Last Updated: April 2026
Classification: External / Client-Facing
Contact: [email protected]
Overview
In 2026, Toku ran a security hardening program across its infrastructure, endpoints, network, and application layers. This included new endpoint protection deployments, network access controls, infrastructure monitoring, credential management improvements, and independent third-party security assessments.
Third-Party Security Assessments
Toku engaged two independent firms to evaluate and improve its security posture:
- Sygnia: Cybersecurity firm that assessed Toku's infrastructure, access controls, and operational security.
- Quantstamp: Blockchain security audit firm that assessed Toku's platform, with focus on cryptocurrency and custody integration components. Findings from both assessments drove the hardening actions below.
Endpoint Security Hardening
- CrowdStrike Falcon deployed on all employee endpoints for threat detection, EDR, and managed threat hunting. Installation is mandatory and compliance is enforced.
- Pathfinder (PF) agent installed on employee devices for enhanced endpoint monitoring and security readiness, adding visibility into endpoint activity on devices with access to critical infrastructure.
- Enhanced endpoint monitoring capability established through collection tooling on all employee devices with access to GitHub and DigitalOcean.
Network and Infrastructure Hardening
- Tailscale VPN deployed as the required access path for all production infrastructure, providing zero-trust network access on WireGuard encryption. No production system is reachable without an authenticated Tailscale connection.
- Cloudflare WAF deployed on all application-layer traffic for DDoS mitigation, bot detection, rate limiting, and request filtering.
- Fireblocks IP restrictions implemented to whitelist only known Toku infrastructure IPs for custody API access. This is now a standard onboarding step for all new custody integrations.
- Network segmentation reinforced with full isolation between production, staging, and development.
Credential and Access Management
- Complete credential rotation across all integration services, including API keys, tokens, and secrets for every client integration.
- Client-side credential refresh coordinated with all clients. Clients revoked and re-provisioned API credentials on their HRIS, payroll, and custody platforms.
- Employee password rotation completed organization-wide with MFA reset and re-enrollment.
- MFA enforced for all employees using TOTP-based verification through 1Password.
- Scheduled credential rotation established as a standing operational practice.
Application and Database Improvements
- Database rebuild completed with enhanced security controls and hardened configurations.
- Enhanced database logging implemented for comprehensive audit trails on all data access and modifications.
- API endpoint hardening to eliminate token exposure in specific endpoints and enforce stricter credential handling throughout the application layer.
- Continuous dependency scanning through Dependabot with triage and remediation SLAs based on severity.
Monitoring and Detection
- New Relic deployed for systematic infrastructure monitoring, performance tracking, and alerting across all production systems.
- Enhanced security event logging across all systems, covering authentication, authorization, data access, and administrative actions.
- Automated alerting configured for integration API failures, anomalous access patterns, and security events, with on-call rotation ensuring 24/7 coverage.
Ongoing Security Program
Beyond the 2026 hardening program, Toku runs these ongoing security practices:
- Quarterly tabletop exercises covering breach, DDoS, ransomware, and insider threat scenarios
- Quarterly penetration testing by third-party firms with reports available on request
- Quarterly access reviews for critical systems and privileged accounts
- SOC 2 Type II compliance with continuous evidence collection via Drata
- Continuous vulnerability scanning via Dependabot with triage and remediation timelines by severity
Current Security Posture
The table below summarizes Toku's current security posture following the completion of the 2026 hardening program.
| Layer | Implementation |
|---|---|
| Endpoint Protection | CrowdStrike Falcon EDR + Pathfinder agent on all devices |
| Network Access | Tailscale zero-trust VPN (mandatory for all production access) |
| WAF and DDoS | Cloudflare WAF on all application traffic |
| Custody API Security | IP whitelisting + scoped credentials + scheduled rotation |
| Employee Authentication | MFA enforced for all employees, TOTP via 1Password |
| Database Security | AES-256 encryption at rest + enhanced audit logging |
| Monitoring | New Relic + Sentry + enhanced database logs + automated alerting |
| Forensic Readiness | Continuous endpoint monitoring + forensic collection capability |
| Credential Management | Scheduled rotation + immediate rotation on any suspected compromise |
| Third-Party Audits | Sygnia (infrastructure), Quantstamp (platform and blockchain) |
Questions
For any questions about Toku's security hardening program or current security posture, contact [email protected].
