Skip to content

Security

How we protect your data and account

Last updated: August 23, 2026

Authentication

We use secure authentication methods:

  • Supabase Auth for secure login
  • Email/password authentication
  • Session management with secure tokens
  • No Amazon password required

Data Protection

Your data is protected by:

  • Row Level Security (RLS) for data isolation
  • Every record is scoped to the authorized business workspace
  • Encrypted OAuth token storage
  • No secrets stored in frontend code

Amazon Connection Security

The Amazon SP-API integration uses:

  • Login with Amazon (LWA) credentials and refresh-token authorization
  • We never ask for your Amazon password
  • LWA secrets and refresh tokens encrypted and stored securely
  • Only business reports needed for the accounting features are processed

Infrastructure Security

Our infrastructure is secured by:

  • Vercel for secure hosting
  • Supabase for database with RLS
  • HTTPS/TLS encryption in transit
  • Automated release checks and security event logging

Operational Security Controls

Controls applied to the website and Amazon-connected workflows:

  • Authenticated sessions end after 15 minutes of inactivity, with a warning before they do
  • Ten failed password attempts trigger a 30-minute account lock
  • The production website and public APIs are protected by a web application firewall (WAF)
  • Amazon OAuth credentials are encrypted at rest using authenticated encryption
  • Verified deletion requests are assigned a deadline of no more than 30 days
  • Security checks cover dependencies, application boundaries, and public APIs before release
Read the data deletion process

Security Best Practices

To keep your account secure:

  • Use a strong, unique password
  • Don't share your account credentials
  • Log out from shared devices
  • Report suspicious activity immediately

Report Security Issues

If you discover a security vulnerability, please report it to:

security@zonraseed.com