Security and compliance

We protect your team's AI data with strong security controls and clear compliance, so you can roll out Tokenize with confidence.

  • GDPR
  • SOC 2 Type II
  • SAML SSO
  • SCIM Provisioning
  • Your data stays yours

    Every customer's data is fully isolated, and inside your org, access follows roles. Admins see the whole org, managers see their teams, and everyone sees their own usage.

  • Security protocols

    Single sign-on, automatic provisioning with SCIM, role-based permissions, and encryption in transit and at rest keep your account protected.

  • Private infrastructure

    Tokenize runs on AWS in the United States, with production systems walled off from the public internet and every device sending data with your org's own key.

Compliant by design

Our security and compliance programs follow industry-standard frameworks, so you can bring Tokenize through your security review without surprises.

  • SOC 2 Type II

    Our security program is independently audited. The latest report is available in our Trust Center.

  • GDPR

    Our Data Processing Addendum includes the EU Standard Contractual Clauses, and we delete your org's data, or a single person's, on request.

  • CCPA and U.S. privacy laws

    We follow existing and emerging U.S. privacy laws and act as your service provider, so your data is only ever used to run Tokenize for you.

Frequently asked questions

Where can I find your Privacy Policy?

You can read our Privacy Policy here.

Where is my data stored?

On AWS in the United States.

What data does Tokenize collect?

Usage from your team's AI tools: which tool and model ran, token counts, and cost. You choose whether session detail is included, and redaction strips out personal details and secrets, like phone numbers and API keys, before anything is stored.

How long do you keep data?

Data is deleted automatically on a rolling schedule and never kept longer than a year. We'll also delete your org's data, or a single person's, on request.

Will Tokenize affect how our AI tools run?

No. The Tokenize app rolls out through MDM like any other company app, with no proxies and no rerouted traffic.

Can my team see each other's sessions?

Only if their role allows it. Admins see the org, managers see their teams, and everyone sees their own usage.

Do you have a Data Processing Addendum?

Yes. You can read our Data Processing Addendum online.

Who are your subprocessors?

The full list is in our Trust Center.

How do I report a security vulnerability?

Email privacy@tokenizehq.com. We look at every report.

Contact us

Want to learn more about how we handle security and privacy? Visit our Trust Center or email privacy@tokenizehq.com.