Security Policy

At TokPros LLC, security is a foundational part of our platform design and daily operations. We follow industry best practices to ensure the confidentiality, integrity, and availability of user data.

1. Infrastructure & Data Hosting

All infrastructure is hosted on Amazon Web Services (AWS) within private VPCs. No databases or backend services are exposed to the public internet. Only AWS Lambda functions with strict IAM permissions can access protected backend resources.

2. Encryption Standards

All traffic is encrypted in transit using TLS 1.2+. Sensitive data such as passwords, tokens, and affiliate credentials are encrypted at rest using AES-256 or equivalent standards. We enforce HTTPS across all environments.

3. Authentication & Access Control

All users authenticate via secure credentials, and sensitive actions require verified accounts. Internal systems use role-based access control (RBAC) to restrict employee access to production and customer data.

4. Secure Development Practices

All code is version-controlled and peer-reviewed before deployment. We run automated dependency scans and static analysis tools to prevent known vulnerabilities. Secrets are stored in environment variables and never hardcoded in source code.

5. Monitoring & Incident Response

We continuously monitor systems for anomalies, failed logins, and unauthorized access. If a security event is detected, we follow our incident response plan, including escalation, containment, and user notification when required by law.

6. Vendor Security

All third-party vendors (e.g., Stripe, MongoDB Atlas, AWS) are vetted for SOC 2, ISO 27001, or equivalent compliance. Data shared with vendors is minimized and always encrypted during transfer.

7. Responsible Disclosure

If you identify a vulnerability, please report it to us at [email protected]. We appreciate all responsible disclosures and work to resolve verified issues promptly and transparently.

8. Access Control & Least Privilege

Access to internal systems and sensitive data is based on least privilege principles. Employees receive only the permissions necessary for their roles, and all access is logged, reviewed, and revoked when no longer required.

9. Data Classification & Encryption

User data is classified by sensitivity and protected accordingly. Sensitive information is encrypted at rest (AES-256) and in transit (TLS 1.2+). Credentials, API tokens, and other secrets are stored securely and never logged.

10. Incident Response

TokPros maintains a comprehensive incident response policy defining roles, escalation steps, and communication channels. Our team is trained to act swiftly to mitigate risks and maintain system integrity during security incidents.

11. Threat & Vulnerability Management

We conduct regular vulnerability scans using industry-standard tools like OWASP ZAP. Discovered threats are triaged by severity and resolved promptly. Our CI/CD pipeline includes automated security linting and dependency checks.

12. Endpoint Protection & Operational Baseline

Developer and admin endpoints are protected with up-to-date antivirus and endpoint security tools. All devices enforce disk encryption, automatic lock, and MFA to prevent unauthorized access.

13. Personal Data Handling & Privacy

Our data handling practices comply with our Privacy Policyand applicable regulations. We minimize the collection of personal data and restrict access based on operational necessity. Regular reviews ensure alignment with security best practices.

Thank you for helping us keep TokPros secure.