Please describe your proposed solution
External Code & Security Audit
- Conduct a thorough review of Tokeo's codebase and security protocols to identify vulnerabilities and areas for improvement. In particular provide assurances on the secure handling and storage of wallet keys.
ISO 27001 Compliance
- Engage a global partner for ISO 27001 compliance. The ISO27001 is a global best practices standard for information security management. Achieve compliance certification by Q2 2025.
- This step involves the documentation of security and information handling processes, along with documenting compliance over a period of time (6-months). Certification is then achieved via an external audit. See below for further benefits on the standard.
Source Code Availability
Tokeo's source code for front-end apps will be made available in a GIT Repository, allowing for community review and contribution. This is a crucial step in ensuring the security and transparency of the platform, particularly when handling sensitive information such as wallet keys.
By making the source code available, Tokeo:
- Demonstrates a commitment to openness and transparency
- Allows the community to review and audit the code for security vulnerabilities
- Enables contributors to identify and fix bugs, improving the overall security and stability of the platform
- Fosters a sense of community ownership and responsibility for platform security
- Encourages collaboration and innovation, driving the development of new features and improvements
Refactoring the source code for source-availability involves:
- Organizing and cleaning up the codebase to make it easily accessible and understandable
- Removing any sensitive or proprietary information
- Documenting the code and development processes
- Establishing clear guidelines for community contribution and engagement
By opening up the source code, Tokeo can leverage the collective expertise and resources of the community to ensure the platform's security and integrity, ultimately providing a safer and more reliable experience for users.
ISO 27001 Compliance
Engaging a global partner for ISO 27001 compliance is a crucial step in ensuring the security and integrity of Tokeo's information systems. ISO 27001 is a globally recognized standard for Information Security Management Systems (ISMS) that provides a framework for implementing robust security controls and best practices.
Achieving ISO 27001 certification demonstrates Tokeo's commitment to protecting sensitive information, including wallet keys, and ensures that the company adheres to a rigorous set of security standards. This certification is particularly important in the financial and technology sectors, where security and trust are paramount.
The process of achieving ISO 27001 compliance involves:
- Documenting security and information handling processes
- Implementing security controls and procedures
- Conducting regular internal audits and risk assessments
- Engaging an external auditor to verify compliance
- Achieving certification by Q2 2025
ISO 27001 compliance provides numerous benefits, including:
- Enhanced security posture
- Increased customer trust and confidence
- Improved risk management
- Compliance with regulatory requirements
- Competitive advantage
By achieving ISO 27001 certification, Tokeo demonstrates its dedication to protecting sensitive information and maintaining the highest level of security and integrity.