Information Security Policy
1. Purpose and Scope
This policy defines information security principles for Weblo TTS and supporting processes for WooCommerce and TikTok Shop integration.
2. Core Principles
- Confidentiality, integrity, and availability of data.
- Risk-proportionate security controls.
- Continuous improvement of safeguards and procedures.
3. Risk Management
Risks are identified, assessed, and mitigated periodically and after significant technology or business changes.
4. TikTok Shop API Protection
- OAuth2/PKCE for access authorization.
- Webhook validation with HMAC signatures.
- Segregation and restricted handling of confidential data.
5. Identity and Access Management
Access is granted on a least-privilege basis and reviewed periodically.
6. Production Environment Security
Production, staging, and development environments are logically separated, and privileged access is monitored.
7. Vulnerability Management
Identified vulnerabilities are classified and remediated according to severity and applicable SLAs.
8. Logging and Monitoring
Security events, administrative actions, and critical API operations are logged with integrity controls.
9. Incident Management
Security incidents are handled under a dedicated process including escalation and stakeholder reporting.
10. Technical Controls
- MFA for administrative accounts and critical systems.
- TLS 1.2+ encryption for data in transit.
- Network firewalls and traffic segmentation.
- Centralized logging and security alerting.
- Regular backups and restoration tests.
TikTok Shop API Addendum
Weblo TTS provides WooCommerce and TikTok Shop integration through the official TikTok Shop API.
- Authentication and authorization are handled through OAuth2 with PKCE.
- Access and refresh tokens are stored and processed under least-privilege controls.
- TikTok webhooks are validated using HMAC signatures before any processing.
- Confidential data is handled in line with TikTok Business Partner Code section 3.11.
- Security incidents are reported to [email protected] within 24 hours and to TikTok as required by the agreement.
Document Approval
This document has been approved by the Management Board of TIME4IT Sp. z o.o.
Version: 1.0
Approval date: 22 June 2026
Contact
For questions regarding this document, security or privacy:
TIME4IT Sp. z o.o.ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]