Information Security Policy

Last updated: June 14, 2026

HAMMR maintains administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of the data processed by our inventory and sales-management application, including data obtained through the TikTok Shop Partner API. This document is our published information security program and is reviewed and updated as our practices evolve.

Access Control & Authentication

Data Classification

We classify the data we process and apply controls accordingly. Sensitive/personal data(e.g., buyer and recipient details contained in orders) and credentials (API keys, OAuth tokens) receive the strictest controls — encryption, least-privilege access, and minimal retention. Operational/business data (inventory, costs, sales totals) is protected by the same authentication and access controls. We collect only the data necessary for the Service to function.

Encryption

Data is encrypted in transit using HTTPS/TLS and encrypted at rest by our database provider. All connections to third-party APIs (including TikTok Shop) are made over TLS, and API requests are signed using TikTok’s required HMAC-SHA256 scheme.

Network & Infrastructure Security

The application is hosted on managed, industry-standard cloud providers (Supabase for database/auth, Vercel for application hosting), which operate on SOC 2-certified infrastructure. These providers enforce network segregation, perimeter protection, DDoS mitigation, and continuous threat monitoring at the infrastructure layer. We do not expose database servers directly to the public internet; database access is mediated through authenticated, row-level-secured APIs.

Endpoint & Operational Baseline

Credential & Secret Management

Sub-processors

We rely on established providers (Supabase, Vercel, and Anthropic for supplier-invoice document processing). We review the security posture of providers before integrating them and limit the data each receives to what is necessary. See our Privacy Policy.

Incident Response & Breach Notification

We maintain an incident response process with clear ownership: the business owner is the designated incident response lead and point of contact. Suspected incidents are detected through application and provider monitoring, then triaged, contained, and remediated. In the event of a confirmed breach affecting personal data, we will notify affected sellers and TikTok Shop, and the relevant regulatory authorities, without undue delay and as required by applicable law. Security issues can be reported to mshenbaum@gmail.com.

Vulnerability & Threat Management

We keep application dependencies up to date, monitor for disclosed vulnerabilities in the components we use, and remediate identified issues in a timely, risk-based manner.

Data Retention & Deletion

We retain data only as long as necessary for operational, accounting, and legal purposes. We will assist sellers and TikTok Shop in responding to end-user requests to access, update, or delete personal data, and upon termination of the integration we will delete the customer data in our possession.

Contact

To report a security concern or request more information about our practices, email mshenbaum@gmail.com.