Contact usTry for free

TargetWise security

Secure access to your enrichment workflows.

TargetWise authenticates REST and MCP requests, keeps provider credentials server-side and validates inputs before retrieving data. Manage access through workspace API keys in your dashboard.

Access controlsWorkspace API keys

Generate and revoke credentials for your integrations from the authenticated dashboard.

Authenticated requests
Fixed provider connections
Request and response size limits

Security controls

Protection at every API request.

The gateway checks authentication, validates inputs and handles provider credentials on the server.

Authentication

Authorized bearer access

REST enrichment routes and the MCP endpoint reject requests without an accepted TargetWise bearer credential.

Credential isolation

Server-side upstream token

Caller credentials, cookies and arbitrary secret headers are not forwarded to the upstream data service.

Routing

Fixed upstream origin

Product operations map to fixed, allowlisted provider paths rather than caller-supplied URLs.

Validation

Strict input shapes

Each operation accepts documented identifiers, rejects unsupported fields and limits request size.

Reliability

30-second provider timeout

The gateway caps each request at 64 KiB and provider responses at 1 MiB. Requests that exceed these limits return an explicit error.

MCP

Metered retrieval boundary

Tool annotations set readOnlyHint false because calls consume credits, while destructiveHint remains false and no tool writes to another system.

Credential lifecycle

Create, isolate and revoke each integration key.

Create a named key in Dashboard → Developers. The complete key is displayed once; only a keyed digest and its last four characters are stored. A revoked key is rejected on its next request.

REST and MCP use the same workspace identity and usage ledger. Provider credentials stay server-side and are never forwarded from the caller.

  • One-time key display
  • HMAC key digests
  • Workspace ownership checks
  • Per-key request activity

Saved results

Encrypted results with a 30-day retrieval window.

Saved dashboard results use AES-256-GCM encryption with workspace, user and request context bound to the encrypted payload. Only the authenticated creator can retrieve a retained result.

Saved result retrieval expires after 30 days. Input fingerprints use a separate HMAC secret; API usage records do not retain full request inputs or contact results.

  • AES-256-GCM saved results
  • Creator-only result retrieval
  • 30-day result expiry
  • Request IDs for support and auditing

Procurement evidence

Review the controls and the contract together.

The Privacy Notice explains processing roles. The DPA covers customer-data processing, and the Subprocessors page identifies service providers. These are available from the legal pages.

For technical diligence, test rejected credentials, revoked keys, unsupported request fields and cross-workspace result access. Send a security questionnaire for infrastructure or contractual evidence that is not published here.

  • Privacy Notice: /legal/privacy
  • DPA: /legal/dpa
  • Supplier register: /legal/subprocessors
  • Service terms: /legal/terms

Frequently asked questions

Clear answers before you continue.

Practical answers about API access, credentials and security reviews.

Deployment review

Ask for the evidence relevant to your integration.

Share the product operation, delivery path and review requirements through the TargetWise contact route.

Request a security review