The following security policy defines W & F TRADING LLC’s requirements for handling seller information. SP-API functionality is enabled only after Amazon approval and explicit seller authorization through Amazon OAuth.
Authorized access
Access must use individual identities, least privilege and MFA. The access policy requires quarterly reviews and revocation within 24 hours of departure. Passwords require at least 12 characters, mixed character types and an expiry no longer than 365 days.
Encryption & credentials
Seller information must use TLS 1.2 or higher in transit. Stored service data, backups and credentials require encryption, with keys held separately in managed key storage. Secrets must not be embedded in code or public repositories.
Network & vulnerability controls
Production systems require firewalls, segmentation, intrusion detection or prevention and anti-malware controls. Vulnerability scans must run monthly; critical and high-risk findings require remediation within seven and 30 days respectively.
Incident response
The incident response policy requires an assigned response owner, documented escalation procedures, review of security and access logs for suspicious activity, and a review of the response plan every six months. Incidents involving Amazon information must be reported to security@amazon.com within 24 hours of discovery, with required customer and authority notices.
Purpose & retention
Collect only information needed for the agreed workflow. The retention policy governs operational data, security records and backup deletion. Deletion must be tested and remain effective after recovery.
Provider oversight
External processors require a documented purpose, access review and contractual protections before receiving seller data. Connected-service processing locations and providers must be disclosed before onboarding.
Seller control
Authorize. Review.
Disconnect.