Last Updated: April 2026
Classification: External / Client-Facing
Contact: [email protected]
Endpoint Detection and Response (EDR)
CrowdStrike Falcon is deployed on all Toku employee endpoints. It provides threat detection, EDR, and managed threat hunting. CrowdStrike monitors for malware, ransomware, fileless attacks, and anomalous behavior on every device with access to Toku systems.
CrowdStrike was deployed as part of Toku's 2026 security hardening program. All employees are required to have it installed and active.
Device Management
Jamf is deployed on all company-managed macOS devices. It handles configuration enforcement, OS patch compliance, software inventory, and security policy application. Devices must meet Toku's baseline security requirements before accessing production systems.
VPN and Zero-Trust Network Access
All internal access to Toku's production infrastructure routes through Tailscale, a zero-trust VPN mesh network on WireGuard. Only authenticated and authorized devices can reach production resources. VPN traffic is encrypted end-to-end.
Tailscale was deployed as part of Toku's 2026 infrastructure hardening, adding network-level access control on top of endpoint and application-level protections.
Endpoint Monitoring
In addition to CrowdStrike Falcon, Toku deployed the Pathfinder (PF) agent on employee devices for enhanced endpoint monitoring. This agent provides additional visibility into endpoint activity, supporting security monitoring and evidence collection for devices with access to critical systems including GitHub and DigitalOcean.
Mandatory Security Software
Every Toku employee is required to have the following installed and active:
| Tool | Purpose |
|---|---|
| CrowdStrike Falcon | Endpoint detection and response (EDR) |
| Tailscale | Zero-trust VPN for infrastructure access |
| Jamf | Device management and patch compliance (macOS) |
Compliance with these requirements is monitored and enforced. Drata verifies endpoint compliance status continuously. Failure to install required security software is treated as a performance issue.
Security Readiness
Toku maintains security readiness on all employee endpoints. Evidence collection scripts can be executed on employee devices with access to critical infrastructure (GitHub, DigitalOcean, production systems) to support investigation if ever needed. This capability was validated and is maintained as part of Toku's 2026 security hardening program.
