Data security
How we protect seller data across the Oufu seller platform, aligned with the Amazon Data Protection Policy and Acceptable Use Policy.
Encryption
- All data in transit is encrypted with TLS 1.2 or higher.
- All Amazon data at rest is encrypted with AES-256.
- Credentials and API tokens are stored in a dedicated secrets manager, never in code or configuration files.
Access control
- Role-based access on the principle of least privilege: staff see only the data their role requires.
- Multi-factor authentication is mandatory for all internal systems that touch seller data.
- Access is reviewed quarterly and revoked immediately on role change or departure.
Infrastructure
- The platform runs on hardened cloud infrastructure with network isolation between environments.
- Production databases are not reachable from the public internet.
- Backups are encrypted and tested for restorability.
Data minimization
- We request only the SP-API roles and datasets a subscribed module needs.
- Buyer personally identifiable information is used solely to fulfill orders and related duties such as tax and returns.
- Buyer PII is deleted within 30 days after order delivery, unless law requires longer retention in a compliant archive.
Monitoring & incident response
- Centralized logging and alerting cover authentication, data access, and API activity.
- A documented incident response plan assigns owners, escalation paths, and communication duties.
- Incidents affecting Amazon data are reported to Amazon within 24 hours of detection.
Vulnerability management
- Dependencies and images are scanned continuously; critical patches are prioritized.
- Changes reach production through review and CI checks, never by direct edits.
- We conduct periodic security reviews of the platform and its integrations.
Security questions or reports: support@desigmetry.com
Read the privacy policy