and derived risk attributes, and we have not yet confirmed a documented upstream holder for them. Rather than attribute them to an institution we cannot evidence, we list them here as unresolved. Do not rely on these two for compliance-sensitive decisions until this is settled.
- Contact details and derived attributes —
/personal/contact/prism/external/queryTagAndInfo
3. Source status, known limitations and change record
This is a versioned transparency page, not a live service-status dashboard. A date is shown only when the underlying fact has been checked and recorded; an unverified gap stays visible rather than being filled with a plausible claim.
- Production metrics snapshot
- 2026-09-22
- Update model
- Manually verified, versioned facts — not an automatic status feed
- Questions or corrections
- Use the contact channels at the end of this page
Known limitations
- A confirmed source holder and a publicly linkable holder page are different things. Where a stable first-party page was not verified, the table says so instead of inserting a secondary link.
- Two endpoints that return contact details and derived attributes still have no documented upstream holder. They remain visible as unresolved and should not be used for compliance-sensitive decisions.
- The request/response and analytics stores have no automated deletion schedule. The retention section below describes that gap rather than promising a period that is not implemented.
Change record
- 2026-09-22Production facts snapshot recorded
The performance figures and observed status-code counts on this page are the full production-call population for the displayed window. This is a dated evidence snapshot, not a forecast or an uptime commitment.
3. Endpoints with no personal data
One endpoint is infrastructure rather than identity data and involves no data subject:
/json— IP address geolocation
4. What the platform stores
Stored
- Account profile, hashed password, last sign-in IP and time, prepaid balance, API token.
mall_user - Per-call metadata: endpoint, route, caller IP, user agent, amount charged, HTTP status, response time, error message.
api_call_log - Request parameters and the upstream response body, retained for troubleshooting and billing disputes. Because queries are by identifier, this includes the identifiers you submit and the personal records returned for them, in readable form.
api_request_log - Website analytics events: page URL and title, referrer, user agent, device type, browser, OS, screen resolution, language, IP address, device identifier.
event_log
Not stored
- Your own upstream credentials — you do not supply any; the gateway uses its own.
- Card numbers or bank credentials — top-ups are settled in USDT and no card data reaches us.
5. Measured performance
Figures below are the full population of production calls between 2026-03-25 and 2026-09-22 — 534 calls, no sampling and no exclusions.
- Mean response time
- 10.0 s
- Business success rate
- 74.9%
- HTTP 200 rate
- 88%
- Calls measured
- 534
The two rates differ because an upstream “no record found” is returned as HTTP 200 with an empty payload — a valid response, but not a substantive result. We report the stricter business figure as the headline so the number is not flattered by empty responses. Latency is dominated by the upstream institution and varies widely by endpoint; build for slow responses.
6. Status codes you will actually see
These are the codes observed across production traffic, with their real frequency. Codes not listed have not occurred.
| Code | Meaning | Occurrences |
|---|---|---|
200 | Request reached the upstream source and a response was returned. This includes “no record found”, so check the payload, not just the code. | 470 |
402 | Prepaid balance did not cover the call. The call was not made and nothing was charged. Top up and retry. | 33 |
504 | Upstream source did not answer in time. Retry later; this is the normal failure mode for slow registries. | 15 |
404 | Route does not exist, or the endpoint is no longer published. | 10 |
401 | Missing or invalid API token. | 6 |
7. Using this data lawfully
The obligations below are conditions of access, not suggestions. They restate section 3 of the Terms of Service in operational terms.
- Have a documented lawful basis for each identifier you query, and keep it auditable.
- Query only subjects you have a relationship with or an express mandate over. Do not enumerate identifier ranges.
- Use a result to verify or corroborate, never as the sole basis for an adverse decision about someone.
- Treat an empty result as inconclusive, not as evidence of absence.
- Honour the individual's rights under their own national law, including access and correction, and route corrections to the issuing institution.
- Do not build a resale or people-search product from responses.
8. If the data is about you
To correct or erase a record at source, go to the issuing institution — the official channels are linked in the table above, and only they can change the underlying record. If you want to know what our platform retained about a query concerning you, or want that removed from our own stores, use the contact channels below.
Registered entity Pending confirmation
The registration details for the entity operating API Pull have not been published yet. Rather than print a placeholder here, we are leaving the table empty and keeping this page out of search indexing until the details are confirmed. Until then, the contact channels below are the authoritative way to reach a responsible party.
How to reach us
Questions about this document, requests about your own data, and requests about a record returned by one of our endpoints all go to the same two channels. Written requests by email are preferred because they leave a record on both sides.
- partner@apipull.com
- Telegram
- https://t.me/Api_pull