Skip Navigation or Skip to Content

Tosi Security Center

Our Commitment to Security

At Tosi, security is at the foundation of everything we build. Our customers entrust us with protecting their critical infrastructure and operational technology environments. This responsibility drives our approach to security at every level of our organization, from product development to daily operations.

Our security program is built on internationally recognized standards and continuously evolves to address emerging threats. We maintain rigorous security controls, undergo regular third-party assessments, and foster a culture where security is everyone's responsibility.

Cybersecurity iStock-610855316-1

Certifications & Standards

Tosi maintains industry-leading certifications that demonstrate our commitment to security excellence:

ISO/IEC 27001:2022 – Information Security Management

Our Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022, the international gold standard for information security. This certification validates that Tosi has implemented comprehensive security controls covering risk management, access control, cryptography, physical security, operational security, and incident management.

Our Security Practices

Product Security

Tosi products are engineered with security as a core design principle. We use industry-standard cryptographic protocols, hardware-based security with dedicated security modules and tamper-resistant designs, zero-trust network architecture that requires authentication and authorization for every connection, and automatic security updates ensuring devices remain protected against emerging threats.

Organizational Security

Our internal security program encompasses regular security awareness training for all employees, background checks and security clearances for personnel handling sensitive systems, principle of least privilege access controls, continuous security monitoring and logging, incident response procedures and regular tabletop exercises, and vendor security assessments for third-party integrations.

Security Policies

Transparency is fundamental to trust. We make our key security policies available to customers, partners, and the security community:

Information Security Policy

Our Information Security Policy establishes the framework for protecting information assets across Tosi. It defines security objectives, roles and responsibilities, risk management approach, and compliance requirements.

Vulnerability Disclosure Policy

We value the security research community and welcome responsible disclosure of security vulnerabilities. Our Vulnerability Disclosure Policy outlines how to report potential security issues, what to expect during the disclosure process, and our commitment to working collaboratively with researchers.

 

Vulnerability Disclosure Policy (PDF) - coming soon.

Security Support

Report a Security Vulnerability

If you believe you have discovered a security vulnerability in a Tosi product or service, we encourage you to report it to us promptly. Please review our Vulnerability Disclosure Policy before submitting a report to security@tosi.net.

Man on laptop

Contact Us

For general security inquiries, certification requests, or security questionnaires, please contact us at:

Security Team: security@tosi.net

General Inquiries: info@tosi.net

Technical support-2