Skip to content

Security

Last updated July 2026

Tulo is operated by Dark Zorse Ltd. We handle financial data, so security is core to how we build and run the platform. This page describes our security practices.

Compliance

Tulo is SOC 2 attested, independently verified by a third-party auditor. Our security program is aligned with SOC 2 and ISO 27001.

Encryption

All customer data is encrypted at rest and in transit using industry-standard encryption practices.

Access Controls

Access to systems and data follows the principle of least privilege, enforced through role-based access control. Administrative access requires multi-factor authentication. Third-party accounting integrations use OAuth 2.0, so we never store your accounting platform credentials.

Data Handling

We classify data by sensitivity and handle each class accordingly, with financial transaction data treated as the most restricted. Customer data is retained only as long as needed, and securely deleted when accounts are closed. The platform is hosted with leading, independently audited cloud providers.

Vulnerability Management

We run regular automated vulnerability scanning across our codebase, dependencies, and infrastructure, and prioritize remediation based on severity.

Insurance

Dark Zorse Ltd maintains commercial insurance appropriate to the nature of our business. Details are available to customers on request.

Contact

To report a vulnerability or ask about our security practices, email security@tulo.co.