Snapshot 54691
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security at Tolstoy Commerce brands trust Tolstoy with their content, product catalogs, and customer-facing experiences. Protecting that trust is an engineering discipline here: independent audits, encryption everywhere, least-privilege access, and verified release processes. Independent audits and testing SOC 2 Type II audits by an independent auditor, on a continuous annual cycle. Reports available on request under NDA. Independent third-party penetration tests of the platform. Continuous vulnerability scanning across application dependencies and cloud infrastructure. Infrastructure Hosted in the United States on enterprise-grade cloud infrastructure, with isolated production and development environments. Encryption in transit (TLS 1.2+) and at rest (AES-256) for data and backups. Automated, encrypted backups with point-in-time recovery for critical data stores. Centralized audit logging and continuous infrastructure monitoring with alerting. Access control Multi-factor authentication and least-privilege, role-based access for internal systems. Two-factor authentication enforced on source control. Protected release branches: mandatory peer code review, required CI checks, force pushes blocked. Data protection Data processing agreements (DPAs) available for customers. Sub-processor list available on request. Data subject requests — access, correction, deletion — honored per our privacy policy. Customer data is deleted on request, in line with our privacy policy. Responsible disclosure If you believe you have found a security vulnerability in a Tolstoy product or service, email privacy@gotolstoy.com. Include what you found and how to reproduce it; we review every report. We appreciate good-faith security research and will work with you on remediation and disclosure. Security FAQ Is Tolstoy SOC 2 compliant? Yes. Tolstoy is audited against SOC 2 Type II by an independent auditor, and audits run on a continuous annual cycle. The most recent report is available on request under NDA — contact us to receive a copy. Where is Tolstoy data hosted? Tolstoy runs on enterprise-grade cloud infrastructure in the United States. Production and development environments are isolated from each other, and infrastructure changes go through peer-reviewed, CI-verified deployment pipelines. How is my data encrypted? Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, using centrally managed encryption keys. Backups are encrypted with the same key infrastructure. Can I get a DPA or your sub-processor list? Yes. Data processing agreements and our current sub-processor list are available on request — contact our team and we will share them as part of your security review. How do I report a security vulnerability? Email privacy@gotolstoy.com with the details and steps to reproduce. We review every report and respond as quickly as we can. Running a security review? We are happy to walk your team through our SOC 2 report, DPA, and sub-processor list. Read our privacy policy and trust & safety commitments, or talk to our team to get the documents.