Last updated: [DATE — fill in before launch]
Every connection to AutoPlusLab, whether from your browser or between our own systems, is encrypted in transit using HTTPS/TLS. Your Amazon account authorization token is additionally encrypted at rest in our database — it is never stored as plain text.
Access to production systems and customer data is limited to the engineers actively working on AutoPlusLab. Our internal admin tools require a separate, dedicated login with two-factor authentication — it is entirely separate from the customer-facing product and is never used to access individual customer accounts without cause.
When you disconnect your Amazon account or delete your AutoPlusLab account, your authorization token and associated order data are permanently and irreversibly deleted within 30 days.
We maintain an internal incident response process. In the event of a confirmed security incident affecting customer data, we commit to notifying affected customers and Amazon within 24 hours of confirmation, and to patching any critical vulnerability within 7 days of discovery.
We rely on established, reputable infrastructure providers to host and run AutoPlusLab (for hosting, database, and payment processing). Each of these providers maintains its own independent security certifications; we do not build our own data centers or payment processing systems.
If you believe you've found a security issue with AutoPlusLab, please report it to security@autopluslab.com — we take every report seriously and will respond promptly.