Security at SellerWeave
The controls used to isolate customers and protect Amazon Information.
Last updated: 27 September 2026Identity and access
Accounts use strong password hashing, server-side revocable sessions and role-based permissions. MFA is mandatory for owners, administrators and operators. Amazon production access is granted separately for each seller connection.
Tenant isolation
Every catalog and workflow record is scoped by organization, Amazon connection and marketplace. PostgreSQL Row-Level Security provides a second deny-by-default boundary. Background jobs carry the same scope and cannot select credentials from another connection.
Encryption and secrets
Traffic is protected with HTTPS. Amazon refresh tokens use authenticated AES-256-GCM encryption at rest. Application secrets and master keys are supplied as Docker secrets and are redacted from logs and audit output.
Operations
Encrypted off-site backups, restore checks, security audit retention and incident response procedures are maintained for the public deployment. Security-relevant account and connection changes are visible to organization administrators.
Report a concern
Please use the support channel and mark the request as a security issue. Do not include passwords, refresh tokens or other secrets.