Security practices
Security
Last updated: July 23, 2026
Peakstar uses focused controls for seller-authorized Amazon access, tenant separation, and the minimum data needed to operate enabled features.
Amazon OAuth
Amazon seller accounts are connected through Amazon OAuth authorization. A future Amazon Ads connection, if approved, will use its separate advertiser authorization flow. Peakstar does not request, receive, or store Seller Central or Amazon Ads login passwords. Sellers and advertisers can revoke authorization through Amazon or contact Peakstar to disconnect it.
Encrypted refresh tokens
Amazon refresh tokens are encrypted before they are written to the application database.
Transport security
Peakstar public web and API traffic is served over HTTPS using TLS. Service-to-service paths are restricted to approved encrypted or private network routes and external provider connections require HTTPS.
Tenant isolation
Amazon connections, synchronized records, projects, assets, and application queries are scoped to the authenticated account owner. Server-side ownership checks are used for tenant-bound reads and writes.
Owner-only production access
Production administration and production Amazon connection controls are restricted to the Peakstar owner in the current release.
Account authentication
Peakstar enforces a minimum 12-character password policy with complexity and common-password checks. TOTP multi-factor authentication, one-time recovery codes, password expiry, session revocation, and rate-limited authentication challenges are supported for protected account access.
Infrastructure monitoring
Peakstar uses host firewalls, login-abuse controls, passive network intrusion detection, operating-system audit logging, isolated service accounts, and restricted administrative access. Detection alerts are reviewed without allowing an IDS rule to make unreviewed production changes.
File malware controls
New user uploads and downloaded provider outputs are checked by an anti-malware scanner before permanent storage. A file is not accepted when the scan reports malware or when a required scan cannot be completed.
Minimum data use
Peakstar requests and processes Amazon data for enabled seller or advertiser features only. Amazon ingestion retains normalized, allowlisted operational or advertising values and excludes raw buyer names, addresses, email addresses, phone numbers, tracking values, and customer comments from persistence and logging.
Generative AI separation
The current release does not send Amazon operational metrics, Brand Analytics metrics, or Amazon Ads performance data to generative AI providers. Explicitly seller-selected product assets and creative prompts may be sent only when the seller starts the related creative task.
Incident response
Peakstar maintains a documented incident-response process with preparation, identification, containment, eradication, recovery, evidence preservation, and lessons-learned stages. Incidents involving Amazon Information are escalated to Amazon within the required notification window. The plan is reviewed at least every six months and after material infrastructure changes.
Security contact
Send security questions or reports to yunus@peakstar.ai. Do not include passwords, refresh tokens, API keys, or full payment-card numbers in a report.