Operational safeguards

Data Security

Controls designed around data minimization, protected credentials, authorized access and human-approved changes.

Security controls

These measures describe the controls prepared for our website and internal listing workflow.

1. Data minimization

Only listing information necessary to complete internal listing-management tasks is retrieved or retained.

2. Credential protection

Amazon Client Secrets, Refresh Tokens and Access Tokens are never written to webpages, Excel files, logs or source code. The desktop application uses Windows Credential Manager or equivalent secure storage.

3. Access control

Only authorized company employees may use the internal application. Access is removed when it is no longer required.

4. Encryption

External API requests use HTTPS/TLS. The public website is published through HTTPS and avoids mixed content.

5. Human approval

Model-generated content requires employee review. Production write operations require a separate confirmation.

6. Logging and backups

Redacted operational logs and versioned snapshots support review and rollback. Backups do not contain API credentials.

7. External model providers

Only when an administrator actively configures a model service are minimum necessary product fields sent. Buyer PII, payment information and Amazon credentials are excluded.

8. Incident response

If credential exposure, abnormal access or another security incident is detected, related access is stopped, credentials are rotated, logs are investigated and corrective action is taken.

9. Data deletion

Authorized administrators delete local listing snapshots and exports when they are no longer required under internal retention rules.

Security boundary

We do not represent that the organization holds ISO 27001, SOC 2 or another external security certification unless such a certification is actually obtained and independently verified.