Security

Built to be trusted with your work.

A plain summary of how Tonioz stores, protects and recovers your data. This page is a working draft while our formal program is finalised.

Data

Encrypted end to end

Traffic runs over TLS 1.3 and everything at rest is encrypted with AES 256 managed keys.

In place

Access

Least privilege by default

Row level policies scope every record to its owner, so a workspace only ever reads its own data.

In place

Identity

Modern authentication

Email, Google sign in and session rotation, with optional two factor for workspace owners.

In place

Resilience

Backups and rollback

Point in time recovery on the database and one click rollback for any published site.

In place

Compliance

SOC 2 Type II

Controls are documented and observation is underway. Reports available under NDA once complete.

In progress

Disclosure

Report a vulnerability

Send findings to security@tonioz.com. We acknowledge within one business day and never pursue good faith research.

Always open