Security at Tolstoy

Commerce brands trust Tolstoy with their content, product catalogs, and customer-facing experiences. Protecting that trust is an engineering discipline here: independent audits, encryption everywhere, least-privilege access, and verified release processes.

Independent audits and testing

  • SOC 2 Type II audits by an independent auditor, on a continuous annual cycle. Reports available on request under NDA.
  • Independent third-party penetration tests of the platform.
  • Continuous vulnerability scanning across application dependencies and cloud infrastructure.

Infrastructure

  • Hosted in the United States on enterprise-grade cloud infrastructure, with isolated production and development environments.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for data and backups.
  • Automated, encrypted backups with point-in-time recovery for critical data stores.
  • Centralized audit logging and continuous infrastructure monitoring with alerting.

Access control

  • Multi-factor authentication and least-privilege, role-based access for internal systems.
  • Two-factor authentication enforced on source control.
  • Protected release branches: mandatory peer code review, required CI checks, force pushes blocked.

Data protection

  • Data processing agreements (DPAs) available for customers.
  • Sub-processor list available on request.
  • Data subject requests — access, correction, deletion — honored per our privacy policy.
  • Customer data is deleted on request, in line with our privacy policy.

Responsible disclosure

If you believe you have found a security vulnerability in a Tolstoy product or service, email privacy@gotolstoy.com. Include what you found and how to reproduce it; we review every report. We appreciate good-faith security research and will work with you on remediation and disclosure.

Security FAQ

Is Tolstoy SOC 2 compliant?

Yes. Tolstoy is audited against SOC 2 Type II by an independent auditor, and audits run on a continuous annual cycle. The most recent report is available on request under NDA — contact us to receive a copy.

Where is Tolstoy data hosted?

Tolstoy runs on enterprise-grade cloud infrastructure in the United States. Production and development environments are isolated from each other, and infrastructure changes go through peer-reviewed, CI-verified deployment pipelines.

How is my data encrypted?

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, using centrally managed encryption keys. Backups are encrypted with the same key infrastructure.

Can I get a DPA or your sub-processor list?

Yes. Data processing agreements and our current sub-processor list are available on request — contact our team and we will share them as part of your security review.

How do I report a security vulnerability?

Email privacy@gotolstoy.com with the details and steps to reproduce. We review every report and respond as quickly as we can.

Running a security review?

We are happy to walk your team through our SOC 2 report, DPA, and sub-processor list. Read our privacy policy and trust & safety commitments, or talk to our team to get the documents.