๐
Toku Security Center
This page documents Toku's security controls, infrastructure, and compliance posture. It is intended for clients, prospective clients, and security reviewers.
Last Updated: April 2026 | Contact: [email protected]
Toku processes sensitive employee data, compensation records, and digital asset transactions across 100+ countries. This Security Center covers how we protect that data at every layer: infrastructure, network, application, endpoint, and operational process.
Table of Contents
I. Platform Security
Infrastructure & Network Security: Hosting, WAF, VPN, network segmentation
Endpoint Security: EDR, device management, endpoint monitoring
Application Security & Secure Development: Code review, vulnerability scanning, change management II. Data Security
Data Protection & Encryption: Encryption standards, data inventory, retention
API & Integration Security: OAuth 2.0, least-privilege scoping, IP whitelisting
Cryptocurrency & Custody Security: Non-custody model, transaction flow, wallet security III. Access & Identity
Authentication & Access Control: SSO, MFA, RBAC, SCIM, session management
Vendor & Personnel Security: Background checks, no-subcontractor policy, least privilege IV. Resilience & Compliance
Incident Response & Management: Severity classification, roles, tabletop exercises
Business Continuity & Disaster Recovery: BCP, DRP, annual testing, backups
Compliance & Certifications: SOC 2 Type II, GDPR, CCPA/CPRA, Drata V. Security Investments
2026 Security Hardening Program: Assessments, deployments, posture improvements
I. Platform Security
๐ Infrastructure & Network Security Toku's production environment runs on DigitalOcean in US data center regions (SOC 2 Type II certified). All inbound traffic passes through Cloudflare WAF for DDoS mitigation, bot detection, and request filtering. Internal access to production requires Tailscale, a zero-trust VPN mesh on WireGuard. Production, staging, and development environments are fully network-isolated.
๐ป Endpoint Security CrowdStrike Falcon is deployed on every Toku employee device for threat detection and EDR. Jamf enforces device management, OS patching, and security configuration on all macOS devices. Tailscale VPN and Pathfinder monitoring agents are required. Endpoint compliance is actively enforced.
๐ก๏ธ Application Security & Secure Development All code changes require mandatory peer review before reaching production. Dependabot runs continuous vulnerability scanning against the codebase. Quantstamp conducted an independent security audit in 2026. Quarterly penetration testing validates security posture. Drata provides continuous compliance automation and evidence collection for SOC 2. PostHog monitors platform behavior with PII excluded.
II. Data Security
๐ Data Protection & Encryption All data at rest is encrypted with AES-256. All data in transit is encrypted with TLS 1.3 (minimum TLS 1.2). Encryption keys are managed through the cloud provider's key management service with automatic rotation. Toku collects only the data necessary for payroll processing and does not store Social Security numbers, bank account numbers, private keys, or biometric data.
๐ API & Integration Security Toku integrates with HRIS platforms (Workday, ADP, UKG, Rippling, Gusto), payroll systems, and custody providers (Fireblocks, Coinbase Prime, Safe, Squads, Bridge, Anchorage) using OAuth 2.0 with least-privilege scoping. Custody integrations use IP whitelisting to restrict API access to known Toku infrastructure addresses. Clients control provisioning and revocation of all API credentials.
โ๏ธ Cryptocurrency & Custody Security Toku operates on a strict non-custody model. Toku calculates payroll settlements and proposes transactions. Clients approve and execute through their custody provider's multi-signature or policy-engine approval. Toku never holds private keys, funds, or signing authority. This separation is enforced at the infrastructure level.
III. Access & Identity
๐ Authentication & Access Control Toku supports SAML 2.0 SSO with any compliant identity provider (Okta, Azure AD, Google Workspace, OneLogin) at no additional cost. Internally, Toku uses Okta SSO for centralized admin access. MFA is enforced using TOTP-based verification. SCIM 2.0 enables automated user provisioning and deprovisioning. Role-based access control (RBAC) ensures users can only access data for their own organization. Drata continuously monitors employee compliance status.
๐ฅ Vendor & Personnel Security All employees pass background checks through Checkr before receiving access to production systems. No subcontractors, offshore teams, or third-party providers handle customer data. CrowdStrike, Tailscale, Jamf, and Okta SSO are required on every device, with compliance monitored through Drata.
IV. Resilience & Compliance
๐จ Incident Response & Management Toku maintains a formal Incident Management Response Plan with severity levels SEV-1 through SEV-4, assigned roles (Incident Commander, Technical Lead, Communications Lead, Legal Advisor), defined communication protocols, and blameless postmortems. Quarterly tabletop exercises cover scenarios including payment rail failures, API outages, and security events.
๐ Business Continuity & Disaster Recovery Business Continuity and Disaster Recovery Plans are tested annually. Backups are encrypted with AES-256 using separate key management. Recovery procedures are validated through tabletop exercises, structured walkthroughs, and simulation tests.
โ Compliance & Certifications Toku has completed a SOC 2 Type II audit, with the renewed report expected in May 2026. Drata provides continuous compliance automation and evidence collection. GDPR compliance is supported with Data Processing Addendums for EU/UK employees. CCPA/CPRA compliance is maintained for California residents. Quarterly penetration testing is conducted by third-party firms with reports available upon request under NDA.
V. Security Investments
๐ 2026 Security Hardening Program In 2026, Toku deployed CrowdStrike Falcon and Tailscale VPN across all endpoints, implemented Fireblocks IP whitelisting, completed a full credential rotation, enhanced database audit logging, and engaged Sygnia and Quantstamp for independent security assessments. Full details are in this subpage.
Quick Reference
| Area | Detail |
|---|---|
| Hosting | DigitalOcean, United States data center regions |
| Encryption at Rest | AES-256 |
| Encryption in Transit | TLS 1.3 (minimum TLS 1.2) |
| Endpoint Protection | CrowdStrike Falcon EDR |
| Device Management | Jamf (macOS) |
| WAF and DDoS | Cloudflare |
| VPN | Tailscale (WireGuard-based, zero-trust) |
| Authentication | PropelAuth with SAML 2.0 SSO |
| MFA | TOTP-based, enforced for all users |
| Compliance | SOC 2 Type II (renewal expected May 2026) |
| Compliance Automation | Drata (continuous control monitoring) |
| Internal SSO | Okta |
| Security Assessments | Quantstamp (2026), Sygnia (2026) |
| Penetration Testing | Quarterly, by third-party firms |
| Monitoring | Sentry, New Relic, PostHog (PII excluded) |
| Vulnerability Scanning | Dependabot (continuous) |
| Background Checks | Checkr (all employees) |
| Subcontractors | None. All operations handled by Toku employees. |
Related Resources
- Stablecoin Payroll: Data Handling and Security - Full data handling documentation for Stablecoin Payroll
- Security and Compliance FAQ - Frequently asked questions on security, compliance, and data practices
- How To Submit a Data Control Request - GDPR and CCPA/CPRA data subject request instructions
Contact
For security inquiries, vendor risk assessments, or to request documentation under NDA:
Email: [email protected]
General Support: [email protected]
Website: www.toku.com
