Security

Tenant-bound evidence and controlled Amazon access

AdsPilot is designed to minimize implicit trust. Connections, observations and decisions remain scoped to the relevant account and marketplace, while supported external actions require an explicit capability and approval path.

OAuth authorization

AdsPilot uses revocable authorization flows instead of asking sellers to share Amazon passwords.

Tenant isolation

Advertising evidence is bound to account, connected account, seller, advertising profile and marketplace where applicable.

Credential protection

Stored connection credentials are encrypted at rest and are not exposed in public content or diagnostic output.

Evidence history

Material observations and decisions retain source, time and scope provenance so a later result can be traced.

Fail-closed decisions

Missing scope, stale sources, conflicting evidence or incomplete data can block action readiness.

Approval boundaries

Amazon Ads, listing, shipment, budget and price mutations are separated from read-only analysis and require the applicable authorization.

Responsible disclosure

If you believe you found a security issue, use the contact channel and avoid including credentials, access tokens or customer data in the initial message.