Information security policy
Last updated 19 August 2026 · Version 1.0
Policy owner: Chief Executive Officer
Review frequency: At least annually and upon material changes to Tovi's systems, products, or security risk profile.
Purpose
Tovi is committed to protecting the confidentiality, integrity, and availability of information entrusted to the company.
This Information Security Policy establishes the administrative, technical, and organizational safeguards Tovi uses to identify, mitigate, and monitor information security risks relevant to its operations.
The policy is designed to be proportionate to Tovi's size, stage of development, technology environment, and the sensitivity of the information processed by the company.
Scope
This policy applies to:
- Tovi employees, contractors, officers, and other authorized personnel
- Company systems, applications, devices, and cloud infrastructure
- Customer and applicant information
- Financial account and transaction information
- Authentication credentials and access tokens
- Information received through third party providers, including financial data providers
- Vendors and service providers that process Tovi information
Security Governance and Risk Management
Tovi assigns responsibility for information security oversight to company leadership.
Tovi periodically evaluates information security risks associated with its systems, data, vendors, and business processes.
Identified risks are evaluated based on their likelihood and potential impact. Appropriate safeguards are implemented based on the sensitivity of the data involved and the severity of the identified risk.
Security risks and controls are reviewed when Tovi introduces material new products, integrations, systems, or vendors.
Access Control
Access to Tovi systems and information is granted according to the principle of least privilege.
Personnel are provided access only to systems and information reasonably necessary to perform their responsibilities.
Tovi requires:
- Unique user accounts for personnel
- Strong passwords
- Multi factor authentication where supported, particularly for systems containing sensitive information
- Prompt removal or modification of access when a person's responsibilities change or their relationship with Tovi ends
- Periodic review of access to sensitive systems
Shared credentials should be avoided wherever technically feasible.
Authentication and Credential Security
Passwords, API credentials, access tokens, private keys, and similar authentication information must be protected against unauthorized disclosure.
Sensitive credentials must not be stored in publicly accessible repositories or transmitted through insecure communication channels.
Production credentials should be stored using secure credential or secrets management mechanisms provided by Tovi's infrastructure providers where reasonably available.
Data Protection
Tovi limits the collection and retention of sensitive information to information reasonably necessary to provide its services, evaluate eligibility, prevent fraud, comply with legal obligations, and operate the business.
Sensitive information must be protected during transmission using industry standard encrypted communication protocols where supported.
Tovi uses reputable infrastructure and service providers that provide appropriate security controls for stored information.
Access to sensitive customer information is restricted to authorized personnel and systems with a legitimate business need.
Financial Data
Financial information obtained through providers such as Plaid is treated as sensitive information.
Tovi uses financial data only for authorized business purposes, which may include:
- Verifying identity or account ownership
- Verifying income
- Evaluating cash flow
- Assessing eligibility for financial products
- Underwriting and risk management
- Fraud prevention
- Servicing products provided to customers
Tovi does not permit personnel to access financial information unless such access is necessary for an authorized business purpose.
Secure Software Development
Tovi incorporates security considerations into the development and maintenance of its applications and integrations.
Relevant practices include:
- Restricting access to source code and production environments
- Keeping dependencies and software components reasonably current
- Reviewing material application changes before deployment
- Separating development and production environments where appropriate
- Avoiding the inclusion of secrets or sensitive credentials in source code
- Monitoring and addressing material vulnerabilities identified in systems or dependencies
Vulnerability and Patch Management
Tovi seeks to keep operating systems, software, libraries, applications, and infrastructure components reasonably current with security updates.
Material vulnerabilities identified through vendor notifications, automated tools, security reviews, or other means are evaluated based on severity and addressed within a timeframe appropriate to the associated risk.
Logging and Monitoring
Tovi uses logging and monitoring capabilities provided by its application, cloud, authentication, and infrastructure providers where appropriate.
Security relevant events may include:
- Authentication activity
- Administrative access
- Changes to permissions
- Application errors
- Suspicious or unauthorized access attempts
- Material changes to production systems
Incident Response
Tovi maintains procedures for responding to suspected or confirmed information security incidents.
Incident response activities may include:
- Identifying and assessing the incident
- Containing affected systems or accounts
- Revoking compromised credentials or access
- Investigating the cause and scope of the incident
- Remediating identified vulnerabilities
- Restoring affected services
- Documenting the incident and lessons learned
- Providing notifications where required by applicable law or contractual obligations
Material incidents are escalated to company leadership.
Vendor and Third Party Risk Management
Tovi relies on third party providers for certain infrastructure, financial data, communications, authentication, and other services.
Before using a provider that will process sensitive information or perform a security critical function, Tovi considers factors including:
- The nature and sensitivity of information processed
- The provider's reputation and security capabilities
- Available security and privacy documentation
- Access controls and authentication capabilities
- Contractual protections where appropriate
Tovi periodically reevaluates material service providers as appropriate to their risk.
Personnel Security
Personnel with access to Tovi systems are expected to:
- Protect passwords and authentication credentials
- Use multi factor authentication where required
- Avoid unauthorized sharing of customer information
- Report suspected security incidents promptly
- Follow company requirements regarding systems and data access
- Protect company devices and accounts against unauthorized access
Access may be suspended or terminated where security requirements are materially violated.
Data Retention and Disposal
Tovi retains information only for as long as reasonably necessary for legitimate business, contractual, regulatory, fraud prevention, or legal purposes.
When information is no longer required, Tovi will delete or dispose of it using methods appropriate to the system and sensitivity of the information, subject to applicable retention obligations.
Business Continuity and Availability
Tovi uses cloud and software providers with resilience, backup, and recovery capabilities appropriate to the systems being operated.
Tovi evaluates material service interruptions and takes reasonable steps to restore critical services and protect information following a disruption.
Security Reviews
Tovi reviews its information security practices periodically and when significant changes occur to its:
- Products
- Technology infrastructure
- Data processing activities
- Third party integrations
- Regulatory or contractual obligations
- Security risk profile
Identified deficiencies are prioritized and remediated based on risk.
Policy Compliance
All personnel with access to Tovi information or systems are responsible for complying with this policy.
Material exceptions to this policy require approval from company leadership and should be documented where appropriate.
Policy Review
This Information Security Policy will be reviewed at least annually and updated when necessary to reflect changes to Tovi's business, technology environment, security risks, and applicable requirements.
See also our privacy notice, which explains what personal data Tovi collects, why, who it is shared with, how long it is kept, and your rights under the Data Privacy Act of 2012.