SellersOS Logo SellersOS SELLERSOS LLC
← Back to site

Security & Vulnerability Reporting

Effective 16 September 2026 · Technical Security Architecture & Responsible Disclosure Policy

At SellersOS, data protection and infrastructure security are fundamental to our architecture. We implement stringent administrative, technical, and physical safeguards designed to align with published Amazon Selling Partner API Data Protection Policy (DPP) requirements, Amazon Key Security Control Guidance, and Amazon Ads Partner Network Policies.

Contents
  1. Technical security controls
  2. Vulnerability disclosure policy
  3. How to report a vulnerability
  4. Incident response and Amazon notification
  5. Security point of contact

1. Technical security controls

Security Domain Implementation & Amazon DPP (August 2026) Compliance Standard
Encryption in Transit All public and internal data communications are enforced via TLS 1.2 or higher (TLS 1.3 preferred where supported) with HTTP Strict Transport Security (HSTS). Unencrypted HTTP traffic is rejected at the network edge.
Encryption at Rest Persistent databases, EBS volumes, and automated backup snapshots are encrypted using AES-256 with keys managed by AWS Key Management Service (AWS KMS). Amazon API credentials, OAuth tokens, and secrets are encrypted at rest with scheduled rotation.
Web Application Firewall (WAF) & API Protection All internet-facing public endpoints and API gateways are protected by a Web Application Firewall (WAF) with managed rule sets defending against OWASP Top 10 vulnerabilities, automated bot abuse, SQL injection, cross-site scripting (XSS), and Layer 7 DDoS attacks.
Workforce Device Full-Disk Storage Encryption All workforce workstations, developer laptops, and administrative devices accessing platform infrastructure enforce full-disk storage encryption (BitLocker, FileVault, or LUKS with AES-256). Storing unencrypted sensitive configuration data on local media is strictly prohibited.
Automatic Screen Locking All workforce and administrative devices enforce an automatic screen lock policy configured to activate after no more than 15 minutes of inactivity, requiring password or biometric re-authentication.
Identity & Access Management (MFA & Lockout) Multi-Factor Authentication (MFA) is mandatory for all user accounts operating within systems that access Amazon Information, including customer accounts, seller workspace team members, engineering, and administrative personnel. Password policies enforce at least 12 characters with mixed uppercase, lowercase, numerals, and symbols; prohibit including usernames, email prefixes, or brand names; enforce a minimum age of 1 day and expiration at 365 days; prohibit reuse of the last 10 passwords; and enforce temporary account lockouts of at least 30 minutes after no more than 10 failed login attempts within a 30-minute window. Access privileges undergo formal quarterly reviews; terminated credentials are revoked within 24 hours.
Workforce Endpoint Security & Anti-Malware All workforce devices running administrative or developer tools maintain centrally managed endpoint protection / anti-malware software with automated signature and definition updates.
Tenant Data Isolation SellersOS employs strict logical tenant isolation. Each selling partner's operational data is partitioned at the database layer; cross-tenant database joins and shared analytics tables are architecturally prohibited. Zero cross-tenant data pooling.
Network Isolation Production databases reside in private subnets with no public internet routing. Databases accept incoming connections exclusively from authorized application instances within dedicated security groups.
Vulnerability Management & Penetration Testing Automated monthly vulnerability scanning across application dependencies, containers, and host infrastructure. Annual third-party penetration testing covering both web applications and public API endpoints. Remediation SLA: Critical severity vulnerabilities are patched within ≤ 7 calendar days; High severity vulnerabilities within ≤ 30 calendar days.
Audit Logging & 12-Month Retention Comprehensive security and audit logs capture authentication events, administrative actions, and API interactions. Security logs are retained for at least 12 months in tamper-resistant log repositories, excluding sensitive customer PII.
Artificial Intelligence & Amazon DPP §2 SellersOS strictly adheres to Amazon Data Protection Policy (DPP) §2 regarding automated and AI-assisted workflows. Amazon Information and seller operational metrics are never utilized to train, retrain, fine-tune, or benchmark generalized, foundational, or third-party artificial intelligence models. All AI-assisted queries and creative features operate within ephemeral, single-tenant memory isolation. Automated bid or inventory recommendations require explicit seller confirmation or user-defined boundary parameters, backed by an immutable 12-month audit log.

2. Vulnerability disclosure policy (Responsible Disclosure)

SellersOS welcomes reports from security researchers and industry partners who identify potential vulnerabilities or suspected data security issues in our services. We are committed to working with ethical researchers to validate and resolve verified findings promptly.

Research Guidelines & Safe Harbor

When conducting security testing, researchers must adhere to the following rules:

If you conduct your research in good faith compliance with these guidelines, SellersOS will consider your research authorized and will not pursue or initiate legal action against you.

3. How to report a security issue

If you discover a vulnerability, security bug, or suspected misuse of Amazon Information, please send an encrypted report directly to our security team:

Report recipient: security@sellersos.net
Required information:

4. Incident response & Amazon notification

SellersOS maintains an active Incident Response Plan overseen by our designated Incident Management Point of Contact. Upon receipt of a vulnerability or security report:

  1. Triage: Initial confirmation of receipt within 24 hours.
  2. Investigation & Containment: Verification of severity, threat assessment, and immediate containment measures.
  3. Remediation: Engineering fix applied pursuant to our SLA (≤ 7 days for Critical, ≤ 30 days for High).
  4. Amazon Notification: Where an incident involves Amazon Information or credentials, SellersOS will notify Amazon at security@amazon.com within 24 hours of detection, and will coordinate fully with Amazon's security and legal personnel.

5. Security point of contact

For inquiries regarding platform security, compliance questionnaires, or vulnerability reports:

SELLERSOS LLC
Attn: Incident Management & Information Security
30 N Gould St Ste N, Sheridan, WY 82801, United States
Email: security@sellersos.net

\n