Security
How we protect your store and your data.
Isolation
Every customer's data is separated at the database level with row-level security. Requests run with the signed-in customer's identity only; one customer's request cannot read or change another customer's records.
Access to Amazon
You connect your Amazon account through Amazon's own authorization page. We never ask for, receive or store your Amazon password or verification codes. Authorization tokens are kept server-side, encrypted, and never shown to users or AI assistants. You can revoke access at any time in Seller Central.
Least privilege
We request only the Amazon data permissions our features need and do not request buyer personal information. Staff access to production systems is restricted, individual, protected with multi-factor authentication and logged.
Every change is governed and recorded
Changes are executed only from tickets that passed your rules and were approved by an authorized person in your account. Tickets are signed by the platform, cannot be edited after creation, expire, and are re-checked before running. An append-only, tamper-evident audit log records each step.
Encryption
All traffic uses HTTPS (TLS). Secrets are stored in the hosting provider's encrypted secret store, never in source code.
Incident response
We monitor for security events. If an incident affects your data we will notify you and, where required, Amazon, within 24 hours of confirming it, and take immediate containment steps.
Report a vulnerability
Email security@storeaioperator.com. Please give us reasonable time to fix issues before disclosure.