eBusiness Services LLC ("Elite Business") provides Amazon Seller Central account-management services on behalf of authorized clients.
Protecting client information and Amazon Information is an important part of our operations. This page summarizes the administrative, technical, and organizational safeguards we maintain for information accessed in connection with our services.
Our internal security procedures address access management, credential security, data protection, vulnerability management, personnel security, and incident response.
1. How We Access Client Amazon Accounts
Client Amazon access is established through Amazon-approved account-access mechanisms and is limited to the permissions required to perform the authorized service.
Where access is provided through Amazon's Solution Provider Portal:
- The seller authorizes the applicable access through Seller Central.
- Access is limited to roles and permissions applicable to the engagement.
- Each authorized staff member uses an individually assigned account.
- We do not request, store, or use a seller's primary Seller Central password, shared login credentials, or two-step verification codes.
- Access is granted according to job responsibilities and the principle of least privilege.
- Personnel and service access is reviewed at least quarterly.
- Access that is no longer required following termination or a relevant role change is disabled or removed within 24 hours.
Access to each client environment is limited to personnel with an authorized business need.
2. Information We Protect
We protect Amazon Information accessed or processed in connection with authorized client services.
Depending on the permissions granted and services performed, this information may include:
- Seller account information
- Account health and performance information
- Catalog and listing information
- Inventory and fulfillment information
- Order information
- Advertising information
- Financial and settlement information
- Buyer communications
- Customer information and PII where necessary for an authorized service
Access to customer PII is limited to circumstances in which it is required to perform the authorized business function.
3. Access Control
We maintain access controls designed to ensure that protected information is accessible only to authorized users.
Our controls include:
- Unique user identities
- Role-based access control
- Least-privilege access
- Multi-factor authentication
- Individual rather than shared accounts
- Formal authorization according to business need
- Quarterly access reviews
- Restricted administrative access
- Prompt removal of access that is no longer required
Microsoft 365 and Microsoft Dynamics 365 are used as part of our approved business environment, with access restricted according to user responsibilities.
Personnel are prohibited from storing protected Amazon Information on personal or unauthorized devices.
4. Credential Management
Authentication credentials and security secrets are protected through documented credential-management procedures.
Our controls include:
- Passwords of at least 12 characters where password authentication is used
- Password complexity requirements
- Multi-factor authentication
- Individual credentials rather than shared credentials
- Restricted access to administrative accounts
- Secure handling of authentication secrets
- Prompt credential changes where compromise is suspected or confirmed
Passwords, authentication tokens, API keys, and other secrets must not be stored in ordinary documents, source code, unsecured email messages, or chat conversations.
Credentials used for client work are restricted to authorized personnel and are not shared between staff members or unauthorized third parties.
5. Systems, Network, and Endpoint Protection
Our approved business and security environment includes Microsoft 365, Microsoft Dynamics 365, Microsoft Defender, and Cloudflare.
We use layered safeguards to protect systems and devices used for client work.
These include:
- Identity-based access controls
- Firewall and access restrictions
- Cloudflare application-layer protection for public-facing website infrastructure
- Traffic filtering and protection against malicious or automated activity
- Microsoft Defender endpoint and anti-malware protection
- Security patching and software updates
- Restricted administrative access
- Monitoring for suspicious or unauthorized activity
Endpoint protection is maintained on workstations authorized to access protected business information.
Users are not permitted to disable required endpoint-security protections.
6. Encryption and Storage
Protected information is encrypted in transit using secure protocols such as TLS 1.2 or higher where applicable.
Sensitive information and PII stored electronically are protected using appropriate encryption-at-rest controls provided by approved enterprise systems.
Our controls are designed to prevent unauthorized storage of Amazon Information on:
- Personal devices
- Unapproved removable media
- Unmanaged cloud-storage services
- Consumer file-sharing services
- Unauthorized messaging or collaboration systems
Backups containing protected information are encrypted and access restricted.
Protected information is limited to the minimum amount reasonably necessary for the authorized purpose.
7. Retention and Secure Deletion
We apply data-minimization and retention controls to Amazon Information.
Amazon Customer PII
Amazon customer PII is retained only for the minimum period necessary to perform an authorized service and is deleted no later than 30 days after order delivery unless applicable law requires specific information to be retained longer.
Other Amazon Information
Non-PII Amazon Information is retained only for as long as strictly necessary for the purpose for which it was obtained or to satisfy applicable legal, tax, or regulatory obligations.
Amazon Information is securely deleted within applicable Amazon-required periods when:
- Amazon requires deletion;
- the client revokes authorization or terminates our access;
- we determine that we are no longer authorized to process the information; or
- our participation in the relevant Amazon service ends.
Where information must legally be retained for a longer period, access remains restricted and the information remains subject to appropriate security controls.
8. Logging and Security Monitoring
We maintain security and access monitoring appropriate to the systems used in our operations.
Monitoring is designed to identify events such as:
- Failed or suspicious authentication attempts
- Unauthorized access attempts
- Malware or endpoint threats
- Unusual account or device activity
- Relevant system or application errors
- Potential security incidents
Security and access information is available only to authorized personnel.
Relevant logs and security events are periodically reviewed and investigated where appropriate.
9. Vulnerability Management
We maintain procedures designed to identify and address security vulnerabilities affecting systems used to process or access protected information.
Our vulnerability-management activities include:
- Routine software and security patching
- Vulnerability scanning at least every 30 days for applicable systems
- Risk-based evaluation of identified vulnerabilities
- Annual penetration testing of applicable systems
- Additional security review following significant changes where appropriate
Critical and high-risk findings are prioritized for timely remediation in accordance with applicable Amazon security requirements.
10. Incident Response
We maintain a documented Incident Response Plan designed to address events including unauthorized access, credential compromise, system compromise, malware, database compromise, and suspected or confirmed information leakage.
Our incident-response process follows six principal phases:
Preparation
We maintain defined responsibilities, escalation procedures, security controls, and response resources so that incidents can be addressed promptly.
Identification
Suspected incidents are investigated to determine what occurred, which systems or accounts are affected, what information may be involved, and the potential severity of the incident.
Relevant evidence is preserved where appropriate.
Containment
Affected accounts, credentials, devices, applications, or services may be isolated, restricted, disabled, or otherwise contained to prevent further unauthorized activity or information loss.
Eradication
The cause of the incident is identified and addressed.
Actions may include removing malicious software, correcting configurations, patching vulnerabilities, resetting credentials, revoking sessions, and removing unauthorized access.
Recovery
Affected systems and services are restored in a controlled manner after appropriate validation.
Heightened monitoring may be used following recovery to identify recurrence or continuing unauthorized activity.
Lessons Learned
The incident and response are documented and reviewed.
Corrective and preventive actions are identified and used to improve security controls, procedures, and future response activities.
Notification and Escalation
A designated incident-management contact coordinates escalation and response.
Security incidents involving Amazon Information are escalated internally without unnecessary delay.
Amazon is notified within 24 hours of detection where required under applicable Amazon security requirements.
Affected clients and relevant governmental or regulatory authorities are notified where required by applicable law, contract, or Amazon requirements.
The Incident Response Plan is reviewed at least every six months and following significant incidents or material changes affecting the security environment.
11. Third-Party Risk Management
We do not share one client's Amazon Information with another client.
Service providers that may process protected information are used only where there is a legitimate business requirement.
Depending on the service and information involved, appropriate controls may include:
- Security and privacy review
- Confidentiality obligations
- Contractual data-protection requirements
- Restricted access
- Periodic reassessment
Third parties are not given access to Amazon Information without an authorized business need.
12. Personnel Security and Training
Personnel with authorized access to protected information receive security and data-protection training appropriate to their responsibilities.
Training addresses areas including:
- Protection of confidential and personal information
- Credential security
- Multi-factor authentication
- Phishing and social-engineering awareness
- Proper handling of Amazon Information
- Reporting security events
- Incident-response responsibilities
Training is provided at onboarding and refreshed at least annually for relevant personnel.
13. Security Governance and Review
Our security procedures are periodically reviewed and updated to reflect changes in:
- Business operations
- Technology
- Security threats
- Applicable law
- Client requirements
- Applicable Amazon security and data-protection requirements
Incident-response and related security procedures are reviewed at least every six months and following material incidents or significant changes.
Identified security issues are documented and tracked for appropriate corrective action.
14. Organizational Changes
Where required under applicable Amazon requirements, we update Amazon regarding material organizational changes such as changes to:
- Legal entity name
- Ownership
- Business address
- Relevant security contacts
- Other material organizational information
Such notifications are made within the applicable required period.
15. Contact
Questions concerning our data-security practices may be directed to:
eBusiness Services LLC
Doing business as Elite Business
210 Brand Lane, STE C
Stafford, TX 77477
United States
Email: security@elitebusinessllc.org
Phone: +1 (945) 544-4305
