Toolyt

Trust centre

The most secure field CRM for regulated enterprises.

ISO 27001:2022 certified, SOC 2 accredited infrastructure and GDPR-aligned processing - protecting your data from the field device in a rep's hand to the cloud region your records live in.

ISO 27001:2022 certifiedSOC 2 accredited cloud infrastructureGDPR aligned

ISO 27001

Certified information security management system

SOC 2

Cloud infrastructure accredited under SOC 2 controls

GDPR

Data-protection aligned processing and retention

MFA

Mandatory for all production infrastructure access

In short

Is Toolyt secure enough for a regulated enterprise?

Yes. Toolyt runs an ISO 27001:2022 certified information security management system on SOC 2 accredited AWS and Azure infrastructure, encrypts data with AES at rest and TLS in transit, enforces MFA and role-based access on every record, tests independently through third-party VAPT, and can pin a deployment to a chosen cloud region for data-residency requirements.

  • Certified ISMS
  • Region-pinned hosting
  • Encrypted offline field data
  • Independent VAPT

Controls

The controls behind every Toolyt deployment

Regulated lenders, insurers and pharma organisations run their field operations on Toolyt. These are the controls their security and risk teams review before go-live.

Security training

All Toolyt personnel go through protection training designed for a cloud-hosted setup. The awareness programme targets the cybersecurity mistakes that put system files at risk.

Penetration testing

We run regular penetration tests through an independent, certified third-party VAPT service to validate our posture and uncover potential vulnerabilities.

Vulnerability management

Third-party software and services are reviewed periodically and patched. When vulnerabilities are disclosed, fixes are applied within pre-defined SLAs.

Application access

Role-based access control (RBAC) governs every record. Users see only the data they are permitted to see, and never data belonging to another organisation.

Access control

Production infrastructure requires multi-factor authentication and is restricted to authorised personnel. Customer data access is limited to staff providing support.

Secured infrastructure

Toolyt runs on AWS and Microsoft Azure. Both physical infrastructures are accredited under SOC 2, ISO 27001, PCI Level 1 and FISMA Moderate.

Security in the field

The riskiest part of field sales is the last mile

Customer data leaves the building every morning. Toolyt is built so it never leaves your control.

Encrypted offline cache

Field officers work without signal. Offline data is held in an encrypted store scoped to the signed-in user and syncs only over TLS.

Device and session control

Session expiry, device binding and remote sign-out mean a lost handset does not become a data-loss incident.

Verifiable field evidence

Geo-stamped visits, timestamped documents and immutable activity logs give audit and risk teams a defensible trail.

Enterprise use cases

How security teams deploy Toolyt in regulated industries

  • Lending and NBFC

    KYC and loan files that survive an audit

    Aadhaar-masked KYC capture, document checklists, deviation approvals and disbursement trails stay inside one permissioned system - so credit, risk and internal audit review the same record.

    • Region-pinned document storage
    • Maker-checker on deviations
    • Full lead-to-disbursement audit log
  • Banking

    Branch and RM data segregated by hierarchy

    Access is scoped by branch, product and reporting line, so a relationship manager sees their book and nothing else, while regional leadership sees roll-ups without record-level exposure.

    • Hierarchy-aware RBAC
    • MFA-protected admin actions
    • Outsourcing-review documentation
  • Insurance

    Proposal and claims data handled with least privilege

    Policy, nominee and health-declaration fields are masked by role, and renewal or claims handoffs move between teams without exporting spreadsheets.

    • Field-level masking
    • No spreadsheet handoffs
    • Retention rules per document type
  • Pharma

    Field force compliance without shadow IT

    Doctor interactions, samples and expenses are captured in-app with geo-verification, removing the WhatsApp-and-Excel trail that compliance teams cannot govern.

    • Geo-verified call reporting
    • Sample custody records
    • Controlled export permissions
  • Healthcare and devices

    Patient-adjacent data kept minimal and permissioned

    Capture only what the workflow needs, mask the rest, and keep identifiable information inside a role-scoped, region-pinned deployment.

    • Data-minimisation by design
    • Role-scoped visibility
    • Regional hosting options

Encryption, disclosure and our commitments

Data encryption at rest

All sensitive data is encrypted with AES at rest. User passwords are securely hashed and never stored in plain text.

Encryption in transit

All communication between your users and our servers is protected with 128-bit SSL/TLS encryption, on mobile and web alike.

Responsible disclosure

Found something? Report it to our security team and we will acknowledge, triage and remediate within our published SLA windows.

Certification
ISO 27001:2022 certified ISMS, reviewed annually
Testing
Independent third-party VAPT on a recurring cycle
Patching
Disclosed vulnerabilities remediated within defined SLAs
Hosting
AWS and Microsoft Azure, region selectable per deployment
Access
MFA-enforced, least-privilege production access
Disclosure
Acknowledge, triage and remediate under published windows

Running a vendor security assessment? We share our ISO 27001:2022 certificate, VAPT summary, data-processing terms and hosting-region options on request.

Request documentation

Security FAQ

What review teams ask us

Is Toolyt ISO 27001 certified?
Yes. Toolyt operates an ISO 27001:2022 certified information security management system, and our cloud infrastructure on AWS and Microsoft Azure is accredited under SOC 2, ISO 27001, PCI Level 1 and FISMA Moderate. We share the certificate and control summary with security teams on request.
How is customer data encrypted in Toolyt?
Sensitive data is encrypted with AES at rest and all traffic between field devices, browsers and our servers is protected with SSL/TLS. Passwords are hashed, never stored in plain text, and production access requires multi-factor authentication.
Can data stay in a specific country or region?
Yes. Deployments can be pinned to a chosen cloud region so customer records, documents and KYC artefacts never leave that jurisdiction, which is how regulated lenders and insurers meet local data-residency expectations.
How does Toolyt secure data on field devices?
The mobile app stores offline data in an encrypted local cache scoped to the logged-in user, enforces session expiry and device binding, supports remote sign-out, and geo-stamps visits so field activity is verifiable and auditable.
Who inside our organisation can see a customer record?
Role-based access control governs every record by role, hierarchy, branch and product. Users only see data they are permitted to see, and no organisation can ever see another organisation's data.
What documentation do you provide for vendor security reviews?
ISO 27001:2022 certificate, third-party VAPT summary, data-processing terms, access-control and encryption overviews, hosting-region options and our incident-response commitments.

Take action today

Compliance-ready field operations

See how regulated teams run KYC, documents and audit trails on Toolyt without leaving their security perimeter.