Legal Center

Security and Trust Overview

Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).

1. Status of this overview

This page describes Klocktech's minimum production security commitments and shared-responsibility model. It must be checked against the implemented architecture before publication. It does not claim ISO 27001, SOC 2, PCI DSS or another certification unless a current certificate is expressly listed.

2. Security principles

Klocktech is designed around tenant isolation, least privilege, data minimisation, traceability and human control. The Customer's own or authorised inventory is the only inventory source. The architecture must not expose a generic crawler, arbitrary URL fetcher, marketplace search or cross-tenant analytics path.

3. Identity and access

  • unique user accounts and role-based permissions;
  • multi-factor authentication for Provider administrators and available or required for privileged Customer roles;
  • least-privilege access to prices, costs, serials, integrations, publication, exports and user administration;
  • regular privileged-access review and prompt offboarding;
  • time-limited, scoped and logged support access; and
  • protected OAuth tokens, API keys and secrets with rotation and revocation processes.

4. Data protection

  • logical tenant separation across database queries, object storage, APIs, background jobs, caches and analytics;
  • encryption in transit and at rest using current industry practices;
  • encrypted, field-level access-controlled full serial numbers with backend-only or public masked display showing no more than three original characters only;
  • no full serial in public text, derivatives, metadata, filenames, URLs, notifications or routine logs, and no disclosure to AI, reference or market-data vendors;
  • immutable originals for dealer-uploaded watch images and a processing audit trail;
  • provenance for uploaded media, reference data and AI-assisted changes;
  • minimised collection and configurable deletion where product requirements permit; and
  • no identifiable cross-dealer model training, benchmarking or pooled identifiable inventory, even by opt-in.

5. Application and infrastructure security

  • separated development, test and production environments;
  • peer review and controlled deployment for material changes;
  • dependency, secret and vulnerability scanning appropriate to the technology;
  • timely patching based on severity and exposure;
  • validation, authorisation and rate controls on APIs and connectors;
  • monitoring of authentication, administrative, export, connector and suspicious events;
  • backups protected separately from primary production and periodic restore tests; and
  • capacity, availability, incident response and recovery procedures.

6. Secure integrations and AI

Connectors authenticate only to the Customer's account and read only its own known listings, orders or events. An official API being unavailable does not authorise scraping. AI vendors must be approved, contractually restricted, listed where they process personal data, and contractually prohibited and technically configured from training on Customer Data.

7. Incident management

The Provider maintains procedures to detect, triage, contain, investigate, recover from and learn from security incidents. Affected Customers receive notice under the DPA and Agreement. Public status and post-incident reporting will be proportionate to impact and security considerations.

Security issues should be reported under the Vulnerability Disclosure Policy. In an urgent suspected account compromise, contact legal@heritagetp.com and identify the affected organisation and account without emailing passwords or unnecessary personal data.

8. Shared responsibility

The Provider secures the Klocktech platform. The Customer must secure its devices, email, identity provider, users, permissions, connected accounts and internal processes; review access regularly; keep contact information current; verify suspicious output or connector errors; and maintain lawful copies or exports needed for its business continuity.

9. Assurance roadmap

Before commercial launch, management should approve a documented risk assessment, vendor review, penetration test plan, recovery test, access review, incident exercise and security owner. Any future audit report or certification must be described accurately with scope and date.