Ansar collects only through official APIs, licensed feeds and permitted public endpoints. Technical ability to fetch something is not permission to use it.
Algolia HN search API and the Firebase item feed are public and unauthenticated. Documented ceiling is 10,000 requests/hour/IP. We link back rather than reproducing comment text in full.
Official REST API. Unauthenticated is 60 req/hour; GITHUB_TOKEN raises it to 5,000. There is no official /trending endpoint, so momentum is recomputed from repository facts rather than scraped. Repository deletions propagate to us.
Public-domain US filings over unauthenticated JSON. SEC requires a descriptive User-Agent and fair-access rate limiting (we hold to <=10 req/s).
LEI reference data is published under CC0. Used strictly as a legal-identity anchor, not as a company-content source.
robots.txt-respecting fetch of a known startup home page only: JSON-LD, OpenGraph, canonical URL, outbound social/repo links. One request per host per run, never a crawl. SSRF-guarded and size-capped.
GraphQL v2 with a bearer developer token; 6,250 complexity points / 15 min. Product Hunt directs commercial users to contact them, so the connector stays off until both a token and a recorded agreement exist. We display headline, link and counts, not reproduced comment bodies.
Blocked on licensing: Product Hunt requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
REST v1 with a tmrr_ bearer key; 10 req/min standard. Acceptable use forbids bulk republication or rebuilding the service, so we store metrics for signals and show per-company figures with attribution and a link, never a browsable copy of their database. Payment-provider verification applies to aggregate revenue only, not to every seller claim.
Blocked on licensing: TrustMRR requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
Free official UK registry API; key required, 600 requests / 5 minutes. Officer personal data is deliberately not ingested - company identity and filing events only.
Missing credentials: COMPANIES_HOUSE_API_KEY
Open access is share-alike; commercial redistribution needs a licence. Until one is recorded the connector is disabled and, if enabled, its records may only anchor entity resolution internally - displayAllowed stays false.
Blocked on licensing: OpenCorporates requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
Licensed v4 API. Plan terms govern display and redistribution, so the default is internal-join-only. Flip displayAllowed to true only against a signed plan that permits it.
Blocked on licensing: Crunchbase requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
Commercial API on request. Same posture as Crunchbase: internal joins until licensed.
Blocked on licensing: Dealroom requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
Paid Domain/Change APIs. Technology detections are third-party inferences and are stored as third_party_estimated. Shared analytics IDs are useful for entity resolution but produce false positives across shared agencies, so they never merge on their own.
Blocked on licensing: BuiltWith requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
Business-plan lookup API, 10 req/s and up to 10 URLs per request. Alternative to BuiltWith; enabling both is supported but redundant.
Blocked on licensing: Wappalyzer requires a recorded agreement before collection. A credential alone is not permission; an operator adds an approval in the admin console once the terms are actually agreed.
Ansar does not bypass authentication or access controls, does not solve CAPTCHAs, does not rotate proxies to defeat blocking, does not impersonate users, and does not attempt to deanonymise confidential marketplace listings. A source that cannot be accessed within its terms stays switched off, with the reason recorded above.