Toffu AI logo
Live monitoring by Delve
Toffu AI Compliance Report
Toffu AI is in compliance with security best practices, has implemented and is monitoring comprehensive controls, and maintains policies to outline its security procedures.

Compliance Certifications

We maintain the highest industry standards and regularly undergo rigorous third-party audits to ensure compliance.

SOC 2 Type IIIn Observation

SOC 2 Type II

Audited controls for security, availability, and confidentiality trust service principles with an observation period.

In the observation period
SOC 2 Type ICompliant

SOC 2 Type I

Audited controls for security, availability, and confidentiality trust service principles.

Resource Library

Access our security documentation, policies, and compliance reports.

PDF

SOC 2 Type I

Compliance report

PDF

Risk Assessment and Treatment Policy

Policy document

PDF

Personnel Security Policy

Policy document

PDF

Vendor Management Policy

Policy document

PDF

Network Security Policy

Policy document

PDF

Baseline Hardening Policy

Policy document

Security controls

Our comprehensive security program includes controls across multiple domains to protect your data.

Access Control & Authorization

LIVE
Access Control Procedures
Completed
Access Review of Infrastructure
Completed
Employee Handbook
Completed

Data Protection & Privacy

LIVE
Access Restricted to Modify Infrastructure
Completed
Customer Termination
Completed
Customers List
Completed

Governance & Oversight

LIVE
Background Checks
Completed
Customer Support Issue Submission Form
Completed
Customer Support Issues Resolved
Completed

IT & Operational Security

LIVE
Alerts and Remediation
Completed
Application Outages
Completed
Asset Register List
Completed

Risk & Compliance Management

LIVE
Access Control Procedures
Completed
Board Charter
Completed
Board Meeting Minutes
Completed

Security & Incident Management

LIVE
Access Restricted to Modify Infrastructure
Completed
Alerts and Remediation
Completed
Antivirus and Malware Configurations
Completed

Subprocessors directory

We carefully select and monitor all third-party services that process data on our behalf.

Sentry logo

Sentry

Application Performance Monitoring

PostHog logo

PostHog

Analytics & Insights

MongoDB logo

MongoDB

Database Services

Slack logo

Slack

Messaging Services

OpenAI logo

OpenAI

AI & Machine Learning

Mixpanel logo

Mixpanel

Analytics & Insights

Showing 6 of 9 subprocessors

Frequently Asked Questions

Find answers to common questions about our security and compliance practices.

Our Security Commitment

Security Shield

At Toffu AI, security isn't just a feature—it's foundational to everything we build. Our security-first mindset drives our development processes, infrastructure decisions, and organizational policies.

We treat the data entrusted to us—whether from our customers, their end users, or anyone who interacts with our organization—with the utmost care and responsibility. Security is embedded in our DNA, enabling us to deliver innovative solutions without compromising on protection.