Security and encryption
Stored provider credentials use AES-256-GCM. Read the implementation scope, key lifecycle, hosting region, rotation policy, and honest threat model.
Read security design →Scout is waking up…
Reviewed August 18, 2026
Stored provider credentials use AES-256-GCM. Read the implementation scope, key lifecycle, hosting region, rotation policy, and honest threat model.
Read security design →Named vendors that process TryTokka data, including disaster-recovery backups. Same list as Privacy §4.
View subprocessors →How a suspected breach is reported, contained, assessed, and published. Not a 24/7 SOC and not a timed-email guarantee.
Read the procedure →Retention depends on data type and legal obligations. What the account delete button removes vs what backups and tax records keep is on the Security page.
Read deletion guarantees →The public status page reports the checks implemented by TryTokka. It is not a contractual uptime SLA.
Open service status →Security researchers can use the RFC 9116 security.txt contact and policy links. Do not include active credentials or personal data in a report.
Open security.txt →TryTokka distinguishes list-rate estimates, synced provider usage, and finalized billing records. Provider invoices remain the settlement source.
Read the accuracy framework →TryTokka names its founder and support channel. No customer count, funding, award, or team-size claim is implied.
Meet the founder →Read current subscription, refund-window, cancellation, and payment-provider terms before purchasing.
Read Terms of Service →Claims are checked against the sources below. Provider prices and product features can change; verify the source before making a purchasing or production decision. Last checked 2026-08-20.
Entries shown as a file path point into TryTokka's application repository, which is not public — you cannot open those to check them yourself, and we would rather say so than link you to a page you cannot read. They are listed so the claim names the exact code it rests on. Everything else links to a primary source you can verify directly.
infrastructure/providers/index.ts; reviewed 2026-07-18Provider adapters receive encrypted credentials and fetch usage out of band.vercel.json; reviewed 2026-07-18The deployed schedule is the source of truth; delivery time is not guaranteed.app/api/connections/sync/route.ts; reviewed 2026-07-18Authenticated owners can request an on-demand sync.lib/model-pricing-catalog.ts; reviewed 2026-07-18Pins include a verification date and are checked by the pricing gate.Found an outdated statement? Email legal@trytokka.com.
For product, privacy, or billing questions, use Support. For a suspected vulnerability, follow security.txt so the report reaches the documented contact.