Security and data sovereignty

Our commitment to security and sovereignty of your data is outlined below:

Ownership

Your data is yours.

All data entered into Tohu by or on behalf of your organisation remains your organisation's sole property at all times. Tohu makes no claim to ownership of it.

Using Tohu does not transfer any ownership, intellectual property, cultural rights, or authority over your information. We recognise that the records held by Māori trusts, hapū, marae and iwi carry significant mātauranga, and we commit to safeguarding it in a way that upholds the integrity, ownership and sensitivity of our clients.

Data sovereignty

Your data stays in Aotearoa.

Tohu runs entirely on New Zealand–based cloud infrastructure. The application, database and document storage are all located within Aotearoa, New Zealand and will never leave the country.

If we ever change hosting provider, any replacement will remain New Zealand based and maintain an equivalent or higher standard of security and data protection.

How we protect it

Security built into the foundations.

Protecting governance information is a core responsibility for Tohu, not an afterthought. The platform is built with layered safeguards.

Secure sign-in & 2FA

Individual accounts with secure login and two-factor authentication for everyone with access to sensitive records.

Role-based access

People see only what their role allows. Access to governance records follows the responsibilities of each user.

Organisation isolation

Each organisation's data environment is fully separated. No other organisation on Tohu can access your data.

Encrypted in transit & at rest

Traffic is encrypted in transit and your data is encrypted at rest. System secrets are protected separately.

Audit logging

Key actions are logged, creating an accountable record of activity across your governance environment.

Independent reviews

As the platform matures, Tohu undertakes independent security reviews and keeps partners informed of material developments.

Your control

You decide who, how and when.

Each organisation retains authority over its own data including who can access it, how it is used and how it may be exported or removed. We will never sell, reuse, or share your data.

Tohu personnel only ever access your data to provide technical support, investigate a fault, maintain platform security, under your authorisation, or as required by law.

Self-service export is in the pipeline and will allow Account Owners to export all organisation records directly.

Continuity. In the unlikely event Tohu ever ceases to operate, you keep full access to your data and we provide reasonable transition assistance before anything is taken offline.

Privacy

Handled under New Zealand law.

We collect, hold and use personal information in accordance with the New Zealand Privacy Act 2020 and its 13 Information Privacy Principles. We will never share your data with a third party without your explicit written consent, except where required by law. If we are ever legally compelled to disclose your data, we will tell you as soon as we are permitted to.

In the event of a privacy breach that poses a risk of serious harm, we will notify you and, where required, the Privacy Commissioner, as soon as reasonably practicable.

Privacy Officer
Mayana Daniels · support@tohugovernance.com

Reliable governance on infrastructure you can trust.