Trust Center
Security you can verify, governance you can prove.
Tokoaido deploys AI agents that act on real systems, so security, privacy and governance are the substrate, not an add-on. Here is exactly how we protect your data and keep autonomy accountable.
Security architecture
Defense in depth, from identity to the audit log.
- SAML / OIDC single sign-on
- SCIM user provisioning
- RBAC: Owner / Admin / Operator / Viewer
- Least-privilege, tool-scoped agents
- Encryption in transit (TLS) and at rest
- Strict multi-tenant isolation
- Session tokens in HttpOnly cookies
- Secrets held in a vault abstraction
- Immutable, hash-chained audit trail
- Tamper-evident provenance on every decision
- Full lineage: source → model → action
- Exportable evidence for auditors
- Human-in-the-loop, risk-tiered approvals
- Earned, progressive agent autonomy
- Continuous evaluation & regression gates
- Guardrail synthesis from violations
- Your systems remain the system of record
- EU processing, or self-host in your own region
- Configurable retention
- Data-subject request support
- Managed SaaS or your own VPC
- On-prem via Docker / Kubernetes
- Air-gapped-capable
- No inbound access to your OT required
The safety boundary
A line agents cannot cross, by construction.
For operational technology, safety is not a policy toggle. Writes route through MES/SCADA with human approval; a direct PLC write, or any interaction with a Safety Instrumented System, is blocked in the architecture itself. No prompt, configuration, or model can override it.
Compliance
Controls mapped to the frameworks your auditors use.
Tokoaido is at design-partner stage: formal certifications are in progress, and the platform's architecture is built to meet them. We'll share the current attestation status and evidence under NDA.
Deployment
Deploy where your data must live.
Sub-processors
Who touches your data.
Named rather than categorised, because a privacy review needs the names. The full list adds what personal data each can receive, which are optional, and where a signed DPA is still outstanding. You get 30 days' notice before we add or replace one.
Documents & requests
Get what your review needs.
Operations X-Ray
Bring us your security review.
We'll walk your team through the architecture, controls, and deployment model, and answer the hard questions.