Identity and access control
Personal accounts, MFA, least privilege, quarterly review, and prompt offboarding.
Control and evidence
No checklist claim without an implementation receipt.
The controls below describe the intended live service, not verified production deployment. Current public demos have no customer login, data upload, live API access or advertising writes.
A policy statement is not proof. Each production control must have a configuration, test, review owner, and dated receipt.
Personal accounts, MFA, least privilege, quarterly review, and prompt offboarding.
TLS, encrypted storage, KMS-bound refresh tokens, and scheduled credential rotation.
Redacted centralized logging, alerts, review cadence, and a 24-hour Amazon notification path.
Encrypted backups, restore exercises, risk-based vulnerability remediation, and supplier assessment.
Automated Amazon requests identify the agent and never emulate human interaction, bypass verification, or evade access controls.
Security questions: zhaojianhong@zach-hub.com.