Home About Services Case Studies Reviews Contact
Services
Amazon Account Management Amazon PPC Management Amazon FBA Management Listing Optimization & SEO Seller Central Support Amazon Creative Design Book a Free Audit

Security, risk management & data protection

How Mudassir Raza protects Amazon Information: the network controls that restrict public access, the risk assessment process and incident response plan, how credentials and data are handled, and the commitment to notify Amazon of organisational changes within 30 days.

Document: Information Security & Data Protection Policy Version: 1.0 Last reviewed: 2 September 2026 Owner: Mudassir Raza Review cycle: Annual, or on material change

01Scope and purpose

This document sets out the information security, risk management and data protection practices of Mudassir Raza (“the Provider”) as they apply to services delivered to Amazon Selling Partners and to any Amazon Information accessed in the course of those services.

“Amazon Information” means any data obtained from Amazon systems or from a Selling Partner’s Seller Central or Advertising account, including order data, performance reports, business reports and any Personally Identifiable Information (PII) contained within them.

This policy applies to all personnel, devices, systems and networks used to deliver services. It is reviewed at least annually and after any material change to the business, its systems or its services.

02Governance and responsibility

Mudassir Raza is a small provider in which the owner is directly accountable for information security. There is no delegated security function; responsibility is not diffused.

  • Security Owner and Incident Response Lead: Mudassir Raza — reachable at Mudassirraza172134@gmail.com and +44 7723 823962.
  • Approves all access requests to Selling Partner accounts and maintains the record of what access is held, by whom, and why.
  • Maintains the risk register, the incident log and the asset inventory.
  • Reviews this policy annually, and immediately following any security incident or material organisational change.

03Network protection controls

The Provider operates no publicly accessible servers, no inbound network services and no self-hosted infrastructure that processes or stores Amazon Information. All work is performed through Amazon’s own web interfaces over encrypted connections. Public access to the Provider’s systems is therefore restricted by the following controls:

Perimeter and inbound access

  • No inbound ports are open to the internet on any Provider device or network. There is no remote desktop, SSH, FTP or VPN listener exposed publicly.
  • Host-based firewalls are enabled and enforced on every endpoint, configured to deny inbound connections by default.
  • The office router uses WPA2/WPA3 encryption, default administrative credentials have been changed, remote administration from the WAN is disabled, and firmware is kept current.
  • Guest and untrusted devices are isolated on a separate network segment with no route to working devices.

Endpoint and connection security

  • Amazon Information is accessed only from Provider-managed devices. Shared, public or client-owned machines are never used.
  • Full-disk encryption is enabled on all devices used for client work.
  • Reputable anti-malware with real-time protection and automatic updates runs on every endpoint; operating systems and browsers are patched on a current-release basis.
  • All connections to Seller Central, the Advertising Console and email are over HTTPS/TLS 1.2 or higher.
  • Public or untrusted Wi-Fi is not used for client work. Where a non-Provider network is unavoidable, the connection is tunnelled through a reputable commercial VPN before any account is accessed.
  • Devices lock automatically after a short idle period and require authentication to resume.

Public-facing web presence

  • This website is a static site. It runs no database, no server-side application, no login area and no user accounts.
  • No Amazon Information, Selling Partner data or PII is stored on, processed by, or accessible from the web server.
  • HTTPS is enforced for all traffic, with HTTP requests redirected to HTTPS.
  • Hosting control-panel access is protected by a unique strong password and multi-factor authentication.

04Access control and credential management

Access to Selling Partner accounts is granted by the Selling Partner, held at the minimum level required, and revoked when it is no longer needed.

  • Least privilege. Only the specific Seller Central permissions required to deliver the agreed service are requested. Administrator-level access is not requested unless the service genuinely requires it.
  • Named user accounts. Access is obtained through the Selling Partner’s own user-invitation process, creating a named account that the partner can audit and revoke at any time.
  • No shared or transferred credentials. The Provider does not ask for, accept, store or use a Selling Partner’s own username and password. Credentials are never shared between people, sent by email or messaging, or recorded in documents or spreadsheets.
  • Multi-factor authentication is enabled on all Provider accounts that can reach Amazon Information, including Seller Central access, email and the password manager.
  • Password standards. Passwords are unique per service, generated at a minimum of 16 characters, and stored only in an encrypted password manager.
  • Revocation. Access is removed within 24 hours of an engagement ending or of any personnel change. The Selling Partner is asked to confirm removal from their side.
  • Access review. The record of which accounts the Provider can reach is reviewed monthly, and any access no longer required is relinquished.

05Data protection, retention and deletion

The Provider works inside Selling Partner accounts rather than extracting data from them. Amazon Information is downloaded only where a task cannot be completed within the Amazon interface.

  • Minimisation. Only the data required for the specific task is accessed. Reports containing PII (such as buyer names or addresses) are not downloaded unless the task requires it, and are avoided wherever an alternative exists.
  • Encryption. Amazon Information at rest is held on full-disk-encrypted devices. Data in transit is protected by TLS 1.2 or higher.
  • No commingling. Each Selling Partner’s data is stored separately. Data from one partner is never used to inform, benchmark or benefit another.
  • No secondary use. Amazon Information is used solely to deliver the agreed service. It is never sold, licensed, shared, published, or used for marketing, model training or any other purpose.
  • No onward transfer. Amazon Information is not transferred to third parties. No third-party tool is granted access to a Selling Partner’s account without that partner’s written approval.
  • Retention. Amazon Information is retained only as long as needed to perform the task for which it was obtained. Any PII is deleted within 30 days of the task completing, and all Amazon Information is deleted within 30 days of the engagement ending, unless retention is required by law.
  • Deletion. Deletion is permanent: files are removed from local storage, cloud storage and the recycle bin or trash, and email containing Amazon Information is deleted from both mailbox and trash.
  • Removable media. Amazon Information is never copied to USB drives or other removable media.
  • Secure disposal. Devices that have held Amazon Information are securely wiped, or their encryption keys destroyed, before disposal, sale or transfer.

06Risk assessment process

The Provider operates a documented risk assessment process. It is performed at least annually, and additionally whenever a new service, tool, device or category of data is introduced, or following any security incident.

  1. Identify assets. Maintain an inventory of devices, accounts, tools and data stores that can reach Amazon Information.
  2. Identify threats and vulnerabilities. For each asset, record credible threats — credential compromise, phishing, device loss or theft, malware, unauthorised access, accidental disclosure, third-party tool compromise, service outage.
  3. Assess. Score each risk for likelihood and for impact on the confidentiality, integrity and availability of Amazon Information, producing a combined rating of low, medium or high.
  4. Treat. Decide for each risk whether to mitigate, avoid, transfer or accept, and record the specific control applied. High-rated risks must have a mitigation and cannot simply be accepted.
  5. Assign and schedule. Record an owner and a target date for every outstanding action in the risk register.
  6. Review. Re-examine the register at each annual assessment and after each incident, verifying that controls remain effective and closing actions that are complete.

The risk register is retained as a written record and is available for review on request.

07Incident response plan

The Provider maintains an incident response plan covering monitoring, detection and response for potential threats and security incidents affecting Amazon Information. The Incident Response Lead is Mudassir Raza.

Monitoring and detection

  • Sign-in and security alerts are enabled on email, Seller Central and the password manager, and are reviewed as they arrive.
  • Anti-malware runs in real time and reports detections immediately.
  • Amazon account activity, user permission lists and login history are reviewed at least monthly for entries that were not expected.
  • Notifications from Amazon regarding account health, security or policy are treated as potential incident indicators and triaged on receipt.
  • Any report from a Selling Partner of unexpected account activity is treated as a suspected incident until shown otherwise.

Response procedure

  1. Detect and record. Log the date and time of detection, what was observed, which systems and which Selling Partners may be affected. The incident log is opened immediately, before remediation begins.
  2. Triage and classify. Determine within 4 hours whether Amazon Information was, or may have been, exposed, and classify severity as low, medium or high.
  3. Contain. Isolate the affected device or account, revoke or rotate the credentials involved, terminate active sessions, and suspend access to affected Selling Partner accounts.
  4. Notify. Notify Amazon within 24 hours of confirming a security incident involving Amazon Information, through the Solution Provider Portal or the applicable Amazon security contact. Affected Selling Partners are notified within the same 24-hour period, with the facts known at that time.
  5. Eradicate. Remove the cause — malware removal or device rebuild, closure of the access path, correction of the misconfiguration that permitted it.
  6. Recover. Restore normal operation from known-good state, re-issue credentials, and confirm with the Selling Partner that access and data are correct.
  7. Review. Complete a written root cause analysis within 5 business days of closure, recording what happened, why, what was done, and which controls will change. Update the risk register and this policy accordingly.

Testing and records

  • The plan is tested at least annually by walking through a realistic scenario — typically credential compromise or device loss — and confirming each step is achievable within its stated timeframe.
  • A record of every incident, including those found to be false alarms, is retained with its classification, timeline, actions and outcome.
  • Contact details for Amazon, affected Selling Partners and the hosting provider are kept current and accessible offline so that they remain available during an incident.

08Notification of organisational changes

Mudassir Raza will notify Amazon within 30 days of any organisational change or event that alters the organisation’s need for, or use of, Amazon Information. Notification is made through the Solution Provider Portal.

Changes that trigger this obligation include, but are not limited to:

  • A change in ownership or control of the business, including merger, acquisition or sale of assets.
  • A change in legal entity, registered business name, registered address or primary contact details.
  • A change in the services offered that alters which Amazon Information is required, or the roles needed to access it.
  • Ceasing to provide services to Amazon Selling Partners, or no longer requiring a previously approved role.
  • A change in the personnel who have access to Amazon Information, including new joiners and leavers.
  • Engagement or removal of a subcontractor or third-party processor that would handle Amazon Information.
  • A material change to the systems, tools or infrastructure used to access or store Amazon Information.
  • A change to the data protection or security practices described in this policy.

Responsibility for making the notification sits with the Security Owner named in section 2. The obligation is reviewed quarterly to confirm that no notifiable change has gone unreported, in addition to being triggered by events as they occur.

09Personnel and third parties

Personnel

Services are delivered personally by Mudassir Raza as a sole operator. No other individual currently holds access to Selling Partner accounts or to Amazon Information.

  • Access to Amazon Information is held by one named person, which removes the risk of shared or inherited credentials.
  • Should anyone else be engaged in future, access will be granted only after a written confidentiality agreement is in place and only at the level required for their role, and Amazon will be notified within 30 days as set out in section 08.

Subcontractors and third-party tools

  • No subcontractors are currently engaged. Amazon Information would not be disclosed to any subcontractor without the Selling Partner’s prior written approval and an equivalent written confidentiality and security commitment from that subcontractor.
  • Third-party software is granted account access only with the Selling Partner’s written approval, at the minimum permission level required, and is removed when no longer needed.
  • Amazon is notified within 30 days where the engagement of a subcontractor changes how Amazon Information is used, as set out in section 8.

10Availability and business continuity

  • Working files, records and documentation are backed up to encrypted storage, so that a lost or failed device does not interrupt service.
  • Backups exclude Selling Partner PII wherever possible; where PII is unavoidably present, it is subject to the same retention and deletion rules set out in section 5.
  • Restoration from backup is verified periodically rather than assumed.
  • Where an outage or incident is expected to interrupt service, affected Selling Partners are informed promptly with an expected time to resume.

11Policy maintenance

This policy is version-controlled and reviewed at least annually. It is also reviewed and updated immediately following any security incident, any material change to the Provider’s systems or services, and any change to Amazon’s Data Protection Policy or Acceptable Use Policy.

Questions about this policy, requests for further detail, or reports of a suspected security issue should be sent to Mudassirraza172134@gmail.com or +44 7723 823962. Suspected security issues are acknowledged within 24 hours.