Security and data protection
Protecting the data our customers authorize is a design requirement of B2M - MCP, not an afterthought. This page describes the security controls we apply. They align with the Amazon Data Protection Policy and with the security program declared in our Amazon developer profile.
Network security
Our systems are protected with network security controls including firewalls, intrusion detection and prevention (IDS/IPS), antivirus protection and network segmentation, so that service components are isolated from each other and from general-purpose systems.
Access control
Access to customer data is restricted according to job function, on a need-to-know basis. Every access requires individual credentials; shared accounts are not used. Access rights are reviewed periodically and removed when no longer needed.
Encryption in transit
All communication with the Amazon Selling Partner API, and all traffic between users and this website, is encrypted in transit using TLS. This website is served exclusively over HTTPS.
Credential and secret management
API credentials, access tokens and other secrets are stored securely, never in source code or shared documents, and are rotated periodically. Application lifecycle and credential rotation are managed through the mechanisms Amazon provides to developers for this purpose.
Password policy and MFA
Accounts with access to customer data follow a strong password policy and are protected with multi-factor authentication (MFA), including the accounts used to operate our infrastructure and storage.
Incident response
We maintain an incident response plan covering detection, containment, remediation and notification. Security incidents affecting Amazon data are reported to Amazon at security@amazon.com within 24 hours of detection, and affected customers are informed without undue delay, together with the measures taken.
Reporting a security concern
If you believe you have found a security issue in B2M - MCP or on this website, please write to hello@b2mktplace.com with the details. We review every report and answer personally.