February 28, 2025
TikTok’s independent security inspector says protected US user data is not in any way being shared with China and the platform is performing exactly as TikTok has been saying for years that it does.
That’s according to a new report released today from HaystackID. And this report is probably going to be very important when TikTok is negotiating with the trump administration to prevent the app from disappearing in the US in just 36 days.
Before I tell you more about this new report and explain why it’s interesting. You need to understand the TikTok corporate structure. I have been reporting for years about the US government’s concerns about TikTok and the national security threat congress says it poses because of its parent company which is based in China. I want you to think back to 2023. You remember those intense congressional hearings starring TikTok’s CEO Shou Chew where democrat and republican lawmakers were unanimously yelling at him saying TikTok was a danger to the 170 million American users because China could assess American data and spew Chinese propaganda into the United States.
Well during that hearing you may have missed it with all the yelling, but the TikTok CEO brought up the fact that the year before in 2022 — TikTok had created a brand new separate American company to secure protected us user data and firewall it from any type of access by China or anyone else. I’ve reported on this other company before….that American subsidiary of TikTok is called US Data Security or USDS. Us Data Security is obviously based here in the United States, is self contained and separate from TikTok. It works with another American company oracle which is TikTok’s cloud partner. Oracle servers house every single piece of American user data on American soil. As of January of 2023, USDS was fully operational and only USDS personnel – who are not even employees of TikTok – have access to TikTok’s oracle cloud infrastructure. Now here’s where haystack-id comes into play.
To prove to the u-s government that TikTok is going above and beyond to protect US user data and China has no access to that data – not only did TikTok stand up this completely separate company USDS, but they did something no other social media company does – they gave third party independent security inspectors access to TikTok’s full source code, algorithm, mobile app code and back end services. Those third party independent security inspectors are basically white hat hackers and they constantly go through TikTok’s code and infrastructure looking for vulnerabilities. And they make sure TikTok is actually doing what they say they’re doing. HaystackID is one of those independent security inspectors.
And that leads me back to the new report released today from HaystackID about what they’ve found. They said they were hired by USDS back in May of 2024 and since July of last year they have been testing TikTok’s systems and infrastructure. In September of last year they started going through the millions of lines of TikTok source code to conduct security tests. While a representative from HaystackID told me they have found run-of-the-mill vulnerabilities that any social media company may have which haystack id says TikTok addressed immediately with patches — they confirmed they have “not observed any indication of internal or external malicious activity. Based on HaystackID’s independent evaluation, the TikTok platform is operating as intended and at this point in testing HaystackID has identified no sharing of protected US user data with China.”
Now – you’re probably thinking what I’m thinking. Well – of course they’re going to say that because TikTok is paying them. Well – I asked the representative from haystack id that very question and he told me that TikTok is not haystack id’s only client. They have worked for years with lots of other high profile companies that are actually under mandatory national security agreements with the federal government. It’s haystack-id’s job to be third party inspectors to make sure those companies are complying with what the federal government wants and all the things outlined in those security agreements. And if those companies aren’t complying it’s HaystackID’s job to let the government know and make sure those companies come into compliance.
the government trusts haystack-id to call balls and strikes and be transparent so it’s not in HaystackID’s best interest to break that trust by making things up about TikTok. Because then HaystackID may miss out on lots of other contracts. Does that make sense.
Now – the only difference in TikTok’s case is that TikTok does not currently have a national security agreement in place with the US government. As I have reported many times — they tried to get one done – and they were this close to getting it done – but during the Biden administration, the federal regulators ghosted them. And then bam – congress passed the law to ban TikTok in the United States. So basically TikTok fully implemented a National security agreement and are in full compliance with that agreement– according to HaystackID…that is not required by the US government. They’re just doing it because they said they would.
Now just because HaystackID hasn’t found any vulnerabilities where us user data could be accessed –yet– the representative form HaystackID told me that doesn’t mean they won’t. He said HaystackID is going to continue to inspect every line of TikTok’s source code and going to continue to work with USDS to confirm that TikTok is upholding all the data security promises they’ve made. But to this point – they say they haven’t found anything.
