Security posture
Munchello Commerce Control operates as an invitation-only private beta. The public information website does not accept Amazon credentials or connect accounts. Each production authorization is activated only after the applicable identity, authorization, encryption, tenant-isolation, logging, incident-response, and recovery controls pass technical validation.
Please do not send passwords, Amazon tokens, API secrets, one-time codes, buyer personal information, or exploit details through ordinary chat or public forms.
Production control requirements
- Separate Amazon authorization grants and encrypted data boundaries for each legal-entity account.
- Encryption in transit and at rest, with secrets stored outside source code and ordinary agent context.
- Least-privilege roles, owner MFA, short-lived agent credentials, and separate read/propose versus approve/execute authority.
- Deterministic budget, portfolio, freshness, profitability, and ownership gates before any approved advertising write.
- Tamper-evident audit evidence for proposals, approvals, executions, verification, and rollback.
- Backups, restoration testing, vulnerability review, dependency scanning, and a documented incident-response process.
These controls are mandatory gates for every connected production account.
Report a vulnerability or incident
Email amazon-api@munchellollc.com with the subject “Security Report.” Include a concise description, affected URL or component, reproduction steps, and potential impact. Do not access, alter, download, or retain data that is not yours; disrupt service; use social engineering; or publicly disclose an unresolved issue.
Response process
Munchello will acknowledge a good-faith security report as soon as reasonably practical, triage its severity, preserve relevant evidence, restrict access where necessary, and communicate material updates to affected authorized administrators. If an incident involving regulated or Amazon data occurs, Munchello will follow applicable notification duties and Amazon’s incident-reporting requirements.
Safe-harbor intent
Good-faith research that follows this page, avoids privacy harm and service disruption, and gives Munchello reasonable time to remediate will be treated as authorized to the extent Munchello can authorize it. This statement does not authorize testing of Amazon or any third party.