Security & Compliance
The intelligence platform built for the security posture institutional clients require.

SOC 2 Type II
Independently attested, no exceptions noted.
ISO 27001:2022
Certified across the platform’s assets and processes.
GDPR
EU data held on dedicated infrastructure in Dublin.
Controls
Our security, in detail.
Full documentation, subprocessor list, and current attestations are available in the security portal.
Single tenant architecture
The platform is designed around tenant isolation and encryption.
Encryption
All proprietary data from VDRs or internal drives are encrypted at Rest.
Model data use
We adhere to Zero Data Retention policies and never use client data to train AI models.
Access control
Strict role-based access control with two-factor authentication for every user.
Continuous Testing
Continuous vulnerability scanning and regular third-party penetration testing.
Governance Programme
A comprehensive Information Security Program governs controls, review, and incident response.
Data residency
Data stays within the region you operate.
ToltIQ supports regional data governance, keeping infrastructure local to where you do business.
US
US client data resides in the USA
All data for US-based clients is held in the United States under a comprehensive Information Security Program.
europe
EU client data resides in Dublin
European clients are served from dedicated AWS infrastructure in Dublin, Ireland, so data can be stored locally to streamline GDPR compliance efforts.
User-level privacy
Layered access control inside the platform.
Two-factor authentication
Protect every sign-in with two-factor authentication.
Role-based access
Define User and Admin permissions across the platform.
Document permissions
Control document management across standard and Vault Deals.
Workspace visibility
Choose Firm-Wide or Private access for each workspace.