Security
How we protect your data and account
Last updated: August 23, 2026
Authentication
We use secure authentication methods:
- Supabase Auth for secure login
- Email/password authentication
- Session management with secure tokens
- No Amazon password required
Data Protection
Your data is protected by:
- Row Level Security (RLS) for data isolation
- Every record is scoped to the authorized business workspace
- Encrypted OAuth token storage
- No secrets stored in frontend code
Amazon Connection Security
The Amazon SP-API integration uses:
- Login with Amazon (LWA) credentials and refresh-token authorization
- We never ask for your Amazon password
- LWA secrets and refresh tokens encrypted and stored securely
- Only business reports needed for the accounting features are processed
Infrastructure Security
Our infrastructure is secured by:
- Vercel for secure hosting
- Supabase for database with RLS
- HTTPS/TLS encryption in transit
- Automated release checks and security event logging
Operational Security Controls
Controls applied to the website and Amazon-connected workflows:
- Authenticated sessions end after 15 minutes of inactivity, with a warning before they do
- Ten failed password attempts trigger a 30-minute account lock
- The production website and public APIs are protected by a web application firewall (WAF)
- Amazon OAuth credentials are encrypted at rest using authenticated encryption
- Verified deletion requests are assigned a deadline of no more than 30 days
- Security checks cover dependencies, application boundaries, and public APIs before release
Security Best Practices
To keep your account secure:
- Use a strong, unique password
- Don't share your account credentials
- Log out from shared devices
- Report suspicious activity immediately
Report Security Issues
If you discover a security vulnerability, please report it to:
security@zonraseed.com