Security

How we protect the data we handle, in particular Amazon buyer personal information obtained through the Amazon Selling Partner API.

Infrastructure and encryption

  • 1stsend runs on Amazon Web Services in the Asia Pacific (Tokyo) region.
  • Data at rest, including backups, is encrypted using AES-256. Encryption keys are generated, stored and rotated in AWS Key Management Service: customer-managed keys are rotated automatically every 365 days and application-level secrets every 90 days.
  • Keys are never stored alongside the data they protect.
  • All data in transit is encrypted using TLS 1.2 or above, and our websites are served over HTTPS only.

Access control

  • Access to Amazon Information is limited to authorised personnel of Ecommerce Transhipment Solution Ltd and of Britannica Creations Limited, which develops and operates the 1stsend platform, all located in the United Kingdom.
  • Access is granted on a least-privilege basis according to job role, and is reviewed when roles change or staff leave.
  • Multi-factor authentication is required for all access.
  • Every access is individually attributable to a named user and fully audit-logged.

Credential protection

  • Amazon Selling Partner API credentials and access tokens are encrypted with keys held in AWS Key Management Service.
  • Credentials are never stored in source code, never exposed to the browser, and never written to logs.
  • Application-level secrets are rotated every 90 days.
  • Automated secret scanning in our code repositories and build pipeline blocks any change containing credentials, and credentials are rotated immediately if exposure is suspected.

Logging and monitoring

  • Security and access events are recorded in centralised audit logs.
  • Personally Identifiable Information is masked or redacted before log ingestion and is never written to application logs.

Vulnerability management

  • Static code analysis and dependency scanning run automatically on every code change, and releases are blocked on high or critical findings.
  • Infrastructure and application vulnerability scans run every 30 days, and an independent penetration test is carried out every year.
  • Findings are tracked to closure with a named owner: critical issues are remediated within 7 days, high within 30 days and medium within 90 days.

Data minimisation and deletion

  • We only retrieve the Amazon data needed to ship an order.
  • Amazon buyer Personally Identifiable Information is permanently deleted within 30 days of order delivery. Deletion is automated and covers primary databases, replicas and encrypted backups.

Incident response

  • We maintain a documented incident response process covering detection, containment, investigation and recovery.
  • Security incidents involving Amazon Information are reported to Amazon within 24 hours of detection, and affected customers are notified without undue delay.

Reporting a security issue

If you believe you have found a security vulnerability, please email admin@1stsend.com.

See also our Privacy Policy.