Skip to main content

Security at Tie: how the Klaviyo integration is protected

T
Written by Tim Hughes

Tie holds itself to a high standard of security, privacy and operational reliability for every customer and integration partner, including Klaviyo users. Our program is designed to align with the SOC 2 Trust Services Criteria and industry best practice. This page covers how the Klaviyo connection is protected and how Tie handles data more broadly.

How the OAuth connection is secured

Tie connects to Klaviyo through its own managed integration service, which is purpose-built for secure, multi-tenant OAuth integrations. That lets us follow best practice for credential storage, access control and token lifecycle management while minimizing exposure.

Secure credential storage. OAuth credentials, including client secrets, access tokens and refresh tokens, are held in that service and never in application code. They are encrypted at rest and in transit, isolated per customer and per integration, and reachable only by authorized operators on a least-privilege basis.

No hardcoded credentials. OAuth credentials never live in source code, repositories or static configuration. They are retrieved from the secure integration service only when they are needed.

Least privilege. The Klaviyo integration requests only the scopes needed for its documented functionality. Requested scopes are configured explicitly in the Klaviyo app registration, and broad or unnecessary permissions are not requested. The full scope list, with what each is for, is in Install the Tie app for Klaviyo.

Credential rotation and token lifecycle. Klaviyo OAuth client secrets can be regenerated as needed without application code changes. Access tokens are short-lived and refreshed automatically by secure server-side mechanisms. Tokens are treated as sensitive secrets at all times.

Server-side flows only. All OAuth authorization, token exchange and refresh operations run server to server. Client secrets are never exposed in a browser or client-side context, flows comply with Klaviyo's OAuth requirements, and tokens are issued, stored and refreshed only within secure backend systems.

Data encryption and protection

In transit. All data moving between Tie and third-party platforms is encrypted with TLS 1.2 or higher. HTTPS is enforced for all API communication, with modern cipher suites consistent with Mozilla's SSL configuration guidance.

At rest. Sensitive data, including authentication credentials, OAuth tokens and customer-identifying information, is encrypted at rest with industry-standard algorithms such as AES-256, across production databases, backups and storage.

Authentication, authorization and access control

  • Every application endpoint requires authentication and authorization, and requests are validated server-side for application identity and integrity.

  • Access tokens are validated on every request and expire automatically. Expired or invalid tokens are rejected.

  • Multi-factor authentication is required for remote access and for privileged and development accounts.

  • Role-based access control gives users and services only the minimum access their function needs, reviewed regularly and revoked promptly when no longer required.

These controls are documented and enforced under our access management and authorization policies.

Data residency and privacy

Tie defines where customer data is stored and processed within our cloud infrastructure. If data must be transferred or processed outside a customer's primary region, that happens in compliance with applicable data protection regulation, with appropriate safeguards, and with customer consent where required.

Secure development

  • All untrusted input is validated and sanitized, and secure coding standards guard against common vulnerabilities such as injection and cross-site scripting.

  • Third-party libraries and dependencies are monitored continuously for vulnerabilities.

  • Critical vulnerabilities are remediated within 7 days and high-severity vulnerabilities within 30 days under our vulnerability management program.

  • Regular vulnerability scanning and independent penetration testing are performed.

Reliability, availability and incident management

  • Automated monitoring and alerting cover system health, performance and security events.

  • Business continuity and disaster recovery plans are documented, tested annually and actively maintained.

  • Automated backups and defined recovery objectives protect data integrity and service continuity.

  • Customer-impacting outages or incidents are communicated promptly and transparently.

These processes are documented and validated as part of our SOC 2 control framework.

Service commitment

Tie maintains reasonable service-level expectations and actively addresses performance, stability and reliability issues, monitoring customer feedback and operational metrics to keep the experience high for integration partners and end users.

Trust Center

Detailed documentation, including SOC 2 controls and policies, is in our Trust Center at trust.oneleet.com/revenue-roll.

Did this answer your question?