Security
Last updated: September 8, 2026
At Tolarai.com, security is foundational to everything we do. We implement industry-standard technical, organizational, and physical security measures designed to protect your data and your members' data against unauthorized access, alteration, disclosure, or destruction.
1. Data Encryption
- Data in transit: All communication between clients and our servers is encrypted using TLS 1.2+ (Transport Layer Security). We enforce HTTPS across all endpoints and redirect all HTTP traffic to HTTPS.
- Data at rest: Sensitive data stored in our databases is encrypted at rest using AES-256 encryption, the industry standard for data protection.
- Key management: Encryption keys are managed through our cloud provider's key management service, with regular key rotation and strict access controls.
2. Access Control
- Role-based access control (RBAC): Every organization has granular control over who can view, create, update, and delete records. Permissions are assigned per role and scoped per tenant.
- Least-privilege principle: Internal staff access is restricted to the minimum level necessary to perform their duties. No staff member has unrestricted access to customer data.
- Multi-tenant isolation: Row-Level Security (RLS) enforces strict tenant isolation at the database level, ensuring no organization can access another organization's data.
- IP allowlisting: Enterprise customers can restrict API access to approved IP addresses and CIDR ranges for additional security.
- Single Sign-On (SSO): Support for Google, Microsoft, and other SSO providers for secure, passwordless authentication.
3. Audit Logging & Monitoring
- Comprehensive audit trail: Every create, update, delete, and status change across all platform entities is logged with user identity, timestamp, IP address, and before/after values.
- Security event tracking: Login attempts, permission changes, role escalations, and suspicious activities are tracked as security events with severity levels.
- Real-time monitoring: Automated alerts are triggered for anomalous behavior, including failed login spikes, unusual data exports, and privilege escalation attempts.
- Log retention: Audit logs are retained for a minimum of 12 months. Security event logs are retained for 24 months.
4. Infrastructure Security
- Cloud hosting: Our infrastructure is hosted on reputable cloud providers with SOC 2 Type II, ISO 27001, and PCI DSS compliance certifications.
- Network security: Firewalls, network segmentation, and DDoS protection are deployed at the infrastructure level.
- Regular patching: Our systems are continuously updated with the latest security patches. Critical vulnerabilities are addressed within 24 hours of disclosure.
- Backup & disaster recovery: Data is backed up daily with encrypted backups stored in multiple geographic regions. Our disaster recovery plan targets a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour.
5. Vulnerability Management
- Regular security assessments: We conduct regular vulnerability scanning and penetration testing, both internally and through third-party security firms.
- Secure development practices: Our development follows OWASP best practices, including code reviews, automated security scanning in CI/CD pipelines, and dependency vulnerability monitoring.
- Bug bounty program: We welcome responsible disclosure of security vulnerabilities. Report findings to security@tolarai.com.
6. Data Privacy & Compliance
- GDPR compliance: We comply with the General Data Protection Regulation (GDPR). See our GDPR page for details on data subject rights and our compliance approach.
- Data processing agreements: We provide DPAs for enterprise customers and maintain written agreements with all subprocessors requiring confidentiality and data protection.
- Data export & deletion: Organizations can export all member data at any time. GDPR-compliant deletion (right to be forgotten) is available through the platform.
- Privacy policy: Our Privacy Policy details how we collect, use, and protect personal data.
7. Incident Response
- Incident response plan: We maintain a documented incident response plan with defined roles, escalation procedures, and communication protocols.
- Breach notification: In the event of a data breach affecting personal data, we notify affected users and relevant authorities as required by applicable law, typically within 72 hours of becoming aware of the breach.
- Post-incident review: All security incidents are followed by a root cause analysis and corrective action plan to prevent recurrence.
8. Business Continuity
- High availability: Our infrastructure is designed for 99.9% uptime with redundant systems and automatic failover.
- Geographic redundancy: Critical services are deployed across multiple availability zones to ensure continuity in the event of a regional outage.
- Regular testing: Our disaster recovery and business continuity plans are tested regularly to ensure effectiveness.
9. Subprocessor Management
We engage trusted third-party vendors and subprocessors (e.g., cloud hosting providers, payment processors, email delivery services) who process data on our behalf. All subprocessors are vetted for security and privacy practices, and are bound by written agreements requiring confidentiality and data protection. A current list of subprocessors is available upon request.
10. Contact Us
If you have any questions about our security practices, or if you believe you have discovered a security vulnerability, please contact our security team:
- Email: security@tolarai.com
- PGP key: Available upon request
We take all security reports seriously and will respond promptly to investigate and address any concerns.