Security
Security by design
Munchello Commerce Control is designed to isolate seller organizations, minimize Amazon data, and keep credentials outside AI systems and user-facing tools.
Effective August 26, 2026
Access control
Administrative access is restricted to approved personnel through identity-aware access controls and multi-factor authentication. Service roles receive only the permissions needed for their function. AI clients receive read and proposal capabilities, never credential, approval, or unrestricted execution access.
Tenant isolation
Each seller organization has its own Amazon grants, tenant identifier, authorization rules, encryption context, and auditable data boundary. Server-side authorization derives the tenant and permitted advertiser profiles from the verified session; clients cannot select another tenant by supplying an identifier.
Credential protection
Amazon client secrets and refresh tokens are encrypted before storage and are available only to dedicated connection and execution services. Credentials are never placed in prompts, browser storage, source control, or application logs. Tokens are rotated or revoked when access changes.
Data protection
Connections use HTTPS. Production data stores use encryption at rest, scoped service bindings, backups, and retention limits. Raw Amazon payloads and search terms are treated as untrusted input and are minimized before logging or AI analysis.
Controlled advertising changes
Advertising changes are evaluated against allowlisted accounts and objects, current account state, data freshness, profitability, inventory, per-change limits, daily exposure, cumulative caps, idempotency, and rollback information. Every executed change is tied to a traceable authorization and verification record.
Monitoring and incident response
Security and operational events are logged, reviewed, and retained according to the privacy notice. Suspected unauthorized access triggers credential revocation, affected-tenant isolation, evidence preservation, investigation, remediation, and notification when required.
Report a vulnerability or incident
Email amazon-api@munchellollc.com with the subject “Security report.” Include the affected URL, a concise description, reproduction steps, and a safe contact method. Do not access data that is not yours, disrupt service, or publicly disclose an unresolved issue. We will acknowledge credible reports and coordinate remediation.