Vendor & Personnel Security

InfoTable of Contentsclock icon2 MIN READ·calendar iconUPDATED APR 20, 2026

Toku's vendor and personnel security policies ensure only vetted, background-checked employees handle customer data with strict access controls, endpoint protection, and zero-trust VPN requirements.

Last Updated: April 2026

Classification: External / Client-Facing

Contact: [email protected]


No Subcontractors Policy

Toku uses only Toku-employed team members for customer service delivery and operations. Toku does not use subcontractors, offshore development teams, or third-party providers for platform development or customer data handling.

Every person who handles customer data is a vetted, background-checked Toku employee subject to Toku's security policies, training requirements, and access controls.


Background Checks

Toku runs background checks on all employees through Checkr before granting access to customer data or production systems. Checks include:

  • Criminal history verification
  • Employment history verification
  • Education credential verification
  • SSN validation
  • Credit history (for financial roles) Proof of completed background checks is available under NDA.

Employee Security Requirements

Every Toku employee is required to meet the following security requirements:

  • CrowdStrike Falcon installed and active on their work device for endpoint detection and response.
  • Tailscale installed and active for zero-trust VPN access to production infrastructure.
  • Jamf enrollment for device management and patch compliance (macOS).
  • Okta SSO for centralized authentication across all internal systems.
  • MFA enforced on all Toku accounts and critical systems (1Password for shared credentials).
  • Drata compliance verified, including hard drive encryption, screen lock, and endpoint protection status.
  • Annual compliance recertification completed through Drata. Compliance with these requirements is continuously monitored through Drata. Non-compliance is treated as a performance issue.

Principle of Least Privilege

All internal access follows the principle of least privilege. Employees are granted access only to the systems and data required for their specific role. Access requests go through a centralized identity management platform with manager and system owner approval. Access is automatically provisioned upon approval and revoked upon role change or separation.


Internal Access Logging

All Toku employee access to production data is logged. Authentication events, data access events, administrative actions, and configuration changes are captured with timestamps, source IPs, and user identifiers. Logs are retained for compliance and audit purposes.


Separation on Termination

When an employee leaves Toku, all administrative and system access is revoked immediately. Revocation is automated through the identity management platform and verified during offboarding.


Third-Party Vendor Assessment

Toku evaluates the security posture of third-party vendors and service providers that access customer data or integrate with Toku's platform. Assessments cover security certifications, data handling practices, and compliance posture.

Key infrastructure and integration partners maintain their own independent security certifications:

Vendor Role Certifications
DigitalOcean Cloud infrastructure SOC 2 Type II, SOC 3 Type II
Cloudflare WAF, DDoS protection SOC 2 Type II, ISO 27001
CrowdStrike Endpoint protection (EDR) SOC 2 Type II
PropelAuth Authentication and SSO SOC 2 Type II
Fireblocks Custody integration SOC 2 Type II
Coinbase Prime Custody integration SOC 2 Type II

Was this article helpful?

Can't find what you're looking for?

The Toku AI assistant has read every article. A human specialist reviews every submission.