2026 Security Hardening Program

InfoTable of Contentsclock icon4 MIN READ·calendar iconUPDATED APR 20, 2026

Toku's 2026 security hardening program strengthened infrastructure, endpoints, networks, and applications through endpoint protection deployment, zero-trust VPN access, credential rotation, enhanced monitoring, and third-party security assessments by Sygnia and Quantstamp.

Last Updated: April 2026

Classification: External / Client-Facing

Contact: [email protected]


Overview

In 2026, Toku ran a security hardening program across its infrastructure, endpoints, network, and application layers. This included new endpoint protection deployments, network access controls, infrastructure monitoring, credential management improvements, and independent third-party security assessments.


Third-Party Security Assessments

Toku engaged two independent firms to evaluate and improve its security posture:

  • Sygnia: Cybersecurity firm that assessed Toku's infrastructure, access controls, and operational security.
  • Quantstamp: Blockchain security audit firm that assessed Toku's platform, with focus on cryptocurrency and custody integration components. Findings from both assessments drove the hardening actions below.

Endpoint Security Hardening

  • CrowdStrike Falcon deployed on all employee endpoints for threat detection, EDR, and managed threat hunting. Installation is mandatory and compliance is enforced.
  • Pathfinder (PF) agent installed on employee devices for enhanced endpoint monitoring and security readiness, adding visibility into endpoint activity on devices with access to critical infrastructure.
  • Enhanced endpoint monitoring capability established through collection tooling on all employee devices with access to GitHub and DigitalOcean.

Network and Infrastructure Hardening

  • Tailscale VPN deployed as the required access path for all production infrastructure, providing zero-trust network access on WireGuard encryption. No production system is reachable without an authenticated Tailscale connection.
  • Cloudflare WAF deployed on all application-layer traffic for DDoS mitigation, bot detection, rate limiting, and request filtering.
  • Fireblocks IP restrictions implemented to whitelist only known Toku infrastructure IPs for custody API access. This is now a standard onboarding step for all new custody integrations.
  • Network segmentation reinforced with full isolation between production, staging, and development.

Credential and Access Management

  • Complete credential rotation across all integration services, including API keys, tokens, and secrets for every client integration.
  • Client-side credential refresh coordinated with all clients. Clients revoked and re-provisioned API credentials on their HRIS, payroll, and custody platforms.
  • Employee password rotation completed organization-wide with MFA reset and re-enrollment.
  • MFA enforced for all employees using TOTP-based verification through 1Password.
  • Scheduled credential rotation established as a standing operational practice.

Application and Database Improvements

  • Database rebuild completed with enhanced security controls and hardened configurations.
  • Enhanced database logging implemented for comprehensive audit trails on all data access and modifications.
  • API endpoint hardening to eliminate token exposure in specific endpoints and enforce stricter credential handling throughout the application layer.
  • Continuous dependency scanning through Dependabot with triage and remediation SLAs based on severity.

Monitoring and Detection

  • New Relic deployed for systematic infrastructure monitoring, performance tracking, and alerting across all production systems.
  • Enhanced security event logging across all systems, covering authentication, authorization, data access, and administrative actions.
  • Automated alerting configured for integration API failures, anomalous access patterns, and security events, with on-call rotation ensuring 24/7 coverage.

Ongoing Security Program

Beyond the 2026 hardening program, Toku runs these ongoing security practices:

  • Quarterly tabletop exercises covering breach, DDoS, ransomware, and insider threat scenarios
  • Quarterly penetration testing by third-party firms with reports available on request
  • Quarterly access reviews for critical systems and privileged accounts
  • SOC 2 Type II compliance with continuous evidence collection via Drata
  • Continuous vulnerability scanning via Dependabot with triage and remediation timelines by severity

Current Security Posture

The table below summarizes Toku's current security posture following the completion of the 2026 hardening program.

Layer Implementation
Endpoint Protection CrowdStrike Falcon EDR + Pathfinder agent on all devices
Network Access Tailscale zero-trust VPN (mandatory for all production access)
WAF and DDoS Cloudflare WAF on all application traffic
Custody API Security IP whitelisting + scoped credentials + scheduled rotation
Employee Authentication MFA enforced for all employees, TOTP via 1Password
Database Security AES-256 encryption at rest + enhanced audit logging
Monitoring New Relic + Sentry + enhanced database logs + automated alerting
Forensic Readiness Continuous endpoint monitoring + forensic collection capability
Credential Management Scheduled rotation + immediate rotation on any suspected compromise
Third-Party Audits Sygnia (infrastructure), Quantstamp (platform and blockchain)

Questions

For any questions about Toku's security hardening program or current security posture, contact [email protected].

Was this article helpful?

Can't find what you're looking for?

The Toku AI assistant has read every article. A human specialist reviews every submission.