$4,154.72
$1,133.31
$796.02
$794.07
$793.28
$778.74
$793.31
$784.30
$784.47
$3,180.77
$3,150.02
$3,123.54
$2,843.36
$49.99
$119.99
$99.99
$74.99
$119.99
$99.99
$32.20
$35.99
$35.99
$37.99
$32.79
$35.99
$34.29
$34.99
$161.76
$220.72
$192.02
$466.72
$591.52
$709.85
$719.96
$338.90
$643.20
$300.00
$395.99
$297.42
$1,026.84
$887.99
$3,179.99
$1,679.99
$539.99
$251.99
$455.99
$335.96
TieredUp Tech, Inc.
Version 1.0 — Effective May 24, 2026
Next Review: May 24, 2027
This Information Security Policy ("Policy") establishes the security controls TieredUp Tech, Inc. ("the Company") applies to information systems, customer data, and financial data under its control. The Policy is published in support of the Company's obligations to its customers, partners, and data providers including but not limited to Plaid Inc., Shopify Inc., RepairDesk LLC, and Chase Bank.
Scope. This Policy applies to all systems, networks, applications, and data owned, leased, or operated by the Company, including:
The Company is a single-officer organization. The President of the Company holds the following functional responsibilities:
| Role | Holder | Responsibilities |
|---|---|---|
| Information Security Officer | Coby Poluk, President | Sets policy, approves access, reviews controls quarterly |
| System Administrator | Coby Poluk, President | All technical administration |
| Data Custodian | Coby Poluk, President | Approves data classification and retention |
| Incident Response Lead | Coby Poluk, President | First responder for security incidents |
Because the Company has a single administrator, traditional role separation is not feasible. The Company implements compensating controls in lieu of role separation:
Other personnel (Lindsey Poluk, Charles Bray) have only point-of-sale (POS) access to RepairDesk under their own credentials. They do not have administrative access to the systems in Section 1.
All authorized users of Company systems must:
Authentication. All access to administrative systems is gated by:
Principle of Least Privilege. Each person is granted only the access required for their role. Non-administrative personnel are restricted to the systems they need (currently: RepairDesk POS only).
Access Review. Quarterly, the Information Security Officer reviews:
De-Provisioning. When personnel leave the Company:
The Company classifies data into four levels:
| Level | Definition | Examples |
|---|---|---|
| Restricted-Financial | Data subject to financial-services regulations | Plaid access tokens, bank account numbers, transaction history pulled via Plaid |
| Confidential | Sensitive business or customer data | Customer PII from Shopify, payment processor records, employee records, RepairDesk customer notes |
| Internal | Non-public business data | Pricing strategy, vendor agreements, internal procedures, source code |
| Public | Publicly available data | Marketing material, public website content, this Policy |
Data shall be handled at the level of its most sensitive component. When data of different classifications is combined, the combined dataset takes the highest classification of its parts.
In Transit. All data transmitted between systems uses TLS 1.2 or higher. The Company does not operate any service that accepts unencrypted (HTTP) connections for authenticated traffic.
At Rest. The Company hosts databases on shared infrastructure (Epik cPanel) that does not provide native disk-level encryption. The Company applies the following compensating controls:
In Use. Sensitive data is accessed only through authenticated administrative interfaces. Direct database access is restricted to the system administrator's authenticated cPanel session.
Retention. Data retention is governed by the Data Retention & Deletion Policy (separate document).
Multi-factor authentication (MFA) is enabled on every system that supports it, including:
MFA is implemented via TOTP authenticator app. SMS-based MFA is used only where the system does not support TOTP. Recovery codes for each MFA-protected system are stored in the password manager.
Workstations used to access administrative interfaces must:
Mobile devices used for MFA or administrative access must have a passcode or biometric lock and remote-wipe capability enabled.
The Company depends on the following critical service providers. Each provider has been reviewed for security posture; the Company maintains contracts and reviews their security disclosures annually.
| Provider | Service | Data Shared | Notes |
|---|---|---|---|
| Plaid Inc. | Bank data aggregation | Plaid access tokens, transaction data | SOC 2 Type II |
| Shopify Inc. | E-commerce platform | Customer PII, order data | PCI DSS Level 1 |
| Epik (cPanel hosting) | Web hosting | All Hub data | Shared hosting; encrypted-in-transit |
| Stripe | Payment processing | Tokenized card data | PCI DSS Level 1 |
| Square | Payment processing | Tokenized card data | PCI DSS Level 1 |
| RepairDesk LLC | Repair ticket management | Customer PII, ticket data | Reviewed annually |
| Vercel | Serverless hosting | Proxy service code | SOC 2 |
| Railway | Application hosting | Listing data | SOC 2 |
| GitHub | Source code hosting | All source code | SOC 2 |
| Password manager | Credential storage | All credentials | SOC 2 |
| Chase Bank | Banking | Account data | Bank-grade |
| Google Workspace | Email, Drive | Communications, documents | SOC 2 |
The Company does not share Restricted-Financial data with any provider outside this list without first updating this Policy.
A security incident is any event that compromises or threatens to compromise the confidentiality, integrity, or availability of Company data or systems.
Response procedure:
Reporting. Suspected incidents should be reported to security@tiereduptech.com or directly to the Information Security Officer.
Patching SLA:
| Severity | Patch Window |
|---|---|
| Critical (CVSS 9.0–10.0) | 7 calendar days |
| High (CVSS 7.0–8.9) | 30 calendar days |
| Medium (CVSS 4.0–6.9) | 90 calendar days |
| Low (CVSS 0.1–3.9) | Next scheduled maintenance |
Vulnerability scanning. The Company maintains automated vulnerability scanning for software dependencies (Composer, npm, GitHub Dependabot alerts), operating system updates (workstations and servers, automatic where possible), and container images and deployed applications.
End-of-life (EOL) software. The Company tracks the support lifecycle of all in-use software and operating systems. Software entering EOL is replaced before the EOL date when feasible, or within 90 days of EOL otherwise.
Current EOL inventory: PHP 8.3 (supported through Dec 2027); Ubuntu 22.04 LTS (supported through April 2027); Node.js LTS (rolling); all workstation OSes are within their support windows.
Changes to production systems follow this procedure:
For changes to systems handling Restricted-Financial data, the Information Security Officer maintains a deployment log.
The Company maintains the following logs:
| System | Log | Retention |
|---|---|---|
| Hub | Application logs (admin actions, audit trail) | 365 days |
| cPanel | Access logs, error logs | 90 days |
| Shopify | Admin activity log | Per Shopify retention |
| GitHub | Repository activity, audit log | Per GitHub retention |
| Plaid | API access logs | Per Plaid retention |
Logs are reviewed weekly (Hub audit log for unusual administrative activity), monthly (GitHub audit log for unauthorized repository access), and all relevant logs are preserved upon incident.
Backups:
Recovery testing: Backup restoration is tested annually.
For all personnel with administrative access:
The Company's office and retail location at 1812 N 16th St, Orange, TX, 77630 is secured by locked entry outside of business hours, an alarm system with monitoring, video surveillance of customer area, and locked storage for equipment in for repair. Workstations are not left logged in unattended.
The Company maintains documented procedures for redeploying critical services, all source code in GitHub (geographically redundant), daily database backups, and documented vendor contact information for emergency support. In the event of extended cPanel outage, services can be redeployed to alternate hosting using the documented infrastructure. Estimated recovery time: 72 hours.
This Policy is designed to support compliance with:
The Company does not handle data of children under 13 (COPPA), health information (HIPAA), or EU resident data subject to GDPR in the ordinary course of business.
This Policy is reviewed annually on or before the effective-date anniversary, after any significant change to systems, vendors, or scope, and after any security incident.
Quarterly self-audit checklist:
For questions, security incident reports, or policy clarification:
Coby Poluk, President & Information Security Officer
TieredUp Tech, Inc.
1812 N 16th St
Orange, TX, 77630, US
Email: security@tiereduptech.com (or coby@tiereduptech.com)
For coordinated vulnerability disclosure: please report directly to the above email. The Company commits to acknowledging vulnerability reports within 72 hours.
This Policy is published at https://tiereduptech.com/pages/security and is the authoritative version.
At TieredUp Tech, Inc., we deliver top-quality repairs and custom-built computer systems, ensuring every device performs at its best for our valued customers.
!