Vismor Information Security Policy

Effective date: August 22, 2026
Last reviewed: August 22, 2026

1. Purpose

Vismor is committed to protecting the confidentiality, integrity, and availability of information used in its business operations and internal applications.

This Information Security Policy establishes the security practices applied to Vismor's systems, devices, credentials, and applications, including VSM Creator Analytics, an internal tool used to support content creation and TikTok Shop affiliate analysis.

2. Scope

This policy applies to:

  • Devices used to access Vismor business systems.

  • Administrative accounts and credentials.

  • VSM Creator Analytics.

  • TikTok Shop API credentials, authorization tokens, and data accessed through approved APIs.

  • Other business information processed by Vismor.

VSM Creator Analytics is currently intended for internal use by Vismor and is not offered as a public consumer service.

3. Access Control

Access to VSM Creator Analytics and related administrative systems is restricted to authorized personnel.

Vismor follows the principle of least privilege. Access is granted only to the information and permissions required for the intended business purpose.

Administrative accounts use strong, unique passwords and multi-factor authentication whenever the service supports it.

Credentials are not shared between unauthorized users.

4. API Credentials and Authentication Tokens

TikTok Shop API credentials and authorization tokens are treated as confidential information.

Application secrets are not embedded in public source code, client-side code, or publicly accessible repositories.

On supported Apple devices, sensitive application credentials and authorization tokens are stored using the macOS Keychain or another appropriately protected credential storage mechanism.

VSM Creator Analytics requests only API permissions required for its intended functionality.

5. Endpoint Security

Devices used to access Vismor systems are protected through security controls provided by the operating system.

For macOS devices, these controls include:

  • Apple XProtect malware protection.

  • Gatekeeper application security.

  • Automatic security and operating system updates.

  • Device authentication.

  • Automatic screen locking.

  • Full-disk encryption where applicable.

  • Host firewall protection where applicable.

Unauthorized software should not be installed on devices used to process protected business information.

6. Network Security

Vismor minimizes unnecessary exposure of internal services to public networks.

Development services used by VSM Creator Analytics are restricted to the local device whenever possible.

The application's OAuth callback used during local development operates through localhost and is not intentionally exposed as a public internet service.

Devices are protected by host-level security controls and should only connect to trusted networks when handling sensitive credentials or business information.

7. Data Minimization

Vismor only accesses and processes information required to provide the intended functionality of its applications.

VSM Creator Analytics is designed to use the minimum TikTok Shop API permissions necessary for affiliate-product analysis.

Data unrelated to the application's stated purpose is not intentionally collected.

8. Data Storage and Retention

Vismor minimizes the permanent storage of TikTok Shop information.

Authentication credentials and tokens are stored separately from application source code and protected using secure credential storage.

Business data is retained only for as long as necessary for operational, analytical, legal, or security purposes.

Data that is no longer required should be securely deleted.

9. Data Sharing

Vismor does not sell TikTok Shop data or authentication credentials.

Protected information is not shared with third parties unless necessary to operate an authorized service, comply with applicable law, or fulfill a legitimate business requirement.

Third-party services are evaluated before being provided access to confidential information.

10. Security Updates

Operating systems, browsers, applications, and security components used to access protected information are maintained with current security updates whenever reasonably possible.

Known critical security updates should be installed without unnecessary delay.

11. Incident Response

Suspected security incidents involving confidential information, credentials, authentication tokens, or unauthorized system access must be investigated promptly.

When an incident is confirmed, Vismor will take reasonable actions to:

  1. Contain the incident.

  2. Protect affected credentials and accounts.

  3. Determine the scope of the incident.

  4. Revoke or rotate compromised credentials when necessary.

  5. Correct the underlying security issue.

  6. Notify affected parties or service providers when required.

    Security responsibility: As an owner-operated business, the business owner acts as the primary security and incident response contact for Vismor and VSM Creator Analytics.

    Security incidents may be reported to vismor.pro@gmail.com.

    The responsible person coordinates incident identification, containment, credential revocation or rotation, remediation, documentation and any required notifications to affected platforms or parties.

12. Credential Compromise

If an API key, secret, access token, refresh token, or account credential is suspected to have been exposed, Vismor will revoke or rotate the affected credential as soon as reasonably possible.

Compromised credentials will not continue to be knowingly used.

13. Privacy and Compliance

Vismor processes data only for legitimate business purposes and seeks to comply with applicable privacy and data protection requirements.

Information obtained through third-party APIs is used in accordance with the applicable platform terms, permissions, and developer policies.

14. Security Review

This Information Security Policy is reviewed periodically and at least once per year, or sooner when significant changes are made to Vismor's systems, applications, security practices, or legal obligations.

15. Contact

Questions relating to information security or this policy may be sent to:

16. Data Classification

Vismor classifies information according to its sensitivity and intended use:

Public: information intended for public disclosure, such as website content and published marketing materials.

Internal: operational information intended only for internal business use.

Confidential: business information, analytics data and non-public operational information requiring restricted access.

Restricted: authentication credentials, API secrets, access tokens, refresh tokens and other security-sensitive information requiring the highest level of protection.

Confidential and Restricted information must be protected against unauthorized access. Data transmitted between Vismor systems and supported third-party APIs is protected using HTTPS/TLS. Sensitive information stored on company devices is protected using full-disk encryption and secure credential storage mechanisms such as macOS Keychain.

17. Vulnerability Management

Vismor maintains a risk-based vulnerability management process for devices and applications used to process business information.

The process includes:

  • Keeping macOS and business applications updated with current security patches.

  • Applying critical security updates without unnecessary delay.

  • Monitoring security notifications from operating system, application and platform providers.

  • Reviewing application dependencies and removing unsupported or unnecessary software.

  • Investigating known vulnerabilities that may affect VSM Creator Analytics.

  • Prioritizing remediation based on severity and potential impact.

  • Rotating or revoking credentials when a vulnerability may have exposed confidential authentication information.

Security controls and application dependencies are reviewed periodically and when significant changes are introduced.

Vismor
Website: https://vismor.com.br
Email: vismor.pro@gmail.com

VISMOR

Do visual ao resultado — com estratégia

Impacto

Contato

contato@vismor.com

+55 (15) 981244259

© 2025. All rights reserved.