Security · control register

Controls, with the settings they actually run at.

Not a posture statement. These are the limits enforced in code, the layers a request passes through, and the encryption each artefact sits behind — the same list we hand to a reviewer.

Access

What stops a compromised integration credential.

Every limit here is structural. An attacker holding your tokens still gets one address per order per hour, and nothing at all from a shipped order.

ControlSettingDenies with
Buyer address read1 per order, per hour429
Read after completeOrder or blockPIIterminal, never reopens403
File operations50 per day, per tenant429
Authorization endpoints5 per 10 seconds, per IP429
Carrier origin7 allow-listed hosts400
Placeholder tokens11 known names, exact match400
General API trafficadaptive, per IP (WAF)429

Custody

Four things must line up before a buyer address moves.

Missing or mismatched at any layer and the request stops there. Three of the four live in your systems; the fourth is the order's own state.

  1. 01

    Data Border access token

    x-adb-access-token

    tenant identity, exchanged from a rotatable refresh token

  2. 02

    Seller access token

    x-seller-access-token

    which seller account this request may touch

  3. 03

    Amazon token secret

    x-amazon-token-secret

    the key that decrypts that seller refresh token — never stored here

  4. 04

    Order state

    (server side)

    whether this specific order is still readable at all

Encryption

Where each artefact sits, and behind what.

At rest

  • Amazon refresh tokens: AES-256-GCM, scrypt key derivation
  • Record layout: version, 32-byte salt, IV, auth tag, ciphertext
  • Volumes: LUKS block encryption (AES-XTS)
  • Object storage: server-side encryption

In transit

  • TLS 1.3 for all external API traffic, no legacy protocols
  • HSTS enforced; certificates issued and renewed automatically
  • WireGuard mesh internally (ChaCha20-Poly1305, Curve25519)
  • Certificate validation on every upstream connection

By design

  • The token secret is supplied per request and never written down
  • Buyer addresses are fetched on demand and never persisted
  • Labels are stored inside the border and streamed to Device Hub
  • Carrier responses are scrubbed before your systems receive them

Platform

Isolation, and how fast holes get closed.

Data Border runs on infrastructure independently audited against SOC 2 Type II controls, on a provider that supports HIPAA workloads and signs BAAs.

ComputeEach instance runs in its own Firecracker micro-VM — hardware isolation, not a shared container runtime.
NetworkDefault deny. Internal services sit on a private IPv6 network with no public exposure and no security groups to misconfigure.
EdgeML-assisted WAF: bot detection, credential stuffing prevention, IP reputation scoring, adaptive rate limits.
UpstreamAutomated and manual DDoS mitigation including blackhole routing and traffic scrubbing before traffic reaches the instance.

Vulnerability remediation

Critical24 hours
High1 week
Medium1 month

Dependency scanning and security monitoring run continuously, not at release time.

Boundaries

Three things this system is unable to do.

Stated as limits rather than promises, because a limit is the part a reviewer can test.

We cannot read a seller Amazon token on our own.

The decryption key is the x-amazon-token-secret your systems send with each request. It is never stored alongside the ciphertext.

The label proxy cannot hand your systems a buyer address.

Scrubbing runs on the response path, not as an option flag. Placeholders resolve inbound; the outbound body comes back [REDACTED].

Nobody can bulk-export addresses through the API.

One read per order per hour, and completed or blocked orders return 403 permanently. There is no batch endpoint to abuse.

Send this page to whoever signs off.

If they want the underlying detail, the encryption, token and rate limiting references are public. If they want a questionnaire filled in, that is what the plan pays for.