Searching knowledge base...
Showing 12 articles
Toku encrypts all data in transit (TLS 1.3) and at rest (AES-256), manages keys securely, and collects only essential payroll data.
Learn how Toku secures user access through SAML 2.0 SSO, mandatory MFA, automated user provisioning via SCIM, and role-based access control. Includes details on session management, access reviews, and comprehensive authentication logging.
Toku's vendor and personnel security policies ensure all customer data is handled only by vetted, background-checked employees with mandatory security tools and access controls.
Toku operates a non-custody model where clients retain full control of funds and private keys.
Toku's incident response framework covers detection, triage, and resolution of security and operational incidents with severity levels (SEV-1 to SEV-4) and defined roles.
Toku's 2026 security hardening program strengthened infrastructure, endpoints, networks, and applications through endpoint protection, zero-trust VPN access, credential rotation, and third-party audits.
Toku's Business Continuity and Disaster Recovery plans ensure payroll and payment processing continuity during disruptions through annual testing, encrypted data backups, and documented recovery procedures for all production systems and third-party integrations.
Toku's compliance certifications and security practices, including SOC 2 Type II audit status, GDPR/CCPA/SOX compliance frameworks, quarterly penetration testing, and documentation available upon request.
Toku's infrastructure uses DigitalOcean hosting with SOC 2 certification, Cloudflare WAF protection, and zero-trust VPN access via Tailscale.
Toku's endpoint security framework includes CrowdStrike Falcon for threat detection, Tailscale for zero-trust VPN access, and Jamf for device management.
Learn how Toku implements security throughout its development lifecycle, including secure code reviews, vulnerability management, third-party audits, and compliance monitoring.
Toku secures integrations with HRIS, payroll, and custody platforms using OAuth 2.0 authentication, encrypted data flows, and IP whitelisting.