Security at Tolstoy
Commerce brands trust Tolstoy with their content, product catalogs, and customer-facing experiences. Protecting that trust is an engineering discipline here: independent audits, encryption everywhere, least-privilege access, and verified release processes.
Independent audits and testing
- SOC 2 Type II audits by an independent auditor, on a continuous annual cycle. Reports available on request under NDA.
- Independent third-party penetration tests of the platform.
- Continuous vulnerability scanning across application dependencies and cloud infrastructure.
Infrastructure
- Hosted in the United States on enterprise-grade cloud infrastructure, with isolated production and development environments.
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for data and backups.
- Automated, encrypted backups with point-in-time recovery for critical data stores.
- Centralized audit logging and continuous infrastructure monitoring with alerting.
Access control
- Multi-factor authentication and least-privilege, role-based access for internal systems.
- Two-factor authentication enforced on source control.
- Protected release branches: mandatory peer code review, required CI checks, force pushes blocked.
Data protection
- Data processing agreements (DPAs) available for customers.
- Sub-processor list available on request.
- Data subject requests — access, correction, deletion — honored per our privacy policy.
- Customer data is deleted on request, in line with our privacy policy.
Responsible disclosure
If you believe you have found a security vulnerability in a Tolstoy product or service, email privacy@gotolstoy.com. Include what you found and how to reproduce it; we review every report. We appreciate good-faith security research and will work with you on remediation and disclosure.
Security FAQ
Is Tolstoy SOC 2 compliant?
Yes. Tolstoy is audited against SOC 2 Type II by an independent auditor, and audits run on a continuous annual cycle. The most recent report is available on request under NDA — contact us to receive a copy.
Where is Tolstoy data hosted?
Tolstoy runs on enterprise-grade cloud infrastructure in the United States. Production and development environments are isolated from each other, and infrastructure changes go through peer-reviewed, CI-verified deployment pipelines.
How is my data encrypted?
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, using centrally managed encryption keys. Backups are encrypted with the same key infrastructure.
Can I get a DPA or your sub-processor list?
Yes. Data processing agreements and our current sub-processor list are available on request — contact our team and we will share them as part of your security review.
How do I report a security vulnerability?
Email privacy@gotolstoy.com with the details and steps to reproduce. We review every report and respond as quickly as we can.
Running a security review?
We are happy to walk your team through our SOC 2 report, DPA, and sub-processor list. Read our privacy policy and trust & safety commitments, or talk to our team to get the documents.