01Our approach
“Privacy focused” is one of TOFO's engineering principles: security and trust are designed in, not added on. Every product in the ecosystem is built on shared, hardened foundations, so an improvement in one place protects all of them.
02Data in transit
Every connection to a TOFO product runs over HTTPS with modern TLS. There are no unencrypted paths to our services.
03Infrastructure
- Modern, globally distributed cloud infrastructure with isolation between services.
- Systems patched and updated continuously — not on a someday list.
- Monitoring and alerting that treats anomalies as incidents until proven otherwise.
04Access control
Inside TOFO, access follows least privilege: people and systems can touch only what their job requires, and sensitive access is logged and reviewed.
05Payments
Payments on TOFO Shop are handled by established payment providers. Full card numbers never touch or rest on TOFO servers.
06Connected accounts
TOFO Automation connects to social platforms through their official token-based APIs. We never see or store your social media passwords, and you can revoke access at any moment from either side.
07Your part
- Use a strong, unique password for your TOFO account.
- Be wary of messages pretending to be TOFO — we will never ask for your password.
- Official TOFO services live on tofo.in and its subdomains. Nowhere else.
08Responsible disclosure
Found a vulnerability? We genuinely want to hear about it. Email contact@tofo.in with “Security” in the subject line, and include enough detail for us to reproduce the issue.
We investigate every report, respond promptly, and ask good-faith researchers to give us reasonable time to fix an issue before disclosing it publicly. We won't pursue action against research conducted in good faith.
09Contact
Security questions or reports: contact@tofo.in — flagged messages are triaged first.
