Security and data handling
This page covers how to connect to the Tomba API securely, how Tomba retains account data, and where to report security issues.
Transport
The API is served over HTTPS only. Send every request to https://api.tomba.io/v1.
API responses carry this Strict-Transport-Security header, so browsers and HSTS-aware clients refuse plain HTTP to the domain for a year:
Code
API credentials
- Keep your API key and secret on your server. Don't put them in browser code, mobile apps, or public repositories, where anyone can read them and spend your credits.
- Load them from environment variables or a secrets manager, as in
$TOMBA_API_KEYand$TOMBA_SECRET_KEYin the examples on this site. - Every key expires. See Key expiry.
- Use a separate key per integration, and rotate a key as soon as you suspect it leaked. See Rotate keys.
If Tomba's firewall blocks the IP address your requests come from, the API returns error type ip_blocked. See Errors.
Webhooks
Callbacks sent to a webhook_url aren't signed. Put a hard-to-guess token in the URL and reject requests that don't carry it. See Per-request callbacks.
Data retention
The Privacy Policy sets these retention periods for account data:
| Data | Retention |
|---|---|
| Active account data | While the account is active, plus 3 years of inactivity |
| Deleted accounts | Most data removed within days; remaining artefacts within 3 months |
| Billing records | As required by tax and accounting law, typically 7 years |
| Security and access logs | Up to 12 months |
| Support correspondence | 3 years from last contact |
If this table and the Privacy Policy differ, the Privacy Policy applies.
Removing personal data
Anyone can remove their email address, phone number, or LinkedIn profile from Tomba. Requests for removed data return status 451. See Data removal.
Reporting a vulnerability
Email security issues to security@tomba.io. To encrypt your report, use Tomba's PGP key. Tomba publishes its disclosure contacts in security.txt.
Compliance
- Security Policy
- GDPR
- Privacy Notice for California Residents
- Data Processing Addendum
- Privacy Policy
- Terms of Service