AMAZON SP-API CERTIFICATION

SP-API Data Protection & Security Policy

Formal technical disclosure of EZPursue’s security controls, encryption ciphers, principle of least privilege, and mandatory 30-day PII sanitization.

Amazon SP-API Data Protection Policy (DPP) Certification:This document certifies our adherence to Amazon's mandatory security controls for developers and partner agencies managing Amazon Seller Central data.

1. Data Governance & Least Privilege Access

In alignment with the Amazon SP-API Data Protection Policy, EZPursue enforces the Principle of Least Privilege (PoLP):

  • Only authorized senior agency personnel with validated business needs obtain access to client reporting data.
  • Mandatory Multi-Factor Authentication (MFA) is enforced across all administrative accounts, workstations, and repositories.
  • Role-Based Access Control (RBAC) restricts permissions on an individual client ASIN/brand basis.
  • 2. Encryption Standards

    All Amazon customer information and marketplace data is protected by strict cryptographic measures:

  • Data at Rest:Encrypted using industry-standard AES-256 encryption. Encryption keys are managed securely and rotated regularly.
  • Data in Transit:Secured exclusively using TLS 1.2 or higher over HTTPS. Unencrypted transmission protocols are strictly blocked.
  • 3. Data Retention & Irreversible Disposal

    EZPursue maintains a strict data retention and disposal schedule:

  • Personally Identifiable Information (PII) related to Amazon buyer order delivery is stored for no longer than 30 daysfollowing order fulfillment, solely for order processing and reconciliation.
  • Following the 30-day window, all customer PII is irreversibly sanitized, purged, or shredded in accordance with NIST SP 800-88 standards.
  • Aggregated, anonymized performance metrics (e.g. ad spend, impressions, blended ACoS) are retained for longitudinal client reporting with zero PII exposure.
  • 4. Vulnerability Management & Incident Response

    Our infrastructure undergoes routine automated vulnerability scans and annual dependency reviews. In the event of any verified or suspected security incident involving Amazon customer data, EZPursue will notify Amazon Information Security via security@amazon.comwithin 24 hours of discovery, in compliance with Amazon SP-API requirements.

    5. Logging & Audit Monitoring

    All programmatic access to client API tokens and database records is monitored via tamper-proof audit logs retained for a minimum of 90 days. Unauthorized access attempts trigger automated alerts to our infrastructure security team.