Security posture
AmazonIQ is designed as a premium SaaS platform with secure authentication, access controls, monitoring, and operational safeguards. The product is built around authorized seller control, Amazon OAuth connection flows, and trusted infrastructure providers.
Amazon token protection
Amazon connection tokens are encrypted at rest and restricted to server-side workflows serving the seller-authorized Amazon SP-API connection. AmazonIQ does not expose connection secrets to the browser.
Read-only protection
AmazonIQ uses supported Amazon seller data in read-only mode. It does not change prices, edit listings, update inventory, alter orders or fulfillment, or send buyer messages. Sellers can disconnect access at any time.
Minimal data principle
AmazonIQ is designed to use the minimum account context needed to provide dashboard intelligence, GPT Actions, recommendations, and seller support. The goal is to help the seller understand and act, not to collect unnecessary data or warehouse Amazon operational history.
Live refresh design
Where possible, AmazonIQ retrieves authorized Amazon data when the seller requests a live update. The dashboard is designed to show the current operational picture rather than old cached history.
Restricted customer data
AmazonIQ does not request restricted data roles or customer personally identifiable information for the current product.
Encryption
AmazonIQ uses encrypted transport and is designed to protect sensitive data using appropriate storage and infrastructure controls.
Access controls
Access to production systems and sensitive records is restricted to authorized personnel and service processes.
Incident response
NAVINES will investigate security issues, mitigate risk, and communicate as appropriate based on severity and legal requirements.
Responsible disclosure
Security concerns should be reported through NAVINES contact channels with clear reproduction details.