Security & Data Protection
The technical and organisational controls we apply to protect Amazon Information and customer data in the Ads Metrica service.
Last updated 6 August 2026
1. Our commitment
Ads Metrica processes commercially sensitive information about our customers’ Amazon businesses, and holds the ability to make changes to their advertising accounts. We treat the protection of that information and that capability as a core requirement of the product, not an add-on.
This statement describes our approach to information security. Our programme is designed to meet the requirements of the Amazon Services API Data Protection Policy, the Amazon Services API Acceptable Use Policy, and the Amazon Ads API Data Protection Policy, and we align our controls to those requirements as the service develops.
2. Data in scope
The measures below apply to “Amazon Information” — data obtained from the Amazon Advertising API and the Amazon Selling Partner API — and to customer account and configuration data.
We do not process Amazon buyer personally identifiable information. Ads Metrica does not request, receive, store or process buyer names, addresses, contact details or payment information. We hold no Selling Partner API restricted roles, and the service is designed so that none are required.
3. Governance
- A named member of management is accountable for information security.
- We maintain written information security, acceptable use, access control and incident response policies, and review them periodically and after any material change to the service.
- Risks to Amazon Information are assessed and tracked to remediation with assigned owners.
- Changes to production systems are reviewed before release.
4. Access control
- Access to Amazon Information is granted on a least-privilege, need-to-know basis, according to the individual’s job duties. Personnel are not given standing access to data they do not require.
- Access is via named individual accounts. Shared or generic logins are not used for production access.
- Multi-factor authentication is required for accounts with access to production systems, source control and cloud infrastructure.
- We enforce strong password requirements for personnel and system accounts, and require periodic rotation.
- Access rights are reviewed periodically and revoked promptly when a person leaves or changes role.
- Customer data is logically segregated per account. Application authorisation checks prevent any customer from accessing another customer’s data, and agency users are scoped to the client accounts they are assigned.
5. Network security
- Production systems run in a segmented cloud environment, with only required ports and protocols exposed.
- Public endpoints sit behind managed web application firewall and DDoS protection, with rate limiting and bot mitigation.
- Databases and internal services are not exposed to the public internet and are reachable only from within the private network.
- Intrusion detection and anti-malware capabilities are provided by our infrastructure platforms and monitored for alerts.
- Administrative interfaces require authenticated, MFA-protected sessions.
6. Encryption
- In transit: all traffic to and from the service — browser to application, and application to Amazon’s APIs — is encrypted using TLS 1.2 or higher. HTTP requests are redirected to HTTPS. Amazon Information is not transmitted in plaintext.
- At rest: databases, object storage and backups are encrypted at rest using industry-standard algorithms provided by our infrastructure platforms.
- Secrets: API credentials and OAuth refresh tokens are encrypted at rest, with keys managed separately from the application database.
7. Credential management
- Credentials, encryption keys and secret access keys are held in a managed secrets store with access restricted by role.
- Credentials are not hard-coded into applications, committed to source control, or stored in public repositories. We use tooling to detect credentials accidentally introduced into source control.
- Credentials are not shared between individuals or transmitted over email or chat.
- Login with Amazon client secrets and API credentials are rotated on a defined schedule and upon any suspected exposure or relevant personnel change.
- Customer OAuth refresh tokens are stored encrypted, are not written to logs, and are not displayed in the user interface.
8. Secure development
- Source control requires authenticated access with MFA. Changes are reviewed before merge.
- Automated dependency and vulnerability scanning is in place; findings are triaged by severity and remediated on a risk-prioritised basis.
- Development and test environments are separate from production and are not populated with live Amazon Information.
- Least-privilege principles are applied to service accounts and API scopes; we request only the Amazon roles and scopes the service requires.
9. Logging and monitoring
- Application, access, administrative and API activity is logged centrally with timestamps and actor identity.
- Logs are protected against modification and retained for a defined period appropriate to their purpose. Audit records of changes applied to customer advertising accounts are retained so that actions remain traceable.
- Amazon Information, credentials and tokens are excluded from application logs.
- Alerting is configured for authentication anomalies, permission changes and infrastructure errors.
- Every change Ads Metrica applies to a customer’s advertising account is recorded with the prior value, the authorising user or rule, and the time — and is reversible.
10. Incident response
We maintain a documented incident response plan with defined roles and responsibilities, covering monitoring, detection, triage, containment, eradication, recovery and post-incident review. The plan is reviewed periodically.
Amazon notification. In the event of a Security Incident involving Amazon Information, we will notify Amazon at security@amazon.com without undue delay and within the timeframe required by Amazon’s Data Protection Policy, and will cooperate with Amazon’s investigation, including providing a root cause analysis and remediation plan.
- Affected customers are notified without undue delay, with the facts known, the impact, and the steps being taken.
- Regulatory notifications are made where required by applicable law.
- Incidents are followed by a documented root cause analysis and tracked corrective actions.
11. Backup and resilience
- Encrypted, automated backups are taken on a regular schedule.
- Backups are access-controlled to the same standard as production data.
- Infrastructure is provisioned so that the service can be rebuilt from configuration in the event of failure.
12. Retention and secure disposal
- Amazon Information is retained only as long as required to provide the service and to meet the retention requirements set out in Amazon’s Data Protection Policy.
- On revocation of authorisation or termination of a subscription, associated Amazon Information is deleted within the period required by Amazon’s Data Protection Policy, except where retention is required by law.
- Deletion requests may be made at any time to amazon@adsmetrica.com.
- Storage is securely wiped or cryptographically erased on decommissioning.
13. Vendor and sub-processor management
- Sub-processors are assessed before engagement and are bound by written agreements requiring appropriate technical and organisational measures.
- Sub-processors are limited to processing on our documented instructions and are prohibited from using Amazon Information for their own purposes.
- The current sub-processor list is published in our Privacy Policy. Customers are given advance notice of additions that would have access to Amazon Information.
- We do not transfer Amazon Information to any third party for that party’s own use, and we do not sell, license or syndicate it. Where a customer configures delivery of their own reports to their own workspace — such as their Slack instance — that transfer occurs at the customer’s instruction, into an environment the customer controls, and can be disabled by the customer at any time.
14. Personnel
- Personnel with access to Amazon Information are bound by written confidentiality obligations.
- Security awareness expectations are communicated at onboarding and reinforced periodically, covering phishing, credential handling, data classification and incident reporting.
- Access is revoked promptly on termination as part of our offboarding process.
- Devices used to access production require full-disk encryption and automatic screen lock.
15. Reporting a security issue
If you believe you have found a vulnerability in the Ads Metrica service, please tell us. Email amazon@adsmetrica.com with the subject line “Security” and include enough detail to reproduce the issue.
We acknowledge reports promptly and will keep you informed as we investigate. We ask that you allow us a reasonable period to remediate before public disclosure, and that testing does not involve accessing other customers’ data, degrading the service, or any denial-of-service activity. We will not pursue legal action against researchers who report in good faith and follow these guidelines.
Pop Art Global LLC — Security415 Peachtree Parkway, Suite 250 PMB 1120
Cumming, GA 30041, United States
Email: amazon@adsmetrica.com
Telephone: +1 862 340 9649