Security

Current controls, stated plainly.

Titan Link distinguishes controls that are implemented and evidenced from controls that are planned. A roadmap item is not a security claim.

Implemented and evidenced today

AreaCurrent control
Corporate websiteStatic informational pages with no account, password, payment, upload, analytics, advertising, or web-form collection.
Commerce Cockpit code boundaryStore-scoped tenant/provider binding, cross-store denial tests, strict read-response schemas, secret-free client responses, and explicit exclusion of buyer/order data in the current PoC.
Credential exposureMarketplace credentials are designed to remain server-side behind opaque references. No Etsy or TikTok seller OAuth credential is currently active in Commerce Cockpit.
Current pilot filesDedicated service identity and owner-only filesystem permissions are evidenced. Current file-vault content is plaintext at rest; this does not satisfy an encrypted-secret-storage claim.
Product separationOperator Bridge and Commerce Cockpit are defined as separate products with separate target nodes, identities, databases, credential stores, backups, and deployment paths.

Planned before broader marketplace activation

AreaPlanned control and gate
InfrastructureSeparate Titan Link-owned AWS nodes for Operator Bridge and Commerce Cockpit, with protected data isolated from unverified root storage.
Encryption and keysProvider-encrypted data volumes and snapshots plus application-layer authenticated encryption for marketplace secrets, with keys held outside the data/snapshot boundary.
Identity and accessProduct-specific least-privilege runtime roles, named administrators, MFA, access reviews, denied-access tests, and controlled break-glass recovery.
BackupsDefined retention, encrypted snapshots, isolated restore drills, deletion propagation, and evidence that keys do not enter backups.
OperationsMonitoring, vulnerability management, rotation, incident escalation, exercises, and retained evidence suitable for the applicable marketplace review.
Current limitation: Titan Link does not claim SOC 2 or ISO certification, independent penetration testing, KMS-backed production secrets, completed incident-response drills, or production Etsy/TikTok OAuth. Those claims will not be made until implemented and evidenced.

Marketplace-specific scope

Etsy and eBay requirements are evaluated against their own APIs, terms, approved scopes, and security obligations. TikTok Shop US ISV/DSPR review has a broader documented evidence baseline, including encryption at rest and in transit, key management, access controls, vendor governance, vulnerability management, and incident response. Because TikTok is a planned Commerce Cockpit provider, the Cockpit production runtime is being designed to meet that higher baseline from the start rather than maintaining a weaker parallel runtime.

Reporting

Email security@titanlinkinc.com with the affected service, a concise description, and safe reproduction details. Do not include passwords, API keys, OAuth tokens, session cookies, recovery material, identity documents, or live seller data.