Tovi

Security policy

Information security policy

Last updated 19 August 2026 · Version 1.0

Policy owner: Chief Executive Officer

Review frequency: At least annually and upon material changes to Tovi's systems, products, or security risk profile.

Purpose

Tovi is committed to protecting the confidentiality, integrity, and availability of information entrusted to the company.

This Information Security Policy establishes the administrative, technical, and organizational safeguards Tovi uses to identify, mitigate, and monitor information security risks relevant to its operations.

The policy is designed to be proportionate to Tovi's size, stage of development, technology environment, and the sensitivity of the information processed by the company.

Scope

This policy applies to:

Security Governance and Risk Management

Tovi assigns responsibility for information security oversight to company leadership.

Tovi periodically evaluates information security risks associated with its systems, data, vendors, and business processes.

Identified risks are evaluated based on their likelihood and potential impact. Appropriate safeguards are implemented based on the sensitivity of the data involved and the severity of the identified risk.

Security risks and controls are reviewed when Tovi introduces material new products, integrations, systems, or vendors.

Access Control

Access to Tovi systems and information is granted according to the principle of least privilege.

Personnel are provided access only to systems and information reasonably necessary to perform their responsibilities.

Tovi requires:

Shared credentials should be avoided wherever technically feasible.

Authentication and Credential Security

Passwords, API credentials, access tokens, private keys, and similar authentication information must be protected against unauthorized disclosure.

Sensitive credentials must not be stored in publicly accessible repositories or transmitted through insecure communication channels.

Production credentials should be stored using secure credential or secrets management mechanisms provided by Tovi's infrastructure providers where reasonably available.

Data Protection

Tovi limits the collection and retention of sensitive information to information reasonably necessary to provide its services, evaluate eligibility, prevent fraud, comply with legal obligations, and operate the business.

Sensitive information must be protected during transmission using industry standard encrypted communication protocols where supported.

Tovi uses reputable infrastructure and service providers that provide appropriate security controls for stored information.

Access to sensitive customer information is restricted to authorized personnel and systems with a legitimate business need.

Financial Data

Financial information obtained through providers such as Plaid is treated as sensitive information.

Tovi uses financial data only for authorized business purposes, which may include:

Tovi does not permit personnel to access financial information unless such access is necessary for an authorized business purpose.

Secure Software Development

Tovi incorporates security considerations into the development and maintenance of its applications and integrations.

Relevant practices include:

Vulnerability and Patch Management

Tovi seeks to keep operating systems, software, libraries, applications, and infrastructure components reasonably current with security updates.

Material vulnerabilities identified through vendor notifications, automated tools, security reviews, or other means are evaluated based on severity and addressed within a timeframe appropriate to the associated risk.

Logging and Monitoring

Tovi uses logging and monitoring capabilities provided by its application, cloud, authentication, and infrastructure providers where appropriate.

Security relevant events may include:

Incident Response

Tovi maintains procedures for responding to suspected or confirmed information security incidents.

Incident response activities may include:

Material incidents are escalated to company leadership.

Vendor and Third Party Risk Management

Tovi relies on third party providers for certain infrastructure, financial data, communications, authentication, and other services.

Before using a provider that will process sensitive information or perform a security critical function, Tovi considers factors including:

Tovi periodically reevaluates material service providers as appropriate to their risk.

Personnel Security

Personnel with access to Tovi systems are expected to:

Access may be suspended or terminated where security requirements are materially violated.

Data Retention and Disposal

Tovi retains information only for as long as reasonably necessary for legitimate business, contractual, regulatory, fraud prevention, or legal purposes.

When information is no longer required, Tovi will delete or dispose of it using methods appropriate to the system and sensitivity of the information, subject to applicable retention obligations.

Business Continuity and Availability

Tovi uses cloud and software providers with resilience, backup, and recovery capabilities appropriate to the systems being operated.

Tovi evaluates material service interruptions and takes reasonable steps to restore critical services and protect information following a disruption.

Security Reviews

Tovi reviews its information security practices periodically and when significant changes occur to its:

Identified deficiencies are prioritized and remediated based on risk.

Policy Compliance

All personnel with access to Tovi information or systems are responsible for complying with this policy.

Material exceptions to this policy require approval from company leadership and should be documented where appropriate.

Policy Review

This Information Security Policy will be reviewed at least annually and updated when necessary to reflect changes to Tovi's business, technology environment, security risks, and applicable requirements.

See also our privacy notice, which explains what personal data Tovi collects, why, who it is shared with, how long it is kept, and your rights under the Data Privacy Act of 2012.