LegalSOC 2
← BackSOC 2
Certification: SOC 2 Type II — in progressStatus: Not yet certifiedContact: security@tokenistt.com
Core Privacy Principle
Tokenistt has not completed a SOC 2 Type II audit yet. We're building toward it and will publish the report here once an independent auditor has certified us — until then, treat any compliance claim beyond what's on this page as aspirational, not certified.
What we do today
- –TLS 1.3 for all data in transit between the MCP server and our analytics endpoint
- –AES-256 encryption for metadata at rest
- –The local MCP server — which processes your prompt content — runs entirely on your machine; prompt content never reaches our servers
- –Access to production systems limited to founders; credentials rotated on a regular basis
SOC 2 roadmap
- –Security (CC): access controls, encryption, vulnerability management — target for Team plan launch
- –Availability (A): uptime SLA, incident response procedures — planned
- –Confidentiality (C): data classification, DLP controls — planned
- –Processing Integrity (PI): input validation, anomaly detection, audit trails — planned
- –Privacy (P): GDPR/CCPA alignment — covered today in our Privacy Policy
What is explicitly out of scope, by design
- –The local Tokenistt MCP server process running on your machine — it never sends prompt content to our infrastructure
- –Your prompt content, source code, LLM inputs and outputs — these never reach our servers
- –Third-party LLM provider infrastructure (Anthropic, OpenAI, etc.)
Questions
If you need specifics on our current security posture before a SOC 2 report exists, contact security@tokenistt.com — we'll answer directly rather than point you at a badge we don't have yet.