DigitEMB AMZSELLER WORKSPACE
SECURITY AND DATA

How we protect
your data.

This page says what is in place today and, just as plainly, what we are finishing before any Amazon account is connected. The current pilot uses sample data and holds no Amazon data and no Amazon access tokens.

IN PLACE TODAY

What protects the pilot right now.

Encrypted connections In place

Every connection uses TLS 1.2 or newer with strict transport security. Traffic passes a managed web proxy, and the server refuses requests that do not come through it.

Locked-down servers In place

A host firewall is active, the database accepts local connections only, and password login to the servers is disabled: access is by SSH key only.

Limited access In place

Server access is limited to the DigitEMB owner and the engineering team he authorises. Secrets files are readable by the system administrator only and are never written to logs.

Invite-only sign-in, no passwords In place

Each sign-in uses a one-time six-digit code sent to your e-mail. It works for 10 minutes, allows five tries, and you can ask for five codes an hour. Codes and invitation links are stored only as hashed values.

Protected sessions In place

Session cookies are HttpOnly and Secure and expire after 14 days. Actions inside your workspace are protected against cross-site request forgery, and pages send strict security headers.

Its own database In place

The service has its own database and database login, separate from DigitEMB's other systems, and runs under a restricted account with limits on memory and processes.

Backups In place

Nightly database backups are kept for 14 days, and we have tested restoring one.

Updates and monitoring In place

Automatic operating-system security updates are enabled and applied. Repeated failed logins are blocked at the host, and web access and sign-in activity are logged.

No buyer personal data In place

We do not ask Amazon for buyer names, addresses or e-mail addresses.

You stay in control In place

Your data stays in your own workspace, is never combined with another seller's and is never sold. It is deleted when you ask, within the periods in our privacy policy.

WHERE DATA LIVES

Hosting and the companies that handle it.

WhatWhere and who
Servers and databaseHosted by DigitEMB's cloud provider, DigitalOcean, in Bangalore, India
Web trafficPasses Cloudflare before reaching the servers
E-mail delivery (sign-in codes, invitations)Amazon Web Services e-mail service
Fonts on public pagesGoogle Fonts, which receives a browser request when the fonts load

If the servers move to another region or provider, this page and the privacy policy are updated first.

BEFORE ACCOUNTS CONNECT

What we are finishing first.

The pilot holds no Amazon data and no access tokens, so these items are not needed for it. They are what we are completing before account connections are introduced.

  • Before connectingEncrypted Amazon tokens. Every access token will be encrypted inside the application with a separate key, and kept out of logs and browser output.
  • Before connectingEncrypted storage. The database will sit on encrypted storage. It does not today.
  • Before connectingA written incident response plan, reviewed and signed by the owner.
  • Before connectingScheduled vulnerability checks of the software the service uses.
  • Before connectingAutomatic deletion. Today our team carries out deletions on request. A job will do it on schedule.
  • Before connectingA visible record of any access by our staff to a seller's workspace.

The planned Amazon connections must meet Amazon's Acceptable Use Policy and Data Protection Policy and receive Amazon's approval before they are offered.

REPORT A CONCERN

Found something? Tell us.

Write to support@digitemb.com with the word "Security" in the subject. Describe what you saw and where. Please do not access other people's data while checking, and give us a reasonable time to fix a problem before you share it. We answer on working days, Monday to Friday.