Sensitive service credentials are kept in protected server configuration rather than public website code.
Administrative access is restricted by account and role, and sensitive operational actions can be logged.
Security concerns can be reported directly to support@podjst.com for triage.
Access Control
PODJST limits administrative and operational access according to role and service need. Users are authenticated before protected functions, and access should be removed when no longer required.
Credentials and Secrets
Database service keys, storage credentials, mail credentials, and similar secrets are maintained in server-side environment configuration. Public client credentials are limited to their intended scope and must be supported by provider access controls.
Transport and Storage
Production web and API connections are required to use HTTPS/TLS. PODJST uses managed database and object-storage providers and applies access controls appropriate to account, product, artwork, and operational records.
Logging and Monitoring
PODJST records selected authentication, administrative, synchronization, security, and operational events to support troubleshooting, accountability, abuse prevention, and incident review. Logs are access-restricted and retained according to operational and legal needs.
Provider and Data Minimization Controls
PODJST selects providers for defined functions, limits shared information to what the function needs, and publishes principal providers in the Subprocessor List. Production and carrier access is limited to the relevant order and route.
Incident Response
PODJST investigates suspected unauthorized access, credential exposure, harmful activity, or personal data incidents and takes reasonable containment, remediation, recovery, and notification steps based on the facts and applicable obligations.
Report a Security Concern
Email support@podjst.com with the subject "Security Report" and include the affected URL or function, steps to reproduce, potential impact, and safe contact information. Do not access, copy, alter, or expose data that is not yours, disrupt service, or publicly disclose an unresolved issue.
PODJST does not currently offer a public bug bounty and does not authorize testing that violates law, privacy, platform rules, or these Terms.
Security Contact
Contact JST COMMERCE LIMITED, operating as PODJST, at support@podjst.com, +852 64203057, or RM D07, 8/F, KAI TAK FTY BUILDING, NO. 99 KING FUK STREET, SAN PO KONG, HK.
Questions or requests?
Contact JST COMMERCE LIMITED, operating as PODJST, and include the policy or request type.