Saltar para o conteúdo principal

Segurança

Última atualização: 4 de setembro de 2026

Hosting

MarginLock, including the marketing site, runs on Amazon Web Services (us-east-1). All production infrastructure is configured via code (AWS CDK) and reviewed in pull requests before applying.

Encryption

  • In transit: TLS 1.2+ for all connections (browser ↔ web, web ↔ API, API ↔ database, API ↔ third-party services).
  • At rest: AES-256 encryption for the application database and object storage. Backups are encrypted with the same key class.

Authentication

We use magic-link authentication backed by short-lived, hashed tokens. Sessions are HTTP-only, secure cookies. We do not store passwords.

Amazon SP-API permissions

The SP-API role set Amazon grants us is broader than what we exercise: MarginLock uses it only to read your Amazon data and compute on it, and it does not create, change, or cancel anything in your seller account — no listings, prices, inventory, orders, inbound shipments, or removal orders. Two of the calls we make are HTTP POSTs because Amazon defines them that way — requesting a report and asking for an FBA fee estimate — and neither alters your account. Every token we store is encrypted with application-level AES-256-GCM before it is written to the database (keys held in AWS Secrets Manager, separate from the database), and tokens are never sent to client browsers.

Data retention

We retain customer Amazon data for as long as your account is active. On account deletion, customer data is purged within 30 days. Aggregated, non-identifying analytics are retained indefinitely.

Incident response

If you believe you've found a security issue, email security@marginlock.io. We acknowledge reports within one business day and follow a coordinated disclosure process.

Subprocessors

For the list of third-party services that may process customer data on our behalf, see our subprocessor list.