Information Security Policy
Last updated: September 24, 2026
LASI is a multi-tenant service: many auction-selling businesses run on one platform, and each one’s inventory, costs, sales, and orders must stay its own. This page describes the technical and organizational measures we keep in place to make that true, including for data obtained through the TikTok Shop Partner API and other platforms our customers connect. It is reviewed and updated as our practices evolve. What we collect and why is on the Privacy Policy.
Access Control & Authentication
- Every person signs in with an individual account (email and password, or Google); there are no shared logins for data access.
- Access inside an organization follows least privilege through five roles:
- Admin — sees everything, including costs, profit, expenses, and billing.
- Manager — operations and revenue; no costs, profit, or expenses.
- Host — runs shows; sees revenue and commission for their own shows only.
- Staff — stages, scans, sells, reconciles, and checks in returned packages; sees no money at all.
- Customer service — replacement requests and TikTok returns; sees the refund on the request in front of them and no other money.
- Role checks are enforced in four layers: route confinement, a gate on every API route, cost-field redaction in responses, and role-aware row-level security in the database.
Tenant Isolation
- Every table carries an organization id and is protected by row-level security, so a session can only read or write its own organization’s rows.
- Every API route re-checks the organization in application code; no route trusts an id sent by the client.
- Incoming webhooks (Shopify, Whop, TikTok Shop) are verified by HMAC signature over the raw body before any data is routed to an organization; an unsigned or mis-signed request is dropped, a redelivered notification is a no-op, and a TikTok notification is only ever a signal to re-read the return from TikTok’s API — its payload is stored as identifiers and statuses, never as buyer data.
- Scheduled jobs run behind a secret and touch one organization at a time.
- A Returns desk photo link (the QR code a phone scans to add photos of a returned package) is a random 15-minute token stored only as a hash; it can add photos to that one package and do nothing else, and requests through it are rate-limited.
- The Claude (MCP) integration authenticates with hashed tokens over OAuth 2.1 with PKCE, works only while the admin who connected it is still an admin, and is bound by the same billing lock as the app. It cannot sell, finalize a show, refund a buyer, delete stock or sales, or change the cost of anything already in stock; inventory it adds goes in through the same FIFO functions the app uses. It never sends a buyer's name or address.
Data Classification
Credentials (API keys, OAuth tokens) and personal data (team members’ contact details, buyer display names on orders, and the shipping address on a box whose label you buy or upload here) receive the strictest controls: encryption, least-privilege access, and minimal retention. Operational business data (inventory, costs, sales totals) is protected by the same authentication, role, and isolation controls. We collect only what the Service needs to function.
Encryption
Data is encrypted in transit using HTTPS/TLS and at rest by our database provider. All connections to third-party APIs are made over TLS; TikTok Shop requests are signed with TikTok’s required HMAC-SHA256 scheme.
Credential & Secret Management
- Application secrets and our own API keys live in the hosting provider’s encrypted environment store — never in source control.
- Customer OAuth tokens (TikTok Shop, Shopify) and the Homebase API key are stored in the database encrypted with AES-256-GCM under a key that exists only in that store.
- The application refuses to store a token unencrypted in production.
- OAuth tokens are refreshed automatically and can be revoked at any time by disconnecting the integration; disconnecting deletes them.
- When a seller removes LASI’s access in TikTok Shop itself, TikTok notifies us; unless TikTok, asked again, still lists the shop as connected, we delete that shop’s stored tokens at once and stop reading from it.
Platform Operator Access
We do not read your business data to run our business. Platform operators are a fixed allowlist of named accounts — not a role a customer can grant. The operator console shows organization names, subscription and billing status, integration connection health, and an audit trail of administrative actions; it does not show inventory, costs, sales, orders, or profit. There is no “log in as customer” feature, and operator console visits are logged. Automated nightly jobs read each organization’s data only to produce that organization’s own reports and never move data between organizations.
Decisions Sent to TikTok
Answering a buyer’s return, refund or cancellation request from LASI — or refunding or cancelling an order the seller’s own team chooses to — moves the buyer’s money, so it is guarded separately:
- Sending decisions is off until an organization admin turns it on, and the admin can turn it off at any time, instantly.
- Right before anything is sent, the request is read again from TikTok together with TikTok’s own list of the decisions it allows; if the request changed, nothing is sent.
- Each decision is sent at most once: it carries a unique key TikTok recognises, and a request TikTok did not answer is settled by reading the return back, never by sending it again.
- A customer-service refund above the organization’s limit waits for an admin, who sees a fresh check before approving; if the request changed meanwhile, it expires. Refunding or cancelling an order outright is for admins and managers only, and a refund over the limit needs their explicit confirmation.
- Every decision, approval, refusal and outcome is written to the audit trail.
- Outside production, the application can send decisions only to a local test server.
Buying Shipping Labels
Buying a label spends the customer’s own money with a carrier, so it is guarded the same way:
- Buying is off for every organization until that organization’s admin turns it on.
- The browser never says what a box weighs or costs. The plan is rebuilt on the server from the order and the customer’s own shipping rules before anything is bought, and a box those rules cannot price is held rather than guessed at.
- Each box is claimed in the database before the carrier is called, so two people pressing Buy at two benches cannot buy the same label twice.
- A label that exists is never reported as a failure: a failed print or a failed tracking push retries only that step, never the purchase.
- Labels are bought on the customer’s own carrier account and bill to it; every purchase is recorded with who pressed it and which environment it ran in.
Application Hardening
- Security headers on every response:
frame-ancestors 'none',nosniff, a strict referrer policy, and HSTS. - Rate limiting on account creation, invite redemption, API-token endpoints, and Returns desk photo links.
- Dependency vulnerability monitoring with prompt upgrades.
- Automated type and lint checks in CI on every change; a change that fails them does not ship.
- An append-only audit trail visible to organization admins (below).
Audit Trail
Organization admins can view their own audit log in Settings: show deletes, finalizes, date changes, team removals, data exports, and host links, each with who did it and when. Entries are written by the server, not the browser, and cannot be edited or deleted from the app.
Network & Infrastructure Security
The application is hosted on managed, industry-standard cloud providers (Supabase for database, auth, and storage; Vercel for application hosting) operating on SOC 2-certified infrastructure with network segregation, DDoS mitigation, and continuous monitoring at the infrastructure layer. Database servers are never exposed directly to the public internet; access is mediated through authenticated, row-level-secured APIs.
Endpoint & Operational Baseline
- Company endpoints run operating-system anti-malware protection and receive security updates.
- Endpoints enforce automatic screen locking and strong passwords.
- Multi-factor authentication is enabled on critical accounts (email, hosting, source control, and the TikTok Shop Partner account).
Sub-processors
We rely on established providers and limit the data each receives to what its job needs. The complete list, and the connected platforms that are your data sources rather than our processors, is on the Privacy Policy. We review a provider’s security posture before integrating it.
Incident Response & Breach Notification
We maintain an incident response process with clear ownership: the business owner is the designated incident response lead and point of contact. Suspected incidents are detected through application and provider monitoring, then triaged, contained, and remediated. In the event of a confirmed breach affecting personal data, we will notify affected customers, and platform partners and regulators where required, without undue delay and in any case within 72 hours of confirming a breach affecting personal data, with what we know about scope and mitigation. Security issues can be reported to support@trylasi.com.
Vulnerability & Threat Management
We keep application dependencies up to date, monitor for disclosed vulnerabilities in the components we use, and remediate identified issues in a timely, risk-based manner.
Data Retention & Deletion
- Data is retained for as long as the customer’s account is active.
- When a customer deletes its business, primary database records are deleted immediately (cascading delete); provider backups age out within 30 days.
- Audit and billing records the law requires us to keep (invoices, payment ledger) are retained for 7 years.
- We assist customers in responding to requests from their buyers to access, update, or delete personal data, and refer requests that reach us directly to the customer.
Contact
To report a security concern or request more information about our practices, email support@trylasi.com.