REGISTRATION_SITE · Amazon authorization is not active. This site documents the intended release scope and policies for developer review.

Control and evidence

No checklist claim without an implementation receipt.

Security is an evidence trail.

The controls below describe the intended live service, not verified production deployment. Current public demos have no customer login, data upload, live API access or advertising writes.

A policy statement is not proof. Each production control must have a configuration, test, review owner, and dated receipt.

Identity and access control

Personal accounts, MFA, least privilege, quarterly review, and prompt offboarding.

Encryption and secrets

TLS, encrypted storage, KMS-bound refresh tokens, and scheduled credential rotation.

Monitoring and incident response

Redacted centralized logging, alerts, review cadence, and a 24-hour Amazon notification path.

Resilience and vendors

Encrypted backups, restore exercises, risk-based vulnerability remediation, and supplier assessment.

Automated-client transparency

Automated Amazon requests identify the agent and never emulate human interaction, bypass verification, or evade access controls.

Security questions: zhaojianhong@zach-hub.com.