Security & data handling

Built for sellers, designed for Amazon's compliance bar.

Flip IQ Batch holds the minimum data needed to analyze your catalogs. We don't request order data, buyer data, or PII to do core analysis.

01

Data in transit

All traffic uses TLS 1.3. Uploads are signed and chunked; no file is processed before integrity is verified.

02

Data at rest

Files and results are encrypted at rest (AES-256). Per-tenant keys; isolated storage buckets per organization.

03

Credentials

API keys are hashed at rest and shown once at creation. Seller authorization tokens are stored in a managed secret vault — never on application servers.

04

Access control

Role-based access for Team plans. SSO available for Team and Enterprise. All actions are audit logged.

05

Data minimization

We don't ingest buyer PII, order data, or financial account details for core catalog analysis. SP-API access is read-only and scoped.

06

Retention & deletion

You control retention. Jobs and exports can be deleted at any time. Account deletion purges all customer data within 30 days.

Technical controls

The exact security posture, by the numbers.

These are the controls a reviewer would expect to see on a Solution Provider operating under Amazon's Data Protection Policy. We meet or exceed each one.

TLS encryption
1.2+ enforced on every endpoint, 1.3 by default
Data-at-rest encryption
AES-256 via AWS KMS, annual key rotation
Credential storage
AWS Secrets Manager — never in code, never in repos
LWA refresh-token rotation
Annual, automated
MFA
Required on every internal account that touches customer data
Account lockout
After 10 failed attempts (per DPP Nov 2025 update)
Password policy
12+ chars, mixed case + digits + symbols, last 10 retained
Network
VPC isolation, IDS/IPS, restricted egress
Backups
Encrypted, geographically separated within the same region
Deletion method
NIST SP 800-88r1 (Clear / Purge)
Non-PII data retention
18 months maximum per Amazon's DPP
On revocation
30-day primary purge, 90-day backup purge
Detection & response

How we find problems and how fast we fix them.

Hardening is one half of the job. Catching what gets through, and reacting fast, is the other. These are the operational practices we run continuously, not just before reviews.

Vulnerability scanning

Automated scans at least monthly. Critical vulnerabilities are resolved within 7 days, high-risk within 30 — the SLAs Amazon's DPP defines.

Logging & audit trail

Centralized logs from every system that touches Amazon data, retained 12 months. Bi-weekly manual review plus real-time anomaly alerting.

Incident response plan

Documented, approved by senior management, reviewed every 6 months. Tabletop exercises run twice a year.

Access management

Least-privilege by default. Quarterly access review for every role and service account. Personnel access disabled within 24 hours of termination.

Third-party risk

Annual risk assessment for every sub-processor. DPAs in place with each. We cooperate with any audit Amazon or its agents may request.

Incident Management Point of Contact

Per Amazon's Data Protection Policy, we maintain a designated IMPOC reachable around the clock for security incidents involving Amazon data. Any incident is reported to Amazon within 24 hours of detection.

Notification SLA24 hours per Amazon DPP
AI use disclosure

Inference, not training. Your data stays yours.

  • Opportunity scoring and explanations run as inference over your authorized data inside our infrastructure.
  • We do not train shared or proprietary models on Amazon-sourced data.
  • Amazon Information is never used to develop or improve AI systems, in line with the 25 November 2025 update to Amazon's Acceptable Use Policy.
  • We do not share or sell prompts, completions, or any model input/output containing your data with third parties.

What we don't do

  • ×Scrape Amazon storefronts or buyer-side pages.
  • ×Store buyer names, addresses, or order history.
  • ×Resell or share your catalog data with third parties.
  • ×Train shared models on your private supplier files.
TL;DR. Your files are yours. We process them, hand back results, and let you delete them whenever you want. No 'buts', no fine print.