INFOSEC & COMPLIANCE
Security Architecture & Amazon DPP Compliance
Executive Security Summary: SunCroix is engineered from the ground up to meet and exceed the security controls mandated by the Amazon Selling Partner API Data Protection Policy (DPP) and Acceptable Use Policy (AUP). Operating as an enterprise-grade multi-tenant SaaS serving global brands, high-volume FBA merchants, and multi-entity cross-border operators, we enforce zero-trust cryptographic isolation, strict non-PII operations, and hardware-backed envelope encryption.
1. The Non-PII Architectural Philosophy
SunCroix does not request, ingest, or persist Amazon Customer Personally Identifiable Information (Buyer Name, Phone Number, Physical Delivery Address). By restricting our integration strictly to financial settlement, FBA inventory movements, and catalog economics, we eliminate 99% of external attack surface and data leakage risks.
2. Key Security Controls Matrix
- Encryption at Rest: AES-256 with tenant-scoped KMS keys applied across all production databases, search indexes, and automated daily backups.
- Encryption in Transit: Mandatory TLS 1.2 and TLS 1.3 with HSTS (HTTP Strict Transport Security) for all public web and API ingress.
- Credential Isolation: HashiCorp Vault manages Amazon SP-API OAuth refresh tokens with envelope encryption. Plaintext secrets exist solely in ephemeral memory during execution.
- Multi-Tenant Row-Level Security (RLS): Hardened database-level row-level security partitions each seller's data by immutable
tenant_id. Zero cross-tenant querying is physically possible. - Administrative Access: Mandatory Multi-Factor Authentication (TOTP MFA) on all developer and operations accounts. Least privilege role-based access control (RBAC).
- Network Protection: Databases, workers, and secret stores reside on private networks with zero public internet exposure. Edge protection is guarded by Cloudflare Enterprise WAF and DDoS mitigation.
3. Enterprise Multi-Tenant Architecture & Workspace Isolation
Whether onboarding global consumer brand manufacturers, high-growth private label brands, or multi-brand cross-border conglomerates, each organization is provisioned a dedicated, cryptographically isolated workspace with:
- Dedicated cryptographic keys for token storage.
- Strict tenant-bound worker execution queues.
- Prohibition of cross-merchant data pooling (no shared analytics, no competitive price benchmarking).
4. Automated 30-Day Data Lifecycle & Purge
In accordance with Amazon DPP Section 3.2, SunCroix implements an automated data lifecycle scheduler:
- Upon receipt of an Amazon OAuth revocation event or seller account closure, all scheduled sync jobs are immediately disabled.
- The workspace enters a quarantined soft-delete state.
- Within 30 calendar days, an automated cryptographic purge wipes all raw and derived records across active tables, worker caches, and snapshot archives.
- An auditable deletion report is generated recording timestamps and object counts without retaining sensitive payload data.
5. Incident Response Protocol (24-Hour SLA)
SunCroix maintains a 24/7 Security Incident Response Team (SIRT). In the event of a verified or suspected security incident involving Amazon Information, we commit to notifying Amazon Security at 3p-security@amazon.com and affected sellers within 24 hours with root-cause analysis and remediation steps.
6. Security Contact & Vulnerability Reporting
We welcome independent security researchers and merchant security teams to review our infrastructure:
- Security Desk: security@suncroix.com
- PGP Key: Available upon request for encrypted disclosure.
- SLA: Critical vulnerability reports acknowledged within 4 hours.