Security at Brecx
Last updated: September 2026
Brecx handles marketplace data, including limited buyer information, on behalf of sellers. These are the controls we use to protect it. They follow our internal Information Security, Access Control, Incident Response and Data Retention policies, which are reviewed at least once a year.
Infrastructure and network
- Production runs on managed cloud providers (Render and Neon) built on AWS data centers certified to SOC 2 and ISO 27001, which handle physical security, network segmentation and firewalling.
- Database connections require TLS and authenticated credentials. Credentials are issued only to production services and authorized engineers.
- Production and non-production environments are kept separate, with separate configuration and secrets.
Encryption
- All traffic is encrypted in transit with TLS 1.2 or higher, and HTTPS is enforced with HSTS.
- Data at rest, including databases and backups, is encrypted with AES-256.
- Marketplace refresh tokens, API keys and other secrets are kept in an encrypted secrets store. They are never committed to source code, and are rotated at least every 90 days and right away if a compromise is suspected.
Identity and access control
- Multi-factor authentication is required on every account that can reach marketplace data or production systems: hosting, database, source control, the Amazon Seller/Developer account, email and the domain registrar.
- Password policy: at least 12 characters, unique per system and kept in a password manager, with lockout after repeated failed logins, password history enforcement, and an immediate change on suspected compromise.
- Role-based, least-privilege access (Admin, Engineer, Support), with read-limited Support. Production database access is restricted to Admin and Engineer roles.
- Access to buyer PII is limited to named individuals with a documented business need. Access rights are reviewed at least quarterly and revoked within 24 hours of a role change or departure.
- Marketplace scopes and roles are requested at the least-privilege level each feature needs.
Logging and monitoring
- Access to production systems and data, authentication events and administrative actions are logged centrally.
- Logs are kept for at least 12 months, and access to them is restricted.
- Alerts fire on anomalous activity such as repeated failed logins and error spikes.
Backups and recovery
- The production database has automated, encrypted backups with point-in-time recovery.
- Backups expire on a defined schedule, so data deleted under our retention policy leaves backups on the next cycle.
Secure development and vulnerability management
- All code changes go through GitHub, with branch protection and mandatory review before release.
- Dependencies are scanned automatically (Dependabot and npm audit).
- Vulnerabilities are fixed by severity: critical within 7 days and high within 30 days of discovery.
- Admin devices use disk encryption and screen lock. Marketplace data is never copied to removable or unmanaged media.
Incident response
- A documented incident response plan covers detection, containment, eradication, recovery and review.
- We notify affected marketplaces within 24 hours of detecting a security incident involving their data. For Amazon, that means security@amazon.com. Affected sellers are also notified as required.
- Each incident is documented, and a post-incident review is completed within 5 business days.
Data retention and deletion
- Buyer PII is deleted no later than 30 days after order delivery.
- Other marketplace data is deleted within 18 months, unless the law requires longer.
- When a channel is disconnected or an account is closed, the related data is purged within 30 days, and it can be exported first.
Full details are in our Privacy Policy. For how Amazon data is used, see Amazon integration.
Subprocessors
Every vendor is risk-assessed before it can access marketplace data, and again each year. We never sell or share marketplace data with subprocessors for their own use.
| Subprocessor | Purpose | Notes |
|---|---|---|
| Render | Application hosting | Runs on AWS infrastructure |
| Neon | PostgreSQL database and backups | Runs on AWS infrastructure |
| Resend | Transactional email | Account and notification emails only |
Report a security issue
If you believe you have found a vulnerability or a security incident affecting Brecx, email contact@brecx.com with the details. We acknowledge reports quickly and investigate every one.