Security & Trust

SellerFusion handles data on behalf of Amazon Selling Partners and other marketplace operators every day. We take that responsibility seriously. This page summarizes how we protect customer and marketplace data, how we respond to security incidents, and how we comply with Amazon, GDPR, and CCPA requirements.

Our Security Program

Reviewed by senior management on a regular basis. Built on industry-standard frameworks (NIST SP 800-53 and the Amazon SP-API security control guidance).

Encryption

All customer data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Encryption keys are stored in dedicated key management systems and rotated periodically.

Access Control

Least-privilege access for all employees and services. Multi-factor authentication on all accounts. Regular access reviews. Terminated employee access promptly disabled.

Vulnerability Management

Ongoing vulnerability scanning. Periodic third-party penetration testing. Vulnerabilities remediated on a prioritized basis according to severity.

Network Protection

Segmented networks with intrusion detection and prevention. Anti-malware on all servers and endpoints, kept up to date. Continuous monitoring for credential exposure.

Logging & Monitoring

Centralized log collection from all systems handling marketplace data. Security logs retained in line with applicable compliance requirements. Continuous monitoring of security events.

Personnel Security

All employees and contractors with access to customer data complete security awareness training. Background checks and signed confidentiality agreements for all personnel.

Incident Response

SellerFusion maintains a documented Incident Response Plan, approved by senior management, structured against NIST SP 800-53 IR-8.

Response Plan

All six standard NIST IR phases — preparation, identification, containment, eradication, recovery, lessons learned — with procedures tailored to each incident category. Severity-based response SLAs from a 15-minute initial response for critical incidents to next-business-day for low-severity events.

A designated Incident Management Point of Contact (IMPOC) is reachable to coordinate response, with primary and backup coverage. Plan reviewed periodically and after any major infrastructure change. Tabletop exercises validate the plan in simulated scenarios.

Notification Commitments

Amazon: within 24 hours of detecting any security incident affecting Amazon information, in line with the Amazon Data Protection Policy.

EU supervisory authorities (GDPR): within 72 hours of confirming a personal data breach affecting EU residents.

Affected customers and marketplace partners: in line with applicable law and our contractual obligations.

To report a suspected incident or vulnerability, contact security@sellerfusion.io. Our IMPOC will respond within one business day.

Data Retention

SellerFusion follows the Amazon Data Protection Policy and applies strict data minimization — we collect, store, and process only the data we need.

Personally Identifiable Information

Retained only as long as necessary, in line with the Amazon Data Protection Policy, then securely deleted following industry-standard sanitization processes.

Non-PII Marketplace Data

Retained in line with applicable retention policies and regulatory requirements.

Security & Audit Logs

Retained in line with applicable compliance requirements for forensic purposes.

Backups

Same retention as primary data. Encrypted at rest using AES-256, geographically replicated.

Data is permanently and securely deleted within 30 days of any deletion request, unless retention is legally mandated. Our data classification system tags PII separately from non-PII at the storage layer.

Compliance

SellerFusion is a registered developer in the Amazon Selling Partner Appstore and complies with the major data protection requirements that govern our platform.

Amazon DPP

Compliant with the Amazon Data Protection Policy, Amazon SP-API security control guidance, and the Solution Provider Agreement.

GDPR

Compliant with the General Data Protection Regulation. 72-hour supervisory authority notification commitment for personal data breaches affecting EU residents.

CCPA

Compliant with the California Consumer Privacy Act. California residents may exercise their privacy rights via privacy@sellerfusion.io.

Reporting a Vulnerability

If you have discovered a potential security vulnerability in SellerFusion, please follow these steps.

  1. Email security@sellerfusion.io with as much detail as you can — affected URL, reproduction steps, impact, and any proof-of-concept material.
  2. Please do not publicly disclose the issue until we have had a chance to investigate and remediate.
  3. We will acknowledge receipt within one business day and provide regular status updates until the issue is resolved.
  4. We are happy to credit responsible researchers in our acknowledgments.

This page was last updated: 8 April 2026. We review and update our security posture on a regular basis.

Have a security question?

Our team is happy to discuss our security posture, compliance, or any specific concerns you have.

Contact Security Team