How the API keeps data safe
Tenancy, read-only access, how secrets are held, who controls credentials, and what is logged.
Switched on per organisationThis is built and working, and is switched on for each organisation on request. Ask your account manager, or reply to any email from us naming it.
| Your data only | The organisation is worked out on our side from the token. A request cannot name another organisation |
| Read only | Nothing can be created, changed or deleted through the API. Fields are limited to an approved list, and leave to annual leave |
| Secrets | Client secrets and tokens are refused in URLs, and the API sends no cross-origin headers |
| Control | Only HR admins and organisation admins create credentials, every HR admin is told when they do, revocation takes effect on the next request, and credentials last a year at most |
| Logging | Every use is logged |
| Terms | Credentials are created under the API Terms. Data you copy out is your organisation's responsibility in your own systems |
If a secret may have been exposed, revoke it in Settings, API access, and tell support@alltoogether.com.