Generating PDF…
WebloTTS ← All documents
← Documents

Information Security Policy

Weblo TTS · TIME4IT Sp. z o.o.
Version 1.0 · last updated: 22 June 2026

1. Purpose and Scope

This policy defines information security principles for Weblo TTS and supporting processes for WooCommerce and TikTok Shop integration.

2. Core Principles

  • Confidentiality, integrity, and availability of data.
  • Risk-proportionate security controls.
  • Continuous improvement of safeguards and procedures.

3. Risk Management

Risks are identified, assessed, and mitigated periodically and after significant technology or business changes.

4. TikTok Shop API Protection

  • OAuth2/PKCE for access authorization.
  • Webhook validation with HMAC signatures.
  • Segregation and restricted handling of confidential data.

5. Identity and Access Management

Access is granted on a least-privilege basis and reviewed periodically.

6. Production Environment Security

Production, staging, and development environments are logically separated, and privileged access is monitored.

7. Vulnerability Management

Identified vulnerabilities are classified and remediated according to severity and applicable SLAs.

8. Logging and Monitoring

Security events, administrative actions, and critical API operations are logged with integrity controls.

9. Incident Management

Security incidents are handled under a dedicated process including escalation and stakeholder reporting.

10. Technical Controls

  • MFA for administrative accounts and critical systems.
  • TLS 1.2+ encryption for data in transit.
  • Network firewalls and traffic segmentation.
  • Centralized logging and security alerting.
  • Regular backups and restoration tests.

TikTok Shop API Addendum

Weblo TTS provides WooCommerce and TikTok Shop integration through the official TikTok Shop API.

  • Authentication and authorization are handled through OAuth2 with PKCE.
  • Access and refresh tokens are stored and processed under least-privilege controls.
  • TikTok webhooks are validated using HMAC signatures before any processing.
  • Confidential data is handled in line with TikTok Business Partner Code section 3.11.
  • Security incidents are reported to [email protected] within 24 hours and to TikTok as required by the agreement.

Document Approval

This document has been approved by the Management Board of TIME4IT Sp. z o.o.

Version: 1.0

Approval date: 22 June 2026

Contact

For questions regarding this document, security or privacy:

TIME4IT Sp. z o.o.
ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]

© 2026 Weblo · TIME4IT Sp. z o.o.

Privacy Policy Terms of Service Documents
PL · EN