Stackbyte APIs
Each API answers one kind of question using data from official public sources. All of them share one key and one credit balance, so adding a second API to your integration does not mean a second contract.
CVE Triage is in development and will open first. Paid plans start when it goes live.
CVE Triage
Is this vulnerability being exploited, and how likely is it to be?
Sources: NVD, FIRST EPSS, CISA KEV, OSV
In development
Package Risk
Is this npm, PyPI or Go package known to be vulnerable or malicious?
Sources: OSV, deps.dev, public malicious-package reports
Next
Cloud Intel
Which provider, region and network does this IP address belong to? Is it a Tor exit?
Sources: Cloud provider IP range files, regional internet registries, Tor Project
Next
Sanctions Screen
Does this name appear on a UN, UK, EU, US or UAE sanctions list?
Sources: UN, OFAC, EU, UK and UAE official lists
Planned
Product Recalls
Has this product been recalled in the UK, EU or US?
Sources: UK OPSS, EU Safety Gate, CPSC, FDA
Planned
UAE Company Verify
Is this UAE trade licence valid, and what is the company registered to do?
Sources: Dubai Pulse trade licence data, ADGM and DIFC public registers
Planned
Dubai Property Data
What have comparable Dubai properties sold and rented for?
Sources: Dubai Land Department via Dubai Pulse
Planned
Pricing
Monthly plans with a credit allowance that works across every API. Credits reset each billing month. Paid plans keep working past the allowance and bill the extra credits; the free plan stops at its limit.
| Plan | Price per month | Credits per month | Beyond the allowance |
|---|---|---|---|
| Free | $0 | 100 | Stops at the limit |
| Starter | $19 | 2,000 | $0.012 per credit |
| Growth | $49 | 10,000 | $0.008 per credit |
| Scale | $149 | 50,000 | $0.005 per credit |
Prices are in US dollars. VAT or other sales tax is added where it applies. For volumes above the Scale plan, or if you need an SLA or a data processing agreement, get in touch.
Credits per call
| CVE lookup | 1 |
|---|---|
| CVE batch | 1 per 10 CVEs |
| Package lookup | 1 |
| IP lookup | 1 |
| Sanctions screen | 2 |
| Recall lookup | 1 |
| Company lookup | 1 |
| Company search | 2 |
| Property query | 2 |
| Rental index | 1 |
| Any repeat of the same request within 24 hours | 1 |
Failed requests are not charged. A lookup that finds no record still counts as a lookup.
What comes with a key
- REST endpoints with an OpenAPI specification and reference docs
- Python and TypeScript client libraries
- An MCP server, so AI agents can call the APIs directly
- Sandbox keys (sb_test_) alongside live keys (sb_live_)
Client libraries and the MCP server ship with the first API.
How we handle the data
- Official sources only
- Every dataset comes from a government register, an official API or a public feed whose licence allows commercial use. Each response names its sources.
- Checked every night
- Each import has to pass checks on structure and volume before it replaces the previous day's data. If a source is down or looks wrong, the API keeps serving the last good copy and tells you its date.
- Lookups, not bulk downloads
- The APIs answer questions about specific records. We do not sell copies of whole datasets.
- As little personal data as possible
- Where a record could identify a person, we keep only what a lookup needs and act on removal requests.
Request early access
Leave your email and we will let you know when CVE Triage opens for testing, then again as each new API launches. Nothing else. To come off the list, reply to any of our emails or write to team@stackbyte.app.