Information Security Policy — GCG / Tiktok Pulse

Version 1.0 · Effective September 4, 2026 · Reviewed at least annually · Owner: André Fogelman (Security Officer & DPO) — andre@anf.com.br

This page is the published, publicly verifiable version of our information security policy. Sections marked How to verify describe checks any external reviewer can perform independently, without an account.

1. Purpose and scope

This policy governs the Tiktok Pulse platform (https://tiktok-pulse.com.br), a TikTok Shop campaign monitoring panel operated by GCG | Growth & Commerce Group for its agency clients. It covers the production application, its database, the hosting infrastructure, and all personnel with access to customer data.

2. Access control and least privilege

  • No public sign-up. Accounts exist only through single-use, expiring invitations issued by an administrator.
  • Role-based access control enforced server-side: admin (full), user (operations, no settings), guest (read-only, scoped to a single client — queries are filtered at the database layer, so a guest cannot reach another client's shops even by crafting URLs or export parameters).
  • Infrastructure access (SSH, private network) is restricted to the Security Officer. The private network (WireGuard-based mesh) has a single authorized user account; production SSH accepts only two keys, one of which is a deploy key restricted to a single directory.
  • Accounts are deactivated immediately when access is no longer required.

How to verify: open /users/register — it returns 404 (no public registration). The login page offers no sign-up path.

3. Authentication and MFA

  • Passwords hashed with Argon2; minimum length 10 characters.
  • Two-factor authentication (TOTP) per RFC 6238: authenticator-app enrollment with QR code, proof-of-possession required to enable, 8 single-use hashed backup codes, per-window replay protection, and incremental lockout after repeated failures. The 2FA challenge applies to both password and Google sign-in.
  • Optional Google OAuth (OpenID Connect) with basic scopes only (email, profile).
  • Session tokens are opaque, stored server-side, and expire after 14 days.

How to verify: the sign-in flow at /users/log-in is the only entry point; accounts with 2FA enabled are challenged at /users/two-factor before any session is created.

4. Encryption

  • In transit: all traffic is TLS (Let's Encrypt certificates, auto-renewed); plain HTTP is redirected to HTTPS with HSTS enabled.
  • At rest (application layer): TikTok Shop API credentials (access/refresh tokens) are encrypted with AES-256-GCM before touching the database; encryption keys are stored outside the database with restricted file permissions. TOTP secrets receive the same treatment. Passwords and backup codes are stored only as one-way hashes.

How to verify: curl -sI https://tiktok-pulse.com.br shows the strict-transport-security header; the TLS certificate is publicly auditable (e.g. crt.sh for tiktok-pulse.com.br) and any browser shows the chain. HTTP on port 80 answers only with a 301 to HTTPS.

5. Network segregation

  • The application and the PostgreSQL database listen on localhost only, behind an nginx reverse proxy. The database is not reachable from the internet.
  • Administrative access happens over a private WireGuard-based mesh network, never over publicly exposed management ports.

How to verify: a port scan of tiktok-pulse.com.br shows no exposed database port (5432/5434); only 80/443 serve this application.

6. Vulnerability management

  • Operating system security patches are applied automatically (unattended upgrades) on the production host.
  • The application runs in containers rebuilt from a pinned base image on every deployment; dependencies are version-locked and updated deliberately.
  • Every change passes an automated test suite (≈370 tests, including authentication, authorization-scoping and webhook-signature tests) before reaching production.

7. Backup and recovery

  • Daily automated database backups, retained for 14 days on the host.
  • Restore procedure documented and tested.

8. Incident response and breach notification

  1. Detect & contain — isolate the affected component; revoke or rotate exposed credentials (TikTok tokens can be invalidated via the seller's authorization panel and re-issued).
  2. Assess — determine scope, affected data, and affected sellers.
  3. Notify — affected sellers and TikTok Shop without undue delay, and the Brazilian data-protection authority (ANPD) where legally required by the LGPD.
  4. Remediate & review — root-cause fix, then a written post-incident review.

Single point of contact for security reports and incidents: andre@anf.com.br.

How to verify: the machine-readable security contact is published per RFC 9116 at /.well-known/security.txt.

9. Data protection, retention and deletion

  • Personal data handling is governed by our published Privacy Policy (LGPD-aligned; DPO appointed).
  • Data is retained only while the seller's authorization and the service relationship are active; on contract end or verified request, related data is deleted, corrected or exported within 15 days.
  • We assist sellers and TikTok Shop with user data deletion/update/access requests.

How to verify: /privacy is public and names the DPO, the storage location (São Paulo, Brazil), the sub-processors, and the deletion SLA.

10. Endpoint and personnel security

  • Team endpoints are Apple devices with the platform's built-in protections enabled (Gatekeeper, XProtect, FileVault-capable), automatic updates on, and screen lock enforced.
  • Credentials are stored in managed keychains/secret stores; secrets are never committed to source control (repository is private; deploy uses a read-only key).

11. Sub-processors

  • Hostinger (VPS hosting, São Paulo, Brazil) — production infrastructure.
  • Resend (United States) — transactional e-mail delivery.
  • Cloudflare — DNS only (no traffic proxying).

12. Policy review

This policy is reviewed at least annually, and after any material change to the platform or any security incident. The current published version at this URL is authoritative.