Trust Center

Security you can verify, governance you can prove.

Tokoaido deploys AI agents that act on real systems, so security, privacy and governance are the substrate, not an add-on. Here is exactly how we protect your data and keep autonomy accountable.

SOC 2 Type IIIn progressISO 27001AlignedGDPR / UK GDPRSupportedEU AI ActReadyHIPAAReadyNIST AI RMFAligned
Security architecture

Defense in depth, from identity to the audit log.

Identity & access
  • SAML / OIDC single sign-on
  • SCIM user provisioning
  • RBAC: Owner / Admin / Operator / Viewer
  • Least-privilege, tool-scoped agents
Data protection
  • Encryption in transit (TLS) and at rest
  • Strict multi-tenant isolation
  • Session tokens in HttpOnly cookies
  • Secrets held in a vault abstraction
Auditability
  • Immutable, hash-chained audit trail
  • Tamper-evident provenance on every decision
  • Full lineage: source → model → action
  • Exportable evidence for auditors
AI governance
  • Human-in-the-loop, risk-tiered approvals
  • Earned, progressive agent autonomy
  • Continuous evaluation & regression gates
  • Guardrail synthesis from violations
Data & privacy
  • Your systems remain the system of record
  • Data residency by region
  • Configurable retention
  • Data-subject request support
Deployment isolation
  • Managed SaaS or your own VPC
  • On-prem via Docker / Kubernetes
  • Air-gapped-capable
  • No inbound access to your OT required
The safety boundary

A line agents cannot cross, by construction.

For operational technology, safety is not a policy toggle. Writes route through MES/SCADA with human approval; a direct PLC write, or any interaction with a Safety Instrumented System, is blocked in the architecture itself. No prompt, configuration, or model can override it.

Allowed
Read telemetry · propose actions · write via MES/SCADA with approval
Blocked
Direct PLC writes
Blocked
Any Safety Instrumented System (SIS) interaction
Compliance

Controls mapped to the frameworks your auditors use.

SOC 2 Type II
In progress
Controls implemented; audit underway.
ISO 27001
Aligned
ISMS architecture aligned to the standard.
GDPR / UK GDPR
Supported
Data minimization, DPA, subject rights.
EU AI Act
Ready
Controls mapped; transparency + risk tiering.
HIPAA
Ready
PHI handling + BAA available for eligible deployments.
NIST AI RMF
Aligned
Govern / Map / Measure / Manage practices.

Tokoaido is at design-partner stage: formal certifications are in progress, and the platform's architecture is built to meet them. We'll share the current attestation status and evidence under NDA.

Deployment

Deploy where your data must live.

SaaS
Managed multi-tenant
Private cloud
Your AWS / Azure / GCP VPC
Self-hosted
Docker / Kubernetes, on-prem
Air-gapped
Isolated / regulated networks
Sub-processors

Who touches your data.

CategoryPurpose
Cloud infrastructureHosting & compute (customer-selectable region)
LLM provider(s)Model inference (data-minimized, disclosed per contract)

The definitive, named sub-processor list is provided with your DPA and kept current; you're notified of material changes.

Bring us your security review.

We'll walk your team through the architecture, controls, and deployment model, and answer the hard questions.