Trust & Compliance

Security & Data Protection Overview

MarginLane is engineered to meet the stringent security, encryption, and data governance standards of the Amazon Selling Partner API (SP-API) and European data privacy laws.

Authorization & Access

Explicit Amazon OAuth 2.0 Authorization

MarginLane accesses Selling Partner API data exclusively through Amazon's official OAuth authorization consent flow. We never ask for, log, or store your Seller Central master password, two-factor codes, or AWS root keys. Sellers retain full control to revoke authorization at any time from Seller Central.

  • ✓No master password collection or storage
  • ✓Explicit user consent via Amazon Appstore / LWA consent flow
  • ✓Per-tenant refresh token isolation with instant revocation support
Credential Governance

Cryptographic Credential Storage & Masking

All Amazon SP-API refresh tokens, client secrets, and sensitive integration parameters are encrypted at rest using AES-256-GCM before database insertion. Tokens are decrypted in volatile server memory solely when generating short-lived access tokens and are never exposed in browser network responses, error logs, or client-side code.

  • ✓Envelope encryption using AES-256-GCM at rest
  • ✓Strict masking in all backend application logs and APM telemetry
  • ✓Short-lived access tokens with automated 60-minute expiry
Data Isolation

Logical Multi-Tenant Isolation & RBAC

Every MarginLane account operates in an isolated tenant boundary. Backend queries enforce strict tenant_id constraints at the data layer, ensuring supplier lists, custom cost profiles, shortlists, and sales metrics can never be viewed or accessed by other subscribers.

  • ✓Enforced tenant ownership validation on every API controller
  • ✓Role-Based Access Control (RBAC) separating workspace members and admins
  • ✓Zero cross-account data leakage across multi-tenant databases
Transport & Storage

End-to-End Encryption Standards

All communications between your browser, our infrastructure, and external APIs (Amazon SP-API, Keepa) are encrypted using TLS 1.2 or TLS 1.3 with modern cipher suites. Cloud databases, backups, and storage buckets are encrypted at rest utilizing industry-standard AES-256 keys.

  • ✓Strict HTTPS / TLS 1.2+ enforcement across all public endpoints
  • ✓Encrypted cloud database storage, automated daily backups, and WAL logs
  • ✓Automated SSL certificate provisioning and renewal with HSTS enabled
Operational Security

Least Privilege & Internal Access Controls

Access to production systems is governed by the principle of least privilege. MarginLane personnel utilize unique SSO identities, hardware-backed multi-factor authentication (MFA), and role-restricted bastions. Production databases are never accessed directly without audited change controls.

  • ✓MFA mandatory on all internal administrative accounts
  • ✓Zero shared credentials across engineering and operations teams
  • ✓Audit logging of all infrastructure modifications and deployments
Data Governance

Amazon Data Protection Policy (DPP) & Lifecycle

In full compliance with the Amazon Data Protection Policy (DPP) and Acceptable Use Policy (AUP), MarginLane retains Amazon data only as long as necessary to fulfill analytical functions. MarginLane V1 operates a strict Zero Buyer-PII policy: customer names, shipping addresses, and phone numbers are never requested, fetched, or stored.

  • ✓Strict Zero Buyer-PII architectural guarantee in MarginLane V1
  • ✓Automated data purging upon account deletion or seller authorization revocation
  • ✓Transient market signal TTLs (cached pricing refreshed within 1-6 hours)
Monitoring & Reliability

24/7 Threat Monitoring & Rate Telemetry

Our infrastructure continuously monitors security events, rate limit limits, authentication anomalies, and API failure rates. Built-in exponential backoff with full jitter ensures strict compliance with Amazon SP-API rate quotas without overwhelming third-party endpoints.

  • ✓Real-time logging of Amazon x-amzn-RateLimit-Limit telemetry
  • ✓Automated IP throttling and DDoS mitigation
  • ✓Automated vulnerability and dependency patch scanning in CI/CD
Governance & Incident Response

Incident Response Plan & 24-Hour Amazon Notification Protocol

MarginLane maintains a documented, senior-management-approved Incident Response Plan reviewed semi-annually. In strict compliance with the Amazon Data Protection Policy (DPP §9) and ML-AZ-09:

1. 24-Hour Amazon SLA

In the event of any verified or suspected unauthorized access, credential exposure, or breach involving Amazon Information, MarginLane will formally notify Amazon Information Security ([email protected]) within 24 hours of discovery.

2. Immediate Containment

Affected seller SP-API tokens and credentials are automatically revoked within minutes. Tombstone markers are applied across all endpoints to prevent replay attacks or unauthorized API interaction.

3. IMPOC & Disclosures

Our Incident Management Point of Contact (IMPOC) leads communication. Security researchers and auditors can verify disclosures via our RFC 9116 security.txt record.

Security Officer (IMPOC): [email protected] • Invora Digital Technologies