How the API keeps data safe

Tenancy, read-only access, how secrets are held, who controls credentials, and what is logged.

Switched on per organisationThis is built and working, and is switched on for each organisation on request. Ask your account manager, or reply to any email from us naming it.
Your data onlyThe organisation is worked out on our side from the token. A request cannot name another organisation
Read onlyNothing can be created, changed or deleted through the API. Fields are limited to an approved list, and leave to annual leave
SecretsClient secrets and tokens are refused in URLs, and the API sends no cross-origin headers
ControlOnly HR admins and organisation admins create credentials, every HR admin is told when they do, revocation takes effect on the next request, and credentials last a year at most
LoggingEvery use is logged
TermsCredentials are created under the API Terms. Data you copy out is your organisation's responsibility in your own systems

If a secret may have been exposed, revoke it in Settings, API access, and tell support@alltoogether.com.