SmartReply Information Security Program

Effective Date: May 26, 2025

1. Scope & Ownership

This Information Security Program ("Program") governs the SmartReply application and all associated data handling processes. SmartReply is a proprietary product of Incharge Marketing LLC, a US-based entity 100% owned and controlled by US Citizens.

This Program defines the minimum security requirements applicable to all SmartReply personnel, systems, and data environments. It covers the full data lifecycle - creation, storage, transmission, and decommissioning - across production and corporate environments.

2. Technical Infrastructure

SmartReply utilizes a cloud-native infrastructure designed for high availability and strict data sovereignty.

  • Data Residency: All servers, databases, and API integrations are hosted exclusively on Amazon Web Services (AWS) within the us-east-1 (Virginia, USA) region.
  • Encryption: Data is encrypted at rest using industry-standard AES-256 and in transit via TLS 1.2+.
  • Architecture: Production workloads are isolated within Amazon VPCs, protected by Cloudflare Zero Trust and Web Application Firewalls (WAF).

3. Governance & Risk Management

Accountability for the SmartReply security posture starts at the executive level.

  • CISO/DPO Oversight: The Chief Information Security Officer (CISO) maintains this policy, coordinates audits, and approves security exceptions.
  • Engineering Compliance: The engineering team is responsible for implementing technical controls, conducting peer code reviews, and maintaining the patch management lifecycle.
  • Annual Review: This Program is reviewed annually or upon significant changes to the threat landscape or regulatory environment.

4. Data Classification & Handling

SmartReply maintains a clear data classification schema to ensure appropriate handling:

  • Public: Marketing and external documentation.
  • Internal: Non-public business communications.
  • Confidential/Restricted: PII and TikTok USDS records. These require the highest level of protection, including hardware-backed encryption keys (AWS KMS) and detailed access logging.

5. Access Control & Identity Management

SmartReply enforces a Zero Trust architecture:

  • MFA: Mandatory FIDO2/WebAuthn Multi-Factor Authentication via Okta for all administrative and cloud resources.
  • Least Privilege: Access to production environments is strictly limited to authorized security personnel (CISO/DPO). No general staff or third-party contractors are granted production database credentials.
  • Credential Management: Secrets and keys are managed via AWS Secrets Manager; hard-coded credentials are strictly prohibited.

6. Security Operations

  • Threat Detection: Continuous monitoring is provided by AWS GuardDuty, Security Hub, and CloudWatch.
  • Endpoint Security: All corporate devices are managed via MDM with real-time endpoint protection and automated patching.
  • Vulnerability Management: Weekly dependency scans (Snyk) and image scans (Amazon Inspector) are performed. Critical vulnerabilities are remediated within 72 hours.

7. Incident Response & Business Continuity

  • Incident Response: In the event of a confirmed breach involving TikTok USDS data, notification will occur within 24 hours.
  • Disaster Recovery: Automated daily backups are managed via AWS Backup with cross-region replication.
  • Recovery Objective: Systems are architected for a Recovery Time Objective (RTO) of 4 hours within US-based availability zones.

8. Software Development Lifecycle (SDLC)

Security is integrated into the development process:

  • Code Integrity: All changes require formal Pull Requests and peer review.
  • Testing: Annual third-party penetration testing is conducted to validate the security of the application layer.

9. Third-Party Risk & USDS Compliance

  • Sub-processors: SmartReply utilizes AWS (Infrastructure), OpenAI (AI Services via US-based API), and Cloudflare (Security).
  • Data Sovereignty: SmartReply certifies that all US user data remains within the United States. Sub-processors are contractually prohibited from using USDS data for model training.
  • Vetting: All vendors undergo security risk assessments prior to onboarding and are reviewed periodically. We prioritize partners with recognized security certifications and evaluate their practices against the sensitivity of data they may access.

10. Personnel Security

  • Training: All employees undergo mandatory security awareness training upon hire and annually thereafter.
  • Background Checks: All personnel with potential access to sensitive systems undergo rigorous background screening.
  • Location: All development, support, and administrative operations are conducted from Chicago, IL, USA.

Contact Information

For inquiries regarding this Program or to report a security concern:

Jonah Belanger
Chief Information Security Officer
SmartReply (Incharge Marketing LLC)
Email: [email protected]