Incident Response Policy
1. Purpose
This document defines how ICE SQUAD MEDIA LLC responds to information security incidents affecting its systems or data obtained through the TikTok Shop Open API.
2. What counts as an incident
- unauthorized access to customer or seller data;
- compromise of credentials, API keys or access tokens;
- compromise of infrastructure or of the code supply chain;
- malware on a workstation with access to production systems;
- loss or theft of a device with such access;
- denial of service affecting availability.
3. Roles
The product owner acts as Incident Owner: makes decisions, coordinates the response and notifies affected parties. Technical containment and remediation are performed by the same person or by an engaged developer. The team is small and roles are not diffuse — every action has a named owner.
4. Severity and response times
| Level | Description | Response begins |
|---|---|---|
| P1 | Leak or compromise of customer or seller data | Immediately |
| P2 | Compromise of internal systems with no evidence of data leak | 4 hours |
| P3 | Vulnerability with no evidence of exploitation | 24 hours |
5. Stages
- Detection. Automated security alerts, external reports, observations during operations.
- Containment. Revoke compromised keys and tokens; disable the affected feature if needed. Keys are rotated on suspicion, without waiting for confirmation.
- Remediation. Fix the cause, not the symptom.
- Recovery. Return the service to normal operation and verify data integrity.
- Review. A test or control is added to prevent recurrence.
6. Reporting channels
External incident and vulnerability reports: security@tikshopro.com. Automated alerts for critical events reach the Incident Owner immediately, around the clock.
7. External notification
- For an incident affecting data from the TikTok Shop Open API, TikTok Shop is notified within 72 hours of confirmation.
- Affected sellers and users are notified directly within the same window.
- Regulators are notified within the timeframes set by applicable law.
Notification is not delayed until the investigation is complete. It is better to report a confirmed fact with an incomplete picture than a complete picture late.
8. What a notification contains
The notification format is fixed in advance, so that during an incident nobody has to decide what to write:
- date and time of detection;
- nature of the incident;
- categories of data affected;
- approximate number of sellers and records affected;
- containment measures taken;
- measures to prevent recurrence;
- a contact for follow-up.
If some details are still unknown when the notification is sent, that is stated plainly — the notification is not held back until they are established.
9. Documentation
Every P1 and P2 incident is documented: timeline, root cause, actions taken and measures to prevent recurrence. Reports are retained for at least two years.
10. Testing
The procedure is tested at least once a year: a tabletop scenario is worked through, alert delivery is verified and contact details are confirmed current.