Incident Response and Vulnerability Management Policy
1. Purpose and Applicability
This policy describes the full incident response and vulnerability management lifecycle for Weblo TTS.
2. Incident and Vulnerability Definitions
An incident is an event that compromises or threatens confidentiality, integrity, or availability of systems or data.
3. Preparation
- Defined roles and escalation paths.
- Maintained monitoring and crisis communication tools.
- Training and scenario-based exercises.
4. Detection and Reporting
Any suspected incident is promptly recorded, classified, and escalated to the responsible team.
5. Analysis and Triage
Analysis covers impact scope, affected data, attack vector, risk level, and customer and partner exposure.
6. Containment and Eradication
Actions include component isolation, key and token rotation, configuration hardening, and security patch deployment.
7. Recovery
Service recovery is performed after integrity verification, testing, and process owner approval.
8. Communications and Notifications
For incidents affecting TikTok Shop API, notification is sent to [email protected] within 24 hours, and TikTok is notified according to contractual obligations and platform requirements.
9. Vulnerability Management and SLAs
- Critical: remediation within 72 hours.
- High: remediation within 14 days.
- Medium: remediation within 30 days.
- Low: remediation in the regular maintenance cycle.
10. Post-Incident Review and Improvement
After each incident, we issue an RCA report, apply corrective actions, and update procedures and preventive controls.
TikTok Shop API Addendum
Weblo TTS provides WooCommerce and TikTok Shop integration through the official TikTok Shop API.
- Authentication and authorization are handled through OAuth2 with PKCE.
- Access and refresh tokens are stored and processed under least-privilege controls.
- TikTok webhooks are validated using HMAC signatures before any processing.
- Confidential data is handled in line with TikTok Business Partner Code section 3.11.
- Security incidents are reported to [email protected] within 24 hours and to TikTok as required by the agreement.
Document Approval
This document has been approved by the Management Board of TIME4IT Sp. z o.o.
Version: 1.0
Approval date: 22 June 2026
Contact
For questions regarding this document, security or privacy:
TIME4IT Sp. z o.o.ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]