Access and credentials
- Each approved user receives an individual identity; shared or default credentials are prohibited.
- Access follows least privilege and is reviewed at least quarterly.
- Access is disabled within 24 hours of termination or a role change.
- Multi-factor authentication is required for accounts that access controlled systems.
- Password standards require at least 12 characters, approved complexity controls, history controls and lockout after no more than 10 unsuccessful attempts.
- Seller passwords and Amazon access keys are never requested or accepted. Credentials under NexZeta’s control are encrypted at rest and rotated at least annually or immediately after suspected compromise.
Encryption and network protection
Information crossing a network boundary is encrypted using TLS 1.2 or higher or another approved secure protocol. Sensitive information at rest is encrypted using at least AES-128 or RSA-2048 strength, with AES-256 preferred where supported. Public endpoints are protected by firewall and application-layer controls. Network access controls, segmentation, anti-malware and endpoint policies restrict unauthorized access and lateral movement.
Endpoint and asset controls
Devices and systems handling Amazon information are inventoried at least quarterly, configured to approved baselines, patched and protected by centrally managed endpoint security. Personal or unmanaged devices and unapproved removable media are not used to store Amazon information. Screen locks activate after no more than 15 minutes of inactivity.
Monitoring and vulnerability management
- Relevant logs record timestamps, user identities, access attempts, changes, errors and success or failure while excluding PII unless required.
- Logs are reviewed through automated monitoring or at least bi-weekly manual review.
- Systems handling Amazon information are vulnerability-scanned at least every 30 days.
- Critical-risk findings are remediated within 7 days; high-risk findings within 30 days.
- Qualified penetration testing and formal third-party security assessment are conducted at least annually where applicable.
- Anti-malware tools are updated at least monthly.
Incident response
NexZeta maintains a management-approved incident-response plan covering preparation, identification, containment, eradication, recovery and lessons learned. The plan and escalation contacts are reviewed at least every six months and after material infrastructure changes or incidents.
Suspected incidents are triaged promptly. If an incident affects Amazon information, NexZeta will notify Amazon at security@amazon.com within 24 hours of detection, preserve chain-of-custody evidence, document remediation and corrective controls, contain access and provide required updates. NexZeta will notify affected clients and authorities where required by law or contract and will not speak on Amazon’s behalf unless Amazon provides written authorization.
To report a suspected security issue involving NexZeta, email info@nexzeta.com with “Security report” in the subject. Do not include customer PII, passwords or keys in the initial email.
Retention, backup and recovery
Amazon customer PII, if permitted and required, is deleted no later than 30 days after order delivery unless a documented law requires limited retention. When authorization ends or NexZeta is otherwise no longer authorized, Amazon information is securely deleted within 30 days of the earliest applicable trigger. Backup and recovery procedures are tested at least quarterly, and recovery objectives are documented for relevant systems.
People and vendors
Approved users must have a documented business need and complete data-protection and security-awareness training at least annually. Vendors are assessed before receiving access and at least annually thereafter, must accept written confidentiality and data-security requirements, and receive only the access necessary for their approved function.
Governance
NexZeta performs an annual risk assessment, maintains change-control procedures, data-processing records, data classification and attribution controls, and documents security responsibilities. Compliance records are retained for the required period and made available during an authorized Amazon assessment. Material organizational changes affecting the need for or use of Amazon information are reported through Amazon’s designated SP-API Solution Provider support channel within 30 days.
This statement describes NexZeta’s control commitments. Implementation records and evidence may be provided during an authorized assessment subject to confidentiality and security restrictions.