Enterprise-Grade Protection for Amazon Seller Data
Security is built into the core architecture of Amazon Seller BI. We employ defense-in-depth methodologies, strict least-privilege API scopes, and zero-PII data policies.
Core Security Architecture & Standards
Every layer of the platform is designed to maintain the confidentiality, integrity, and availability of your seller operations.
Amazon Selling Partner API Data Protection Standards
Built to meet Amazon’s strict developer security, data retention, and tenant isolation specifications.
Zero PII Data Storage
The platform does not ingest, store, or process buyer Personally Identifiable Information (PII) such as customer names, shipping addresses, or payment card details.
OAuth 2.0 Token Isolation
Amazon Seller Central authorization tokens (LWA refresh tokens) are secured using AES-256 GCM envelope encryption with hardware-backed key rotation.
Strict Multi-Tenant Isolation
Every seller organization is partitioned with strict tenant isolation, ensuring your sales, fee structures, and SKU profit margins are completely inaccessible to other accounts.
Encrypted In-Transit & At-Rest
All traffic is strictly enforced over TLS 1.3 with modern cipher suites. Database records and cache snapshots are encrypted at rest with AES-256 standard encryption.
Least-Privilege API Scopes
We request only the minimum required SP-API operational roles necessary to calculate financial reporting and advertising metrics, without requesting buyer-restricted data.
Audit Logging & Monitoring
Comprehensive audit trails record all administrative actions, data synchronization sync timestamps, and credential access events with immutable log retention.
Adherence to Amazon Developer Data Protection Policies
Our operational systems are engineered specifically to comply with Amazon's Selling Partner API Data Protection and Acceptable Use Policies.
1. Strict Zero-PII Policy
Amazon Seller BI is an aggregate financial analytics and business intelligence tool. We intentionally exclude Personally Identifiable Information (PII) from our ingestion pipelines. Customer buyer names, street addresses, phone numbers, and postal codes are stripped prior to storage, preventing any risk of consumer privacy exposure.
2. Encryption Standards (In-Transit & At-Rest)
All data transmission between client browsers, application servers, and Amazon SP-API endpoints is enforced exclusively over TLS 1.3 with modern ephemeral key exchanges. Sensitive configuration metadata and seller tokens at rest are secured using industry-standard AES-256 GCM encryption with keys managed in isolated key management infrastructure.
3. Multi-Tenant Logical Partitioning
Each organization operates within isolated logical boundaries. Database queries enforce strict organizational tenant ID scoping at the data layer, ensuring that no cross-tenant data leakage or unauthorized access is possible under any scenario.
4. Least-Privilege API Role Scopes
When connecting your seller account via Login with Amazon (LWA), we request only the specific role permissions necessary to fetch order item totals, fee schedules, advertising reports, and financial settlements. We never request permissions for restricted customer data.
Responsible Disclosure & Security Inquiries
If you have specific security architecture questions, wish to report a potential vulnerability, or require technical compliance details for your organization, please contact our security team directly.
jmtrends13@gmail.comReady to See the True Financial Reality of Your Amazon Business?
Eliminate spreadsheet errors and calculate true net profit after fees, ad spend, COGS, and operating expenses in one unified dashboard.