Last Updated: April 2026
Classification: External / Client-Facing
Contact: [email protected]
No Subcontractors Policy
Toku uses only Toku-employed team members for customer service delivery and operations. Toku does not use subcontractors, offshore development teams, or third-party providers for platform development or customer data handling.
Every person who handles customer data is a vetted, background-checked Toku employee subject to Toku's security policies, training requirements, and access controls.
Background Checks
Toku runs background checks on all employees through Checkr before granting access to customer data or production systems. Checks include:
- Criminal history verification
- Employment history verification
- Education credential verification
- SSN validation
- Credit history (for financial roles) Proof of completed background checks is available under NDA.
Employee Security Requirements
Every Toku employee is required to meet the following security requirements:
- CrowdStrike Falcon installed and active on their work device for endpoint detection and response.
- Tailscale installed and active for zero-trust VPN access to production infrastructure.
- Jamf enrollment for device management and patch compliance (macOS).
- Okta SSO for centralized authentication across all internal systems.
- MFA enforced on all Toku accounts and critical systems (1Password for shared credentials).
- Drata compliance verified, including hard drive encryption, screen lock, and endpoint protection status.
- Annual compliance recertification completed through Drata. Compliance with these requirements is continuously monitored through Drata. Non-compliance is treated as a performance issue.
Principle of Least Privilege
All internal access follows the principle of least privilege. Employees are granted access only to the systems and data required for their specific role. Access requests go through a centralized identity management platform with manager and system owner approval. Access is automatically provisioned upon approval and revoked upon role change or separation.
Internal Access Logging
All Toku employee access to production data is logged. Authentication events, data access events, administrative actions, and configuration changes are captured with timestamps, source IPs, and user identifiers. Logs are retained for compliance and audit purposes.
Separation on Termination
When an employee leaves Toku, all administrative and system access is revoked immediately. Revocation is automated through the identity management platform and verified during offboarding.
Third-Party Vendor Assessment
Toku evaluates the security posture of third-party vendors and service providers that access customer data or integrate with Toku's platform. Assessments cover security certifications, data handling practices, and compliance posture.
Key infrastructure and integration partners maintain their own independent security certifications:
| Vendor | Role | Certifications |
|---|---|---|
| DigitalOcean | Cloud infrastructure | SOC 2 Type II, SOC 3 Type II |
| Cloudflare | WAF, DDoS protection | SOC 2 Type II, ISO 27001 |
| CrowdStrike | Endpoint protection (EDR) | SOC 2 Type II |
| PropelAuth | Authentication and SSO | SOC 2 Type II |
| Fireblocks | Custody integration | SOC 2 Type II |
| Coinbase Prime | Custody integration | SOC 2 Type II |
