Security is foundational to how we handle your marketplace data and the Amazon Selling Partner data you authorize us to process. This page describes the controls we have in place. For how we collect and use data, see our Privacy Policy.
Encryption
- In transit: all traffic is served over TLS (HTTPS) with a valid certificate. We do not accept unencrypted connections.
- At rest: stored data — including Amazon Information, reports, and integration credentials — is encrypted at rest using AES-256.
- Secrets: API keys and OAuth tokens are stored encrypted, isolated from application data, and never exposed in client-side code or logs.
Access Controls
- Access to production systems and customer data is restricted to authorized personnel on a least-privilege basis.
- Administrative access is authenticated and logged for auditability.
- Role-based access control (super_admin, admin, user) governs what each account can see and do within the platform.
- Customer data is logically segregated by agency so one customer cannot access another's data.
Infrastructure
- The Service runs on Amazon Web Services (AWS), which maintains its own physical and network security certifications.
- Data is hosted in the United States. See our sub-processor disclosure for the full list.
- Automated backups protect against data loss; backups are encrypted.
Application Security
- Authentication uses signed, HTTP-only session tokens.
- Inputs are validated and queries use parameterized statements to prevent injection.
- Dependencies are monitored and updated to address known vulnerabilities.
Compliance Posture
We handle Amazon Information in accordance with the Amazon Data Protection Policy and Acceptable Use Policy, including its requirements for encryption, retention, access control, and deletion on request.
Data Retention & Deletion
We retain data only as long as needed to provide the Service, and we delete or anonymize it on verified request. Personally Identifiable Information derived from the Amazon SP-API is retained no longer than 30 days after order delivery. See Data Deletion to submit a request.
Vulnerability Disclosure
If you believe you have found a security vulnerability, please report it to [CONTACT EMAIL] with the subject line "Security." We investigate all reports and ask that you give us a reasonable opportunity to remediate before public disclosure.