# Security and Data Protection

Tomba for Salesforce is a managed package that runs inside your Salesforce org and calls the Tomba API only for
the work you ask it to do.

## Data flow

1. A user, a bulk job, an automation rule, a Flow or an agent asks Tomba to look up a record.
2. The package sends **only the inputs of that lookup** — for example an email address, or a first name, last name
   and company domain — to `https://api.tomba.io` over HTTPS.
3. Tomba answers with the result (email, verification status, company data…).
4. The package writes the result to the fields your [field mapping](/salesforce/field-mapping) allows.

Nothing is sent in the background unless an admin turns on automation, and automation is off in sandboxes unless
explicitly allowed ([Sandboxes](/salesforce/sandboxes)).

## What Tomba stores

Requests are recorded in your tomba.io account's request log (the **Salesforce** source on your usage page) like any
API call, under the tomba.io [privacy policy](https://tomba.io/privacy). The package does not export your Salesforce
records in bulk to Tomba.

## Credentials

- The connection is made with **OAuth** (PKCE) to your Tomba Enterprise account, or with an API key.
- The package creates a dedicated API key named after your org, so you can see and revoke it at
  [app.tomba.io/api](https://app.tomba.io/api); it is renewed automatically before it expires.
- The key, secret and refresh token are stored in a Salesforce **external credential**, encrypted by Salesforce.
  Users and Apex code cannot read them; they are only added to requests to `api.tomba.io`.

## Salesforce permissions

- Queries and updates run in **user mode**: object permissions, field-level security and sharing are enforced, so
  users only see and change records they have access to.
- Fields are written only when the user may edit them and only according to the field mapping.
- Access is granted with the **Tomba User** and **Tomba Admin** permission sets; only Tomba Admins can connect,
  change settings and edit field mappings.

## Control and audit

- **Usage log**: every lookup is recorded per day, user and source (record action, search, bulk, automation, Flow,
  agent) — see [Usage, limits and alerts](/salesforce/usage-and-limits).
- **Limits**: monthly automation budget and per-user credit limits.
- **Bulk jobs** record who started them, what they processed and the credits used.

## Disconnecting

Disconnecting removes the stored credentials and revokes the OAuth grant. You can also revoke access at
[app.tomba.io › Connected apps](https://app.tomba.io/settings/connected-apps) or delete the `Salesforce – …` key.

## Salesforce Security Review

Tomba for Salesforce is distributed through AppExchange, which requires passing the Salesforce Security Review;
the review status is shown on the AppExchange listing. For security questionnaires, contact your Tomba account
team or [Tomba support](https://help.tomba.io).
