# Security and data handling

This page covers how to connect to the Tomba API securely, how Tomba retains account data, and where to report security issues.

## Transport

The API is served over HTTPS only. Send every request to `https://api.tomba.io/v1`.

API responses carry this `Strict-Transport-Security` header, so browsers and HSTS-aware clients refuse plain HTTP to the domain for a year:

```http
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
```

## API credentials

- Keep your API key and secret on your server. Don't put them in browser code, mobile apps, or public repositories, where anyone can read them and spend your credits.
- Load them from environment variables or a secrets manager, as in `$TOMBA_API_KEY` and `$TOMBA_SECRET_KEY` in the examples on this site.
- Every key expires. See [Key expiry](/authentication#key-expiry).
- Use a separate key per integration, and rotate a key as soon as you suspect it leaked. See [Rotate keys](/authentication#rotate-keys).

If Tomba's firewall blocks the IP address your requests come from, the API returns error type `ip_blocked`. See [Errors](/error-handling#error-types).

## Webhooks

Callbacks sent to a `webhook_url` aren't signed. Put a hard-to-guess token in the URL and reject requests that don't carry it. See [Per-request callbacks](/webhook#delivery).

## Data retention

The [Privacy Policy](https://tomba.io/legal/privacy-policy) sets these retention periods for account data:

| Data                     | Retention                                                          |
| ------------------------ | ------------------------------------------------------------------ |
| Active account data      | While the account is active, plus 3 years of inactivity            |
| Deleted accounts         | Most data removed within days; remaining artefacts within 3 months |
| Billing records          | As required by tax and accounting law, typically 7 years           |
| Security and access logs | Up to 12 months                                                    |
| Support correspondence   | 3 years from last contact                                          |

If this table and the Privacy Policy differ, the Privacy Policy applies.

## Removing personal data

Anyone can remove their email address, phone number, or LinkedIn profile from Tomba. Requests for removed data return status `451`. See [Data removal](/data#data-removal).

## Reporting a vulnerability

Email security issues to [security@tomba.io](mailto:security@tomba.io). To encrypt your report, use Tomba's [PGP key](https://tomba.io/tomba-security.asc). Tomba publishes its disclosure contacts in [security.txt](https://tomba.io/.well-known/security.txt).

## Compliance

- [Security Policy](https://tomba.io/legal/security-policy)
- [GDPR](https://tomba.io/legal/gdpr)
- [Privacy Notice for California Residents](https://tomba.io/legal/privacy-notice-for-california-residents)
- [Data Processing Addendum](https://tomba.io/legal/data-processing-addendum)
- [Privacy Policy](https://tomba.io/legal/privacy-policy)
- [Terms of Service](https://tomba.io/legal/terms-of-service)
