Security at SellerWeave

The controls used to isolate customers and protect Amazon Information.

Last updated: 27 September 2026

Identity and access

Accounts use strong password hashing, server-side revocable sessions and role-based permissions. MFA is mandatory for owners, administrators and operators. Amazon production access is granted separately for each seller connection.

Tenant isolation

Every catalog and workflow record is scoped by organization, Amazon connection and marketplace. PostgreSQL Row-Level Security provides a second deny-by-default boundary. Background jobs carry the same scope and cannot select credentials from another connection.

Encryption and secrets

Traffic is protected with HTTPS. Amazon refresh tokens use authenticated AES-256-GCM encryption at rest. Application secrets and master keys are supplied as Docker secrets and are redacted from logs and audit output.

Operations

Encrypted off-site backups, restore checks, security audit retention and incident response procedures are maintained for the public deployment. Security-relevant account and connection changes are visible to organization administrators.

Report a concern

Please use the support channel and mark the request as a security issue. Do not include passwords, refresh tokens or other secrets.