Tolis

Security and privacy

Tolis will operate inside the systems companies depend on. Strong access controls, private data handling, and verifiable execution are requirements, not optional features.

HIPAA-readyBAA includedPIPEDAGDPRZero data retentionSOC 2 program

Protection built into the platform

Least-privilege access

Every connection receives only the permissions required for its workflow.

Tenant isolation

Customer workloads, credentials, and execution data remain separated by design.

Encryption by default

Data is encrypted in transit and at rest across the Tolis platform.

Complete audit history

Administrative changes, connection activity, and workflow runs are recorded and reviewable.

Enterprise customers will be able to configure retention or use zero data retention for eligible workloads. Customer data will never be sold, used for behavioural advertising, or used to train shared models.

The standard we are building toward

The platform is being designed around the privacy, contractual, and audit requirements enterprise teams expect at launch.

HIPAA-ready

Eligible workloads will include the required safeguards and a Business Associate Agreement at no additional cost.

PIPEDA

Canadian privacy requirements will be supported through clear processing terms, access controls, and customer data rights.

GDPR

Data processing terms, deletion, export, retention, and transfer controls will be built into the platform.

SOC 2 Type II

Our control environment is being designed for independent SOC 2 Type II examination, with reports published when completed.

Questions and requests

If your company has specific compliance, security, data residency, or deployment requirements, please reach out. We will consider those requirements as we define the platform and its launch controls.