Information Security Policy

Last updated: September 24, 2026

LASI is a multi-tenant service: many auction-selling businesses run on one platform, and each one’s inventory, costs, sales, and orders must stay its own. This page describes the technical and organizational measures we keep in place to make that true, including for data obtained through the TikTok Shop Partner API and other platforms our customers connect. It is reviewed and updated as our practices evolve. What we collect and why is on the Privacy Policy.

Access Control & Authentication

Tenant Isolation

Data Classification

Credentials (API keys, OAuth tokens) and personal data (team members’ contact details, buyer display names on orders, and the shipping address on a box whose label you buy or upload here) receive the strictest controls: encryption, least-privilege access, and minimal retention. Operational business data (inventory, costs, sales totals) is protected by the same authentication, role, and isolation controls. We collect only what the Service needs to function.

Encryption

Data is encrypted in transit using HTTPS/TLS and at rest by our database provider. All connections to third-party APIs are made over TLS; TikTok Shop requests are signed with TikTok’s required HMAC-SHA256 scheme.

Credential & Secret Management

Platform Operator Access

We do not read your business data to run our business. Platform operators are a fixed allowlist of named accounts — not a role a customer can grant. The operator console shows organization names, subscription and billing status, integration connection health, and an audit trail of administrative actions; it does not show inventory, costs, sales, orders, or profit. There is no “log in as customer” feature, and operator console visits are logged. Automated nightly jobs read each organization’s data only to produce that organization’s own reports and never move data between organizations.

Decisions Sent to TikTok

Answering a buyer’s return, refund or cancellation request from LASI — or refunding or cancelling an order the seller’s own team chooses to — moves the buyer’s money, so it is guarded separately:

Buying Shipping Labels

Buying a label spends the customer’s own money with a carrier, so it is guarded the same way:

Application Hardening

Audit Trail

Organization admins can view their own audit log in Settings: show deletes, finalizes, date changes, team removals, data exports, and host links, each with who did it and when. Entries are written by the server, not the browser, and cannot be edited or deleted from the app.

Network & Infrastructure Security

The application is hosted on managed, industry-standard cloud providers (Supabase for database, auth, and storage; Vercel for application hosting) operating on SOC 2-certified infrastructure with network segregation, DDoS mitigation, and continuous monitoring at the infrastructure layer. Database servers are never exposed directly to the public internet; access is mediated through authenticated, row-level-secured APIs.

Endpoint & Operational Baseline

Sub-processors

We rely on established providers and limit the data each receives to what its job needs. The complete list, and the connected platforms that are your data sources rather than our processors, is on the Privacy Policy. We review a provider’s security posture before integrating it.

Incident Response & Breach Notification

We maintain an incident response process with clear ownership: the business owner is the designated incident response lead and point of contact. Suspected incidents are detected through application and provider monitoring, then triaged, contained, and remediated. In the event of a confirmed breach affecting personal data, we will notify affected customers, and platform partners and regulators where required, without undue delay and in any case within 72 hours of confirming a breach affecting personal data, with what we know about scope and mitigation. Security issues can be reported to support@trylasi.com.

Vulnerability & Threat Management

We keep application dependencies up to date, monitor for disclosed vulnerabilities in the components we use, and remediate identified issues in a timely, risk-based manner.

Data Retention & Deletion

Contact

To report a security concern or request more information about our practices, email support@trylasi.com.