Security training
All Toolyt personnel go through protection training designed for a cloud-hosted setup. The awareness programme targets the cybersecurity mistakes that put system files at risk.
ISO 27001:2022 certified, SOC 2 accredited infrastructure and GDPR-aligned processing - protecting your data from the field device in a rep's hand to the cloud region your records live in.



ISO 27001
Certified information security management system
SOC 2
Cloud infrastructure accredited under SOC 2 controls
GDPR
Data-protection aligned processing and retention
MFA
Mandatory for all production infrastructure access
Yes. Toolyt runs an ISO 27001:2022 certified information security management system on SOC 2 accredited AWS and Azure infrastructure, encrypts data with AES at rest and TLS in transit, enforces MFA and role-based access on every record, tests independently through third-party VAPT, and can pin a deployment to a chosen cloud region for data-residency requirements.
Regulated lenders, insurers and pharma organisations run their field operations on Toolyt. These are the controls their security and risk teams review before go-live.
All Toolyt personnel go through protection training designed for a cloud-hosted setup. The awareness programme targets the cybersecurity mistakes that put system files at risk.
We run regular penetration tests through an independent, certified third-party VAPT service to validate our posture and uncover potential vulnerabilities.
Third-party software and services are reviewed periodically and patched. When vulnerabilities are disclosed, fixes are applied within pre-defined SLAs.
Role-based access control (RBAC) governs every record. Users see only the data they are permitted to see, and never data belonging to another organisation.
Production infrastructure requires multi-factor authentication and is restricted to authorised personnel. Customer data access is limited to staff providing support.
Toolyt runs on AWS and Microsoft Azure. Both physical infrastructures are accredited under SOC 2, ISO 27001, PCI Level 1 and FISMA Moderate.
Customer data leaves the building every morning. Toolyt is built so it never leaves your control.
Field officers work without signal. Offline data is held in an encrypted store scoped to the signed-in user and syncs only over TLS.
Session expiry, device binding and remote sign-out mean a lost handset does not become a data-loss incident.
Geo-stamped visits, timestamped documents and immutable activity logs give audit and risk teams a defensible trail.
Aadhaar-masked KYC capture, document checklists, deviation approvals and disbursement trails stay inside one permissioned system - so credit, risk and internal audit review the same record.
Access is scoped by branch, product and reporting line, so a relationship manager sees their book and nothing else, while regional leadership sees roll-ups without record-level exposure.
Policy, nominee and health-declaration fields are masked by role, and renewal or claims handoffs move between teams without exporting spreadsheets.
Doctor interactions, samples and expenses are captured in-app with geo-verification, removing the WhatsApp-and-Excel trail that compliance teams cannot govern.
Capture only what the workflow needs, mask the rest, and keep identifiable information inside a role-scoped, region-pinned deployment.
All sensitive data is encrypted with AES at rest. User passwords are securely hashed and never stored in plain text.
All communication between your users and our servers is protected with 128-bit SSL/TLS encryption, on mobile and web alike.
Found something? Report it to our security team and we will acknowledge, triage and remediate within our published SLA windows.
Running a vendor security assessment? We share our ISO 27001:2022 certificate, VAPT summary, data-processing terms and hosting-region options on request.
Request documentationSee how regulated teams run KYC, documents and audit trails on Toolyt without leaving their security perimeter.