Generating PDF…
WebloTTS ← All documents
← Documents

Incident Response and Vulnerability Management Policy

Weblo TTS · TIME4IT Sp. z o.o.
Version 1.0 · last updated: 22 June 2026

1. Purpose and Applicability

This policy describes the full incident response and vulnerability management lifecycle for Weblo TTS.

2. Incident and Vulnerability Definitions

An incident is an event that compromises or threatens confidentiality, integrity, or availability of systems or data.

3. Preparation

  • Defined roles and escalation paths.
  • Maintained monitoring and crisis communication tools.
  • Training and scenario-based exercises.

4. Detection and Reporting

Any suspected incident is promptly recorded, classified, and escalated to the responsible team.

5. Analysis and Triage

Analysis covers impact scope, affected data, attack vector, risk level, and customer and partner exposure.

6. Containment and Eradication

Actions include component isolation, key and token rotation, configuration hardening, and security patch deployment.

7. Recovery

Service recovery is performed after integrity verification, testing, and process owner approval.

8. Communications and Notifications

For incidents affecting TikTok Shop API, notification is sent to [email protected] within 24 hours, and TikTok is notified according to contractual obligations and platform requirements.

9. Vulnerability Management and SLAs

  • Critical: remediation within 72 hours.
  • High: remediation within 14 days.
  • Medium: remediation within 30 days.
  • Low: remediation in the regular maintenance cycle.

10. Post-Incident Review and Improvement

After each incident, we issue an RCA report, apply corrective actions, and update procedures and preventive controls.

TikTok Shop API Addendum

Weblo TTS provides WooCommerce and TikTok Shop integration through the official TikTok Shop API.

  • Authentication and authorization are handled through OAuth2 with PKCE.
  • Access and refresh tokens are stored and processed under least-privilege controls.
  • TikTok webhooks are validated using HMAC signatures before any processing.
  • Confidential data is handled in line with TikTok Business Partner Code section 3.11.
  • Security incidents are reported to [email protected] within 24 hours and to TikTok as required by the agreement.

Document Approval

This document has been approved by the Management Board of TIME4IT Sp. z o.o.

Version: 1.0

Approval date: 22 June 2026

Contact

For questions regarding this document, security or privacy:

TIME4IT Sp. z o.o.
ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]

© 2026 Weblo · TIME4IT Sp. z o.o.

Privacy Policy Terms of Service Documents
PL · EN