Tokaware

updated October 2, 2026

Security

Tokaware reads how you and your team use Claude Code and Codex. This page says what it keeps, how it protects it and for how long. Questions, or a security issue to report: support@tokaware.com.

Encryption

  • In transit: every connection to the website and its API, the desktop app's included, uses HTTPS, and browsers are told to reach the website over HTTPS alone.
  • In the browser: the website's pages, and the desktop app's, load scripts, styles, fonts, images and data from their own address only; no other site can show them inside its own; and they ask for no camera, microphone or location.
  • At rest: the sign-in tokens of linked Claude and ChatGPT accounts and their usage, what computers report (projects, sessions, token counts), conversations, prompts, images, commands, remote sessions and their output, sharing choices, organization policies and billing events are encrypted in the database with AES-256-GCM. The key comes from a secret kept outside the database, so a copy of the database alone does not expose them. The key can be rotated: each value names the key that sealed it, and the previous key opens older values only until all of them are sealed again under the new one. Analytics keep numbers per day (tokens, sessions, prompts, lines, active time) against opaque ids, with project names encrypted.
  • Passwords are hashed with scrypt, each with a salt of its own: nobody can read them, us included.
  • Sign-ins, connected computers, an organization's API and ingest tokens, invites and links sent by email use random tokens of 192 to 256 bits, of which only a SHA-256 hash is stored. An API token reads only what it was given, a limited number of times a minute.
  • The desktop app keeps the logins it saves in its own database, encrypted with a key made on that computer.

Where data is kept

The website and its API run on Vercel, and the database is Turso's hosted libSQL. Emails go out through Resend, payments through Lemon Squeezy, Enterprise single sign-on through WorkOS, and the desktop app is downloaded from Cloudflare, which also forwards the email sent to our support and sales addresses. They are companies in the United States; transfers from the European Union, the United Kingdom and Switzerland rely on the Standard Contractual Clauses. The subprocessors page lists what each one handles.

Without an account, the accounts you add to the dashboard stay in your browser: the website passes each request on to Claude or OpenAI and keeps nothing. A browser that kept them for aicooldown.com, the site's former address, hands them to tokaware.com once, encrypted in the browser with a key the website never receives, and nothing of them is kept on the way. As a guest, the desktop app keeps everything on your computer and talks to Claude and OpenAI directly.

With self-hosted Enterprise, all of it stays on the customer's own servers, in its own database, encrypted with its own key; the license is checked there, offline, and nothing reaches us.

What computers send

  • The desktop app reads the logs Claude Code and Codex write on the computer, and sends numbers: tokens by project, model and day; prompts, edits, lines and commands; sessions with their times. Session titles only when the computer shares session content.
  • Conversations, prompts and images leave the computer only when someone allowed to read them asks, and only if the computer's owner allows it in the app's settings. Never code or files.
  • Remote sessions run only on computers whose owner turned them on, at the level they chose: read only, edits, or full.
  • A computer in an organization holds to its policy: how much of what its sessions say reaches the organization (numbers only, titles, or conversations too), how far remote sessions may go there, whatever its owner allows, and the oldest Tokaware version accepted. New organizations start with numbers only and no remote sessions.
  • An organization's IT can set the desktop app up through device management: the organization a computer connects to as soon as someone signs in, whether it may disconnect, and limits on remote sessions and what sessions say that go below the policy's. The organization sees which computers are managed.
  • An organization on Business or Enterprise can instead collect Claude Code's and Codex's own telemetry (OpenTelemetry), pushed to its computers by its device management: numbers by the developer's email (tokens and their cost, sessions, lines, commits, pull requests, active time, how many prompts), sent with an ingest token kept as a hash. The text of a prompt is never kept, even when a computer is set to send it. A day a computer reported through the desktop app counts that report instead.

How long it is kept

DataKept
Your account, linked accounts and teamsUntil you delete them
What a connected computer last reportedWhile it stays connected
Daily numbers of usage and work, limit readings, and what connectors bring in (billed costs, API usage, seat counts)As long as the plan keeps history: 30 days on Free, 90 days on Team, 13 months on Business and Enterprise; 30 days outside an organization
An organization's alertsWhile they fire, then as long as its plan keeps history
An organization's audit logAs long as its plan keeps history: 13 months on Business and Enterprise
A month an organization closed (its chargeback as it stood)Until an owner reopens it, or the organization is deleted
Conversations, prompts and commands read from computers7 days
Images from conversations3 days
Remote sessions and their output30 days
Sign-ins, with the browser and the address each was last used from30 days, or less where an organization says so, or until you sign out
Links sent by emailUntil used, and at most an hour (a new password) or a day (confirming an email)
Invites7 days
What Lemon Squeezy sends about subscriptions, and messages to sales2 years
Our host's request logsUp to 30 days
Deleted data in our database provider's backupsUntil those backups expire

Signing in

  • Email and password, of at least 8 characters. An email is confirmed with a link before an invite sent to it can be accepted.
  • Google or Microsoft instead of a password, through OpenID Connect with PKCE: their ID tokens are checked against the keys they publish. A Google account joins the account with its email when Google has verified that email; a Microsoft account goes by its tenant and object ids, and its email counts only where the tenant's domain is verified. An account made this way has no password until you choose one, and changes to it ask for a sign-in of the last 15 minutes instead. A password reset disconnects the Google and Microsoft accounts that do not vouch for the account's email.
  • An organization on Enterprise can sign its people in through its own identity provider (single sign-on, SAML or OpenID Connect) by way of WorkOS: "Sign in with SSO" finds it by the work email's domain, and the sign-in counts only when WorkOS says it is that organization's and the email is on a domain the organization verified here. It joins the account with that email, or makes one, and they join the organization as its verified domain lets them.
  • An organization on Enterprise can also connect its directory (Okta, Microsoft Entra ID, Google Workspace, or any SCIM one) through WorkOS: people its IT adds there, with an email on a domain the organization verified, join it as members while a seat is free; people removed or deactivated there leave it and are signed out everywhere, though its owner stays; and its groups become the organization's groups. WorkOS's messages are checked against their signature, and each change goes in the audit log.
  • An organization on Business or Enterprise can ask everyone in it to sign in one way: with Google or Microsoft on an account whose email is on a domain it verified, or (Enterprise) through its single sign-on, which also counts for the two-factor sign-in it may ask for. Anyone signed in otherwise sees nothing of it until they sign in that way; its owner never has to, so a broken sign-in never locks it out.
  • Two-factor sign-in with an authenticator app (TOTP): after the password (or Google or Microsoft), a six-digit code, each one good once. Its key is encrypted in the database, and its ten recovery codes are kept only as keyed hashes. Turning it on signs out every other session; turning it off takes the password and a code. A password reset link still asks for the code.
  • An organization on Business or Enterprise can ask everyone in it for two-factor sign-in: people without it see nothing of the organization until they turn it on.
  • An organization on Business or Enterprise can verify its email domains with a DNS record, one organization per domain: AI accounts and CLI logins on them count as the company's, and, when it allows, people who confirm an email there join it as members while a seat is free. A verified domain never makes a Google or Microsoft sign-in trusted on its own.
  • A sign-in lasts 30 days in a cookie that the page's scripts cannot read (HttpOnly, Secure, SameSite=Lax), or less where an organization on Business or Enterprise says so for its people.
  • Your account lists where you are signed in: each sign-in's browser, the address it was last used from (encrypted in the database) and when, with a button to end it.
  • Signing in, registering, resetting a password and accepting invites are limited per address and per email, and wrong two-factor codes per person, across every server.
  • Changing or resetting a password signs out every other session and disconnects your computers.

Who sees what

A computer, and a linked Claude or ChatGPT account, is its owner's alone or in one of their organizations; its owner chooses. An organization's owners and admins see all the work on its computers, and what sessions say as far as its policy allows; its billing people and viewers see numbers only; its members see their own. Its analytics add up, by day, the work done on its computers, which stays with it: everyone's for its owners, admins and viewers, their own for anyone else. On Enterprise, someone who manages one of its groups also sees the analytics and finance of the group's people, never what their sessions say. A personal computer shows others only what its owner shares with them. Every request is checked on the server, and an organization someone is not in answers as if it did not exist.

Audit log

  • An organization on Business or Enterprise keeps an audit log: its people's sign-ins and wrong passwords, changes to their passwords, two-factor sign-in and sign-in methods, who joined, left, was invited, removed or given another role, groups and who is in or manages each, changes to the policy, billing, domains, connectors and channels, CSV downloads, remote sessions and commands, computers enrolled, released or removed, and what our support changed for it.
  • It also records every read of what its computers' sessions say (a conversation, prompts, media) by anyone but the computer's owner, once per person, computer and session a quarter hour. A download of prompts as CSV counts as that download.
  • Each entry keeps who did it (their email then, which stays after they leave or delete their account), when, what it was done to, and the address it came from, encrypted in the database with its details. The organization's owners, admins and viewers read it on the Audit tab and download it as CSV; it is kept as long as the plan keeps history, and deleted with the organization.
  • On Enterprise it can stream to your SIEM: a webhook channel gets every entry written after it starts, in order, a hundred to a request signed with the channel's secret, within five minutes; a request that fails is tried again, from where it stopped, until it goes through. Starting and stopping a stream go in the log.

Payments

Lemon Squeezy, the merchant of record, takes payments and handles sales tax and VAT. Card numbers go to Lemon Squeezy only; we never see or store them. Its notices about subscriptions are checked against their signature before anything changes.

Reporting a security issue

Write to support@tokaware.com with "Security" in the subject: what you found and how to reproduce it. Please keep it private until it is fixed, and do not access other people's data or disrupt the service while testing.

More

Business and Enterprise customers can send us their security questionnaires.