Searching knowledge base...
Showing 12 articles
Toku's secure development practices include mandatory code reviews, continuous vulnerability scanning, quarterly security audits, and encrypted secret management.
Toku's infrastructure uses DigitalOcean hosting with SOC 2 certification, Cloudflare WAF/DDoS protection, and Tailscale zero-trust VPN access.
Toku's endpoint security framework includes CrowdStrike Falcon for threat detection, Jamf for device management, and Tailscale for zero-trust network access. All employees must install and maintain these tools to access production systems.
Toku encrypts all data in transit (TLS 1.3) and at rest (AES-256), manages keys securely, and collects only essential payroll data.
Toku's integration architecture connects HRIS, payroll, and custody platforms using OAuth 2.0 authentication with minimal scoped permissions.
Toku operates a non-custody model where clients retain full control of funds and private keys. Learn how Toku calculates payroll, proposes transactions to your custody provider, and confirms settlement - with client approval required at every step.
Learn how Toku secures access through SAML 2.0 SSO, mandatory MFA, automated user provisioning via SCIM, and role-based access control. Includes details on session management, access reviews, and comprehensive authentication logging.
Toku's incident response framework covers detection, triage, and resolution of security and operational incidents with severity levels (SEV-1 to SEV-4) and defined response times.
Toku's vendor and personnel security policies ensure only vetted, background-checked employees handle customer data with strict access controls, endpoint protection, and zero-trust VPN requirements.
Toku's Business Continuity and Disaster Recovery plans ensure payroll processing and system availability during disruptions.
Toku's 2026 security hardening program strengthened infrastructure, endpoints, networks, and applications through endpoint protection deployment, zero-trust VPN access, credential rotation, enhanced monitoring, and third-party security assessments by Sygnia and Quantstamp.
Toku's compliance certifications and security practices, including SOC 2 Type II audit status, GDPR/CCPA/SOX compliance frameworks, continuous penetration testing, and available documentation for clients.