1. Security Program
Security is integrated into the design, development, operation, and support of AlcaAds. Our safeguards are selected according to the nature of the data, the sensitivity of connected-account credentials, the purpose of the Services, and foreseeable risks to confidentiality, integrity, and availability. Controls are reviewed and improved as the platform, applicable law, and threat landscape evolve.
No system can eliminate all risk. We therefore apply defense-in-depth: preventative controls, detection and logging, response procedures, and continuity measures. Customers also play an essential role by protecting credentials, assigning appropriate roles, reviewing connected accounts, and reporting suspected misuse promptly.
2. Encryption
AlcaAds is designed to protect data in transit using modern transport-layer encryption and to protect sensitive data at rest using encryption mechanisms appropriate to the storage environment. TikTok authorization tokens and similar integration credentials are treated as sensitive secrets: access is restricted, storage is protected, and they are not displayed in ordinary user interfaces or support responses.
Encryption is one component of security rather than a substitute for access control, monitoring, secure development, or incident response. We maintain procedures intended to rotate, invalidate, or replace credentials when a connection is revoked, an exposure is suspected, or a provider requires it.
3. Authentication and Password Security
Access to AlcaAds is protected through authenticated account sessions, secure transport, session-management safeguards, and controls designed to resist common account attacks. Passwords, when AlcaAds credentials are used, should never be stored or transmitted in readable form. We encourage Users to use unique, strong passwords and to protect any linked identity provider or TikTok account with the security measures offered by that provider.
TikTok Login Kit authorizes access through TikTok's authentication flow. AlcaAds does not ask for, receive, or store a User's TikTok password. Login and connection events may be logged to investigate fraud, unauthorized access, and integration issues.
4. Access Control
AlcaAds applies least-privilege and need-to-know principles. Customer workspace access is segmented by account and role. Internal access to production systems or customer data is limited to authorized personnel with a legitimate operational purpose, such as support, security, or maintenance, and is subject to administrative safeguards and logging where appropriate.
Access rights are reviewed and may be changed or removed when a role changes, access is no longer needed, a security concern arises, or a contractual relationship ends. We do not grant access to a connected TikTok account unless the authorized User has completed the relevant connection flow and holds the necessary authority.
5. Data Storage and Secure APIs
We limit data collection and storage to information needed for the AlcaAds service. Data is logically associated with the applicable account or workspace. We apply validation, authorization, request controls, and error-handling practices intended to protect API endpoints against unauthorized requests, malformed input, and common abuse patterns.
Connections to TikTok use TikTok-provided authorization and API mechanisms. AlcaAds uses TikTok data only for the requested platform features, such as showing authorized advertising data, generating reports, analytics, and campaign-management actions. Users may revoke permission or request deletion as described in the TikTok API Data Deletion Instructions.
6. Infrastructure Security
AlcaAds uses managed infrastructure and service providers selected for reliability and security capabilities appropriate to a SaaS environment. We implement configuration, network, secret-management, and deployment controls designed to reduce exposure and separate operational duties. Production changes are subject to review and testing practices proportionate to the change and risk.
Third-party providers remain responsible for their own infrastructure. We evaluate relevant provider assurances and contractual commitments, but no third-party service is treated as risk-free. We maintain appropriate data-processing, confidentiality, and security requirements with service providers where applicable.
7. Security Monitoring and Incident Response
We maintain operational logging and monitoring intended to identify suspicious activity, system errors, and service degradation. Signals may include authentication anomalies, unexpected API failures, permission changes, unusual access patterns, and infrastructure alerts. Logs are access-controlled and retained in accordance with operational and legal needs.
Our incident-response process is designed to support triage, containment, investigation, remediation, and communication. If we determine that a security incident has affected Personal Data, we will assess notification obligations and notify affected Customers, users, regulators, or other parties as required by applicable law and our contractual commitments.
8. Backups and Business Continuity
We use backups and recovery practices designed to support service continuity and restoration following an outage or data-loss event. Backups are protected using controls appropriate to their environment and are not used for ordinary product processing. Recovery operations are limited to authorized personnel and follow operational procedures. Backup retention is finite; data deleted from active systems is removed through normal backup rotation unless a legal obligation requires preservation.
9. Vulnerability Management
We evaluate reported and identified vulnerabilities based on severity, exploitability, affected systems, and potential impact. Remediation may include patches, configuration changes, compensating controls, dependency updates, credential rotation, or service changes. We prioritize material security risks and work to reduce exposure through secure development, testing, monitoring, and updates.
To report a potential security issue, do not include sensitive credentials in ordinary email. Send a concise description to support@alcaads.com; we will coordinate a secure follow-up channel if needed.
10. Security Contact
For security questions or reports, email support@alcaads.com. For privacy or data deletion matters, see our Privacy Policy and Data Deletion Policy.
Website: https://alcaads.com
Application: https://app.alcaads.com