Security at FBAgent

FBAgent processes Amazon Selling Partner data on behalf of our customers. Protecting that data is a first-order concern for us. This page describes the technical and organizational measures we use.

Network security

  • All traffic to and from FBAgent is encrypted in transit using TLS 1.2 or higher
  • Our infrastructure is protected by firewalls, DDoS mitigation, and network segmentation
  • We use intrusion detection and prevention systems at the infrastructure layer
  • Anti-virus and anti-malware protection is deployed on all systems that process customer data

Data protection

  • All customer data at rest is encrypted using industry-standard encryption (AES-256 or equivalent)
  • Amazon Selling Partner data is stored in dedicated database instances with encryption enabled
  • Backups are encrypted and stored in geographically redundant locations
  • We do not store Amazon buyer Personally Identifiable Information (PII); we do not request Restricted Data Token (RDT) roles

Access control

  • Access to production systems is restricted to authorized personnel on a least-privilege basis
  • All administrative access requires multi-factor authentication (MFA)
  • Passwords for internal systems must meet minimum length, complexity, and rotation requirements consistent with Amazon's Data Protection Policy: 12-character minimum with special characters, MFA required, 365-day expiration, annual rotation
  • Access is reviewed on a regular basis and revoked promptly on personnel change
  • Access based on job duties and business function; separation of duties enforced where appropriate

Credential and secrets management

  • Amazon LWA client secrets, refresh tokens, database credentials, and API keys are stored in dedicated secret management systems
  • Secrets are never checked into source code repositories
  • Secrets are never shared in email, chat, or public channels
  • Rotation procedures are in place for all long-lived credentials

Application security

  • Code changes are reviewed before deployment
  • Dependencies are monitored for known vulnerabilities and patched on a regular cadence
  • Production deployments go through automated testing and staged rollout
  • Static analysis and dependency scanning are integrated into our build pipeline

Incident response

  • We maintain an incident response plan with defined roles, responsibilities, and escalation paths
  • The plan is reviewed and tested at least every six months
  • In the event of a confirmed security incident involving Amazon Selling Partner data, we will notify Amazon at security@amazon.com within 24 hours of detection, and will notify affected customers as required
  • Post-incident reviews are conducted and used to strengthen our controls

Sub-processor security

  • Is reviewed for security posture before onboarding
  • Operates under a data processing agreement that requires them to protect customer data
  • Is subject to periodic re-review

Data sharing

  • We do not sell or share Amazon Selling Partner data with third parties for marketing or advertising
  • We do not use Amazon Selling Partner data to train third-party machine learning models
  • We do not access customer data except as required to operate, support, or improve the service, or as authorized by the customer

Retrieval of Amazon data

FBAgent retrieves Amazon Information only from Amazon's Selling Partner API, on behalf of the customer who has authorized us to do so. We do not retrieve Amazon data from third-party sources, screen scraping, or other unofficial channels.

Reporting a security concern

If you believe you've found a security vulnerability in FBAgent, please report it to robert@fbagent.ai. We appreciate responsible disclosure and will respond within 3 business days.

FBAgent (a service operated by 14518110 Canada Inc.)
11 Greengable Way, Kitchener, Ontario N2N 3A7, Canada
Email: robert@fbagent.ai