Information Security Policy

Information Security Policy

TieredUp Tech, Inc.

Version 1.0 — Effective May 24, 2026

Next Review: May 24, 2027


1. Purpose & Scope

This Information Security Policy ("Policy") establishes the security controls TieredUp Tech, Inc. ("the Company") applies to information systems, customer data, and financial data under its control. The Policy is published in support of the Company's obligations to its customers, partners, and data providers including but not limited to Plaid Inc., Shopify Inc., RepairDesk LLC, and Chase Bank.

Scope. This Policy applies to all systems, networks, applications, and data owned, leased, or operated by the Company, including:

  • The customer-facing e-commerce site at tiereduptech.com (Shopify-hosted)
  • The internal operations application "Hub" at hub.tiereduptech.com
  • The application services site at app.tiereduptech.com
  • The eBay integration service at ebay.tiereduptech.com (Railway-hosted)
  • The proxy service bitcrate-proxy.vercel.app
  • The ticket filing service running on cPanel
  • All endpoints (workstations, mobile devices) used to access the above
  • All third-party services storing the Company's business or customer data

2. Roles & Responsibilities

The Company is a single-officer organization. The President of the Company holds the following functional responsibilities:

Role Holder Responsibilities
Information Security Officer Coby Poluk, President Sets policy, approves access, reviews controls quarterly
System Administrator Coby Poluk, President All technical administration
Data Custodian Coby Poluk, President Approves data classification and retention
Incident Response Lead Coby Poluk, President First responder for security incidents

Because the Company has a single administrator, traditional role separation is not feasible. The Company implements compensating controls in lieu of role separation:

  • All administrative actions are logged with timestamps in the systems they affect
  • All write access to production systems requires multi-factor authentication
  • A documented change log is maintained for production deployments
  • Quarterly self-audit using the checklist in Section 19

Other personnel (Lindsey Poluk, Charles Bray) have only point-of-sale (POS) access to RepairDesk under their own credentials. They do not have administrative access to the systems in Section 1.

3. Acceptable Use

All authorized users of Company systems must:

  • Use unique, randomly generated passwords stored in a password manager
  • Enable multi-factor authentication on every account that supports it
  • Not share credentials with any other person under any circumstances
  • Report suspected security incidents to the Information Security Officer within 24 hours
  • Not install unauthorized software on systems used to access Company data
  • Log out of administrative interfaces when not actively in use
  • Not connect to administrative interfaces from public Wi-Fi without VPN

4. Access Control

Authentication. All access to administrative systems is gated by:

  1. Unique username per individual
  2. Password meeting these minimum requirements: at least 16 characters, stored only in a password manager, unique per system
  3. Multi-factor authentication (TOTP authenticator app)

Principle of Least Privilege. Each person is granted only the access required for their role. Non-administrative personnel are restricted to the systems they need (currently: RepairDesk POS only).

Access Review. Quarterly, the Information Security Officer reviews:

  • Active accounts in each system
  • Permission levels assigned to each account
  • API tokens, OAuth grants, and SSH keys
  • Inactive accounts to be disabled

De-Provisioning. When personnel leave the Company:

  1. Password manager access revoked
  2. RepairDesk account disabled
  3. Any device access revoked
  4. Email forwarding configured if needed for handoff
  5. De-provisioning completed within 24 hours of separation

5. Data Classification

The Company classifies data into four levels:

Level Definition Examples
Restricted-Financial Data subject to financial-services regulations Plaid access tokens, bank account numbers, transaction history pulled via Plaid
Confidential Sensitive business or customer data Customer PII from Shopify, payment processor records, employee records, RepairDesk customer notes
Internal Non-public business data Pricing strategy, vendor agreements, internal procedures, source code
Public Publicly available data Marketing material, public website content, this Policy

Data shall be handled at the level of its most sensitive component. When data of different classifications is combined, the combined dataset takes the highest classification of its parts.

6. Data Protection

In Transit. All data transmitted between systems uses TLS 1.2 or higher. The Company does not operate any service that accepts unencrypted (HTTP) connections for authenticated traffic.

At Rest. The Company hosts databases on shared infrastructure (Epik cPanel) that does not provide native disk-level encryption. The Company applies the following compensating controls:

  • Plaid access tokens are stored in the Hub database; rotation procedures are documented
  • Bank account numbers from Plaid are stored only as the last-4-digit "mask" — full account numbers are not retained
  • Payment card numbers are never stored by the Company; all payment processing is handled by Shopify Payments, Stripe, and Square under PCI-compliant terms
  • Database backups are stored in the same hosting account and inherit its access controls
  • Roadmap item: migration of Restricted-Financial data to encrypted-at-rest storage by end of fiscal year 2026

In Use. Sensitive data is accessed only through authenticated administrative interfaces. Direct database access is restricted to the system administrator's authenticated cPanel session.

Retention. Data retention is governed by the Data Retention & Deletion Policy (separate document).

7. Authentication & Multi-Factor Authentication

Multi-factor authentication (MFA) is enabled on every system that supports it, including:

  • Hub administrative login (hub.tiereduptech.com)
  • Shopify Admin
  • cPanel / Epik hosting
  • Plaid Dashboard
  • RepairDesk Admin
  • GitHub (organization-wide enforcement)
  • Vercel
  • Chase Business Banking
  • All email accounts under tiereduptech.com

MFA is implemented via TOTP authenticator app. SMS-based MFA is used only where the system does not support TOTP. Recovery codes for each MFA-protected system are stored in the password manager.

8. Endpoint Security

Workstations used to access administrative interfaces must:

  • Run a currently supported operating system with automatic updates enabled
  • Have full-disk encryption enabled (FileVault, BitLocker, or equivalent)
  • Have screen lock enforced after 5 minutes of inactivity
  • Run anti-malware software
  • Be password- or biometric-protected at the OS level

Mobile devices used for MFA or administrative access must have a passcode or biometric lock and remote-wipe capability enabled.

9. Vendor & Third-Party Risk Management

The Company depends on the following critical service providers. Each provider has been reviewed for security posture; the Company maintains contracts and reviews their security disclosures annually.

Provider Service Data Shared Notes
Plaid Inc. Bank data aggregation Plaid access tokens, transaction data SOC 2 Type II
Shopify Inc. E-commerce platform Customer PII, order data PCI DSS Level 1
Epik (cPanel hosting) Web hosting All Hub data Shared hosting; encrypted-in-transit
Stripe Payment processing Tokenized card data PCI DSS Level 1
Square Payment processing Tokenized card data PCI DSS Level 1
RepairDesk LLC Repair ticket management Customer PII, ticket data Reviewed annually
Vercel Serverless hosting Proxy service code SOC 2
Railway Application hosting Listing data SOC 2
GitHub Source code hosting All source code SOC 2
Password manager Credential storage All credentials SOC 2
Chase Bank Banking Account data Bank-grade
Google Workspace Email, Drive Communications, documents SOC 2

The Company does not share Restricted-Financial data with any provider outside this list without first updating this Policy.

10. Incident Response

A security incident is any event that compromises or threatens to compromise the confidentiality, integrity, or availability of Company data or systems.

Response procedure:

  1. Detect. Incidents may be detected through monitoring, vendor notification, user report, or external disclosure.
  2. Contain. Within 1 hour of detection: isolate affected systems, rotate exposed credentials, block compromised access.
  3. Assess. Within 24 hours: determine what data was affected, what systems were involved, the timeline, and the likely cause.
  4. Notify. Within 72 hours of confirmed breach of personal data: affected individuals per Texas Business & Commerce Code §521.053, Plaid Inc. if Plaid-related, affected vendors per contract terms, and law enforcement if criminal activity is suspected.
  5. Remediate. Fix the root cause; apply additional controls to prevent recurrence.
  6. Document. Maintain a written incident record with timeline, response actions, and lessons learned.

Reporting. Suspected incidents should be reported to security@tiereduptech.com or directly to the Information Security Officer.

11. Vulnerability Management & Patching

Patching SLA:

Severity Patch Window
Critical (CVSS 9.0–10.0) 7 calendar days
High (CVSS 7.0–8.9) 30 calendar days
Medium (CVSS 4.0–6.9) 90 calendar days
Low (CVSS 0.1–3.9) Next scheduled maintenance

Vulnerability scanning. The Company maintains automated vulnerability scanning for software dependencies (Composer, npm, GitHub Dependabot alerts), operating system updates (workstations and servers, automatic where possible), and container images and deployed applications.

End-of-life (EOL) software. The Company tracks the support lifecycle of all in-use software and operating systems. Software entering EOL is replaced before the EOL date when feasible, or within 90 days of EOL otherwise.

Current EOL inventory: PHP 8.3 (supported through Dec 2027); Ubuntu 22.04 LTS (supported through April 2027); Node.js LTS (rolling); all workstation OSes are within their support windows.

12. Change Management

Changes to production systems follow this procedure:

  1. Change is developed in a non-production environment (local development, branch, or staging where applicable)
  2. Code changes are committed to GitHub with a descriptive commit message
  3. For database schema changes, a migration script is created
  4. Change is deployed to production
  5. Functional verification is performed immediately post-deployment
  6. Rollback procedure is identified prior to deployment

For changes to systems handling Restricted-Financial data, the Information Security Officer maintains a deployment log.

13. Logging & Monitoring

The Company maintains the following logs:

System Log Retention
Hub Application logs (admin actions, audit trail) 365 days
cPanel Access logs, error logs 90 days
Shopify Admin activity log Per Shopify retention
GitHub Repository activity, audit log Per GitHub retention
Plaid API access logs Per Plaid retention

Logs are reviewed weekly (Hub audit log for unusual administrative activity), monthly (GitHub audit log for unauthorized repository access), and all relevant logs are preserved upon incident.

14. Backup & Recovery

Backups:

  • Hub database: Daily automated backup via cPanel, retained 30 days
  • Source code: Git history on GitHub provides version recovery
  • Shopify data: Backed up by Shopify per their SLA
  • Critical configuration: Documented in the Hub project documentation

Recovery testing: Backup restoration is tested annually.

15. Personnel Security

For all personnel with administrative access:

  • Background reference checks at hire (informal for owner-officers)
  • Onboarding includes review of this Policy and acknowledgment in writing
  • Annual re-acknowledgment of the Policy
  • Offboarding follows the de-provisioning procedure in Section 4

16. Physical Security

The Company's office and retail location at 1812 N 16th St, Orange, TX, 77630 is secured by locked entry outside of business hours, an alarm system with monitoring, video surveillance of customer area, and locked storage for equipment in for repair. Workstations are not left logged in unattended.

17. Business Continuity

The Company maintains documented procedures for redeploying critical services, all source code in GitHub (geographically redundant), daily database backups, and documented vendor contact information for emergency support. In the event of extended cPanel outage, services can be redeployed to alternate hosting using the documented infrastructure. Estimated recovery time: 72 hours.

18. Compliance References

This Policy is designed to support compliance with:

  • PCI DSS — by ensuring payment card data is never stored by the Company (all card processing is outsourced to PCI-compliant providers)
  • Plaid Network Agreement — by implementing the security controls Plaid requires of data recipients
  • Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code §521) — by providing breach notification procedures
  • Texas Sales Tax — by maintaining records adequate for state tax authorities
  • GLBA Safeguards Rule principles — where applicable to financial data handling
  • CCPA / state privacy laws — by maintaining the published Privacy Policy at tiereduptech.com/policies/privacy-policy

The Company does not handle data of children under 13 (COPPA), health information (HIPAA), or EU resident data subject to GDPR in the ordinary course of business.

19. Policy Review

This Policy is reviewed annually on or before the effective-date anniversary, after any significant change to systems, vendors, or scope, and after any security incident.

Quarterly self-audit checklist:

  • ☐ Active accounts in each system reviewed; inactive accounts disabled
  • ☐ MFA verified enabled on every system in Section 7
  • ☐ Patching status: no Critical vulnerabilities open past 7 days
  • ☐ Patching status: no High vulnerabilities open past 30 days
  • ☐ Backup verified: at least one recent restore test
  • ☐ Vendor list (Section 9) reviewed; no new vendors added without policy update
  • ☐ Audit logs reviewed for the past quarter

20. Contact

For questions, security incident reports, or policy clarification:

Coby Poluk, President & Information Security Officer
TieredUp Tech, Inc.
1812 N 16th St
Orange, TX, 77630, US
Email: security@tiereduptech.com (or coby@tiereduptech.com)

For coordinated vulnerability disclosure: please report directly to the above email. The Company commits to acknowledging vulnerability reports within 72 hours.


This Policy is published at https://tiereduptech.com/pages/security and is the authoritative version.