Data Protection & Security Policy
1. Data Encryption & Storage
eBusiness Services LLC enforces strict data protection standards for all Amazon Selling Partner API (SPAPI) data. Data in transit is encrypted using TLS 1.2+. Data at rest is encrypted using AES-256. No SPAPI data is stored on local devices or in unsecured environments.
2. Personally Identifiable Information (PII) Retention
We follow strict data retention rules to protect seller and customer privacy. SPAPI data is retained only for the minimum time required. Data containing PII is securely deleted immediately after use and strictly within 30 days of order fulfillment, using secure deletion methods (cryptographic wipe).
3. Credential & Secret Management
eBusiness Services LLC utilizes secure, encrypted vaults for credential storage. Credentials are stored in an encrypted secrets manager using AES-256 encryption. Passwords and access keys are never hardcoded in applications or stored in source code. SPAPI refresh tokens, IAM access keys, and application secrets are rotated regularly. Multi-factor authentication (MFA) is required for all administrative access.
4. Incident Management & Response SLA
We maintain a robust Incident Response Plan that encompasses detection, containment, investigation, eradication, recovery, and notification. If SPAPI data is affected by a breach, we isolate affected systems and reset all affected credentials.
- Amazon Notification SLA: In the event of a confirmed or suspected security breach, we will notify Amazon directly at security@amazon.com within 24 hours of detection.
5. Vulnerability Management & Monitoring
eBusiness Services LLC continuously monitors API usage patterns, authentication attempts, and system logs for anomalies. To prevent future incidents, we conduct periodic penetration testing and vulnerability scans.
- Network and application vulnerability scans are conducted every 30 days.
- Comprehensive penetration tests are conducted every 365 days.
6. Policy Review
Our security, credential management, and incident response policies are reviewed every 6 months, after any security incident, or when Amazon updates SPAPI security requirements.
Credential Management Policy
1. Purpose & Scope
This policy defines how eBusiness Services LLC securely manages all credentials used to access Amazon SP-API, Seller Central roles, internal systems, and cloud environments. The goal is to prevent unauthorized access, credential leaks, and misuse of Amazon data.
This policy applies to all employees, contractors, and authorized users, as well as all systems, servers, and cloud environments handling Amazon data. All managed credentials—including SP-API LWA (Login With Amazon) credentials, refresh tokens, IAM access keys, application client secrets, Seller Central role access credentials, internal system passwords, and MFA authentication tokens—are classified as Highly Sensitive.
2. Secure Credential Storage
eBusiness Services LLC uses secure, encrypted vaults for credential storage to ensure no credentials are computationally exposed.
- Credentials are stored in an encrypted secrets manager using AES-256 encryption.
- No credentials are stored in plain text, nor are they stored on local devices.
- No credentials are stored in source code, configuration files, GitHub, or any version control system.
- Access to the credential vault is restricted strictly to authorized personnel only.
3. Access Control & Identity Management
Strict access control is enforced across all systems touching Amazon data.
- Role-based access control (RBAC) determines who can access which credentials, and only authorized team members with a direct business need can access SP-API credentials.
- Multi-Factor Authentication (MFA) is strictly required for all administrative access.
- Password Governance: Passwords must have a minimum length of 12 characters, include a mix of character types (uppercase, lowercase, numbers, special characters), and cannot contain user information. The reuse of the last 10 passwords is computationally prevented, and passwords expire after a maximum of 365 days.
- Account Lockout: Systems are configured to automatically lock user accounts after 10 or fewer unsuccessful login attempts to prevent brute-force attacks.
- Rapid Offboarding: System access and associated credentials for employees, contractors, and third parties are permanently disabled or removed within 24 hours of termination or role change.
4. Credential Rotation Lifecycle
eBusiness Services LLC rotates credentials regularly to ensure they remain secure and uncompromised.
- Amazon API keys and associated application credentials are automatically rotated at least annually.
- IAM keys are rotated every 90 days.
- Application secrets are rotated after major updates or security incidents.
- SP-API refresh tokens are rotated when employees change roles or leave the company.
5. Credential Usage & Third-Party Restrictions
To prevent leaks or misuse, strict usage rules are enforced.
- Credentials are never shared between employees or sent via email, chat, or other unsecured channels.
- Credentials are used only for approved business purposes.
- eBusiness Services LLC does not share credentials with third parties or allow external contractors to access SP-API credentials without formal approval.
- We do not use third-party tools that store credentials insecurely, and all third-party integrations undergo rigorous security review.
6. Monitoring, Logging & Incident Handling
eBusiness Services LLC continuously monitors API usage patterns, authentication attempts, credential access logs, suspicious IP addresses, and unusual SP-API activity. All access attempts (successful or failed) are logged and monitored daily.
If a credential is suspected to be compromised, the following Incident Response protocol is executed immediately:
- The compromised credential is immediately revoked and a new credential is generated.
- A full investigation is performed, and all affected systems are checked for unauthorized access.
- Amazon Notification SLA: If Amazon data or systems are affected, the Amazon SP-API Security Team is notified at security@amazon.com within 24 hours of detection.
7. Employee Training & Policy Review
- Training: All employees receive mandatory, annually refreshed training on secure credential handling, SP-API security requirements, password hygiene, MFA usage, and incident reporting procedures.
- Review Cadence: This policy is reviewed every 6 months, after any security incident, or whenever Amazon updates SP-API security requirements. Updates are documented and communicated to all staff.
SP API Data Protection Policy
1. Purpose & Scope
This policy defines how our organization protects all Amazon Selling Partner API (SP-API) data, including seller information, operational data, and any sensitive or confidential content accessed through Amazon’s API. The goal is to ensure the confidentiality, integrity, and availability of Amazon SP-API data at all times.
This policy applies to all employees, contractors, and authorized users; all systems, servers, databases, and cloud environments handling SP-API data; all SP-API applications, tokens, credentials, and integrations; and all data stored, processed, or transmitted through Amazon SP-API.
2. Data Classification & Access Controls
Our organization classifies SP-API data as Highly Sensitive. This includes seller account information, orders, inventory, pricing, financial data, account health and performance metrics, reports generated via SP-API, and any Personally Identifiable Information (PII) provided through SP-API. This data requires maximum protection and restricted access.
Strict access controls are enforced:
- Access is granted only to authorized personnel with a clear business need.
- Role-based access control (RBAC) is implemented across all systems.
- Multi-factor authentication (MFA) is strictly required for all administrative access.
- Access logs are monitored daily for unusual activity, and any unauthorized access attempts trigger an immediate investigation.
3. Data Storage, Encryption & Transmission
All SP-API data is protected using industry-standard encryption.
- In Transit: Data in transit is encrypted using TLS 1.2+.
- At Rest: Data at rest is encrypted using AES-256.
- No SP-API data is stored on local devices or in unsecured environments.
- Backups are encrypted and stored in secure cloud infrastructure.
- SP-API data is transmitted only through secure, encrypted channels; no SP-API data is sent via email, chat, or unsecured communication tools.
4. Data Retention & Disposal
We follow Amazon’s strict retention rules to ensure sensitive data is never stored longer than necessary.
- SP-API data is retained only for the minimum time required.
- Amazon Compliance SLA: Data containing PII is securely deleted immediately after use and strictly within 30 days of order fulfillment.
- Secure deletion methods (cryptographic wipe) are utilized, and logs and backups follow strict retention schedules to ensure no SP-API data is kept longer than Amazon allows.
5. Credential Management
Strict credential security is maintained at all times:
- SP-API tokens and access keys are stored securely in encrypted vaults and are never shared between employees.
- No credentials are ever hardcoded in applications.
- Credentials are rotated regularly, and compromised credentials are revoked immediately.
6. Monitoring, Logging & Incident Response
We continuously monitor API usage patterns, authentication attempts, system logs for anomalies, suspicious IP addresses, and unauthorized access attempts. Logs are stored securely and reviewed regularly.
If SP-API data is affected by a breach, we follow a structured Incident Response Plan:
- Detection: Identify unusual activity.
- Containment: Isolate affected systems.
- Investigation: Determine cause and impact.
- Eradication: Remove threats and patch vulnerabilities.
- Recovery: Restore clean systems.
- Notification (Amazon SLA): Inform the Amazon SP-API Security Team immediately at security@amazon.com within 24 hours of detection.
- Prevention: Update policies and strengthen controls.
7. Third-Party Restrictions
We do not share SP-API data with unauthorized third parties or use SP-API data for any purpose outside the approved service. SP-API data is never stored in third-party tools without encryption and compliance verification, and all third-party integrations undergo comprehensive security reviews.
8. Employee Training & Policy Review
- Training: All employees receive mandatory, annually refreshed training on SP-API security requirements, data protection best practices, handling sensitive seller information, and incident reporting procedures.
- Review Cadence: This policy is reviewed every 6 months, after any security incident, or whenever Amazon updates SP-API security requirements. Updates are documented and communicated to all staff.
Incident Response Steps
Phase 1: Detection & Identification
eBusiness Services LLC uses continuous monitoring tools and manual log reviews to detect abnormal activity. Detection mechanisms include:
- Automated alerts for unauthorized login attempts.
- Monitoring API usage for unusual patterns.
- Reviewing server and database logs for anomalies.
- Identifying suspicious IP addresses or failed authentication attempts.
Once detected, the incident is immediately classified and escalated to our Incident Management Point of Contact (IMPOC).
Phase 2: Containment
The goal of this phase is to stop the attack from spreading. Containment is performed within minutes of detection and includes:
- Isolating affected systems.
- Disabling compromised user accounts or API keys.
- Blocking malicious IP addresses.
- Temporarily suspending affected services and restricting access to sensitive data until the issue is resolved.
Phase 3: Investigation & Eradication
Our technical team performs a detailed investigation to determine how the incident occurred, what systems were affected, the extent of data exposure, and whether Amazon SP-API data was accessed. All findings are documented.
After investigation, eBusiness Services LLC removes the threat completely by:
- Removing malware or unauthorized scripts.
- Patching vulnerabilities and updating firewall access rules.
- Cleaning compromised systems and resetting all affected credentials.
- Eradication ensures the environment is safe before recovery begins.
Phase 4: Recovery
Systems are restored to normal operation under strict validation. Recovery actions include:
- Restoring clean backups and validating system integrity.
- Ensuring all credentials and tokens are newly generated.
- Re-enabling services gradually and monitoring systems closely for recurring issues.
- Amazon Compliance SLA: Our Recovery Time Objective (RTO) ensures we restore availability and access to critical operations and data within hours of a service interruption. Recovery is completed only after confirming the environment is completely secure.
Phase 5: Notification & Communication
eBusiness Services LLC follows strict communication rules regarding security events:
- Mandatory Amazon SLA: If any Amazon data or systems are affected, the Amazon SP-API Security Team is notified at security@amazon.com within 24 hours of detection (superseding our baseline of immediate internal notification).
- Impacted clients are informed promptly.
- Internal management receives a full incident report, and documentation is stored securely for compliance audits. Notifications follow Amazon’s required guidelines.
Phase 6: Post-Incident Logging & Prevention
Every incident is logged with the date and time, description of the event, systems affected, actions taken, recovery steps, final resolution, and lessons learned. Logs are stored securely for compliance and audits.
To prevent future incidents, eBusiness Services LLC:
- Updates security policies regularly and implements stronger authentication and credential rotation.
- Enhances monitoring tools and conducts staff training on security best practices.
- Performs periodic penetration testing and vulnerability scans.
- Amazon Compliance SLA: Specifically, network and application vulnerability scans are executed at least every 30 days, and comprehensive penetration tests are conducted every 365 days.
Policy Review
This Incident Response Plan is reviewed:
- Every 6 months.
- After any major incident.
- When Amazon updates SP-API security requirements.
eBusiness Services LLC Incident Response Plan
Incident Response Plan Summary (Database Hacks, Unauthorized Access & Data Leaks)
eBusiness Services LLC follows a six-phase Incident Response Plan to address database hacks, unauthorized access, and data leaks involving Amazon Information.
Detection & Identification: Continuous monitoring, log analysis, security alerts, failed login monitoring, and SP-API traffic analysis are used to identify potential security incidents.
Containment: Upon detection, affected databases, applications, and cloud resources are isolated. Compromised API keys, tokens, and user accounts are revoked, malicious IP addresses are blocked, and unauthorized access is restricted.
Investigation & Eradication: Technical personnel determine the scope, impact, and root cause of the incident. Unauthorized access, malware, or malicious code is removed, vulnerabilities are remediated, and credentials are reset where necessary.
Recovery: Systems are restored from verified clean backups, integrity checks are performed, security controls are validated, and enhanced monitoring is implemented before normal operations resume.
Amazon Notification: If a security incident involving Amazon Information is detected, eBusiness Services LLC will notify Amazon SP-API Security at security@amazon.com within 24 hours of detection.
Post-Incident Review & Prevention: All security incidents are documented and retained in accordance with applicable compliance and audit requirements. Following remediation, lessons learned are reviewed to improve security controls, incident response procedures, and employee security awareness. Amazon data is retained and deleted in accordance with Amazon’s Data Protection Policy requirements. Regular vulnerability scans are conducted every 30 days, and penetration tests are performed every 365 days to identify and reduce security risks.
