We cannot read a seller Amazon token on our own.
The decryption key is the x-amazon-token-secret your systems send with each request. It is never stored alongside the ciphertext.
Security · control register
Not a posture statement. These are the limits enforced in code, the layers a request passes through, and the encryption each artefact sits behind — the same list we hand to a reviewer.
Access
Every limit here is structural. An attacker holding your tokens still gets one address per order per hour, and nothing at all from a shipped order.
Custody
Missing or mismatched at any layer and the request stops there. Three of the four live in your systems; the fourth is the order's own state.
01
x-adb-access-token
tenant identity, exchanged from a rotatable refresh token
02
x-seller-access-token
which seller account this request may touch
03
x-amazon-token-secret
the key that decrypts that seller refresh token — never stored here
04
(server side)
whether this specific order is still readable at all
Encryption
At rest
In transit
By design
Platform
Data Border runs on infrastructure independently audited against SOC 2 Type II controls, on a provider that supports HIPAA workloads and signs BAAs.
Vulnerability remediation
Dependency scanning and security monitoring run continuously, not at release time.
Boundaries
Stated as limits rather than promises, because a limit is the part a reviewer can test.
The decryption key is the x-amazon-token-secret your systems send with each request. It is never stored alongside the ciphertext.
Scrubbing runs on the response path, not as an option flag. Placeholders resolve inbound; the outbound body comes back [REDACTED].
One read per order per hour, and completed or blocked orders return 403 permanently. There is no batch endpoint to abuse.
If they want the underlying detail, the encryption, token and rate limiting references are public. If they want a questionnaire filled in, that is what the plan pays for.