Security and privacy
Tolis will operate inside the systems companies depend on. Strong access controls, private data handling, and verifiable execution are requirements, not optional features.
Protection built into the platform
Least-privilege access
Every connection receives only the permissions required for its workflow.
Tenant isolation
Customer workloads, credentials, and execution data remain separated by design.
Encryption by default
Data is encrypted in transit and at rest across the Tolis platform.
Complete audit history
Administrative changes, connection activity, and workflow runs are recorded and reviewable.
Enterprise customers will be able to configure retention or use zero data retention for eligible workloads. Customer data will never be sold, used for behavioural advertising, or used to train shared models.
The standard we are building toward
The platform is being designed around the privacy, contractual, and audit requirements enterprise teams expect at launch.
HIPAA-ready
Eligible workloads will include the required safeguards and a Business Associate Agreement at no additional cost.
PIPEDA
Canadian privacy requirements will be supported through clear processing terms, access controls, and customer data rights.
GDPR
Data processing terms, deletion, export, retention, and transfer controls will be built into the platform.
SOC 2 Type II
Our control environment is being designed for independent SOC 2 Type II examination, with reports published when completed.
Questions and requests
If your company has specific compliance, security, data residency, or deployment requirements, please reach out. We will consider those requirements as we define the platform and its launch controls.