Security
Last updated October 4, 2026
SellerHQ is a service of The Goven House Inc. If you think you've found a security vulnerability, a privacy problem, or misuse of data connected to SellerHQ, including Amazon data, please tell us. Anyone can report: clients, researchers, Amazon, or the public.
Report a problem
Email security@sellerhq.com and include:
- What you found, and where: a web address, system or account
- Steps to reproduce it, or the evidence of misuse
- When you noticed it
- How to reach you
Please don't paste working passwords, keys or other people's personal data into the email. Describe them, and we'll arrange a safe way to share them.
What happens next
- Acknowledgement. We reply within two business days and give your report a reference number.
- Containment. We treat suspected misuse of Amazon data or credentials as urgent: we revoke or rotate the affected credentials first and investigate after.
- Tracking. Every report is logged with when it arrived, what we found, what we did, and how it was resolved. It stays open until it's resolved.
- Updates. If a fix takes longer than a week, we update you at least weekly. We tell you the outcome when it's resolved.
- Notification. We notify affected clients without delay. We report incidents involving Amazon data to Amazon within 24 hours of discovering them, as Amazon's data protection policies require.
Good-faith research
We won't take legal action against good-faith security research that follows these rules:
- Test only against this website.
- Don't access, change or keep data that isn't yours.
- Don't disrupt the service.
- Give us reasonable time to fix the problem before you make it public.
We don't run a paid bug bounty.
How we protect client data
- Your data stays in your accounts. The warehouse is in your own Google Cloud project, and the software runs on a server in your own account. We don't hold your business data on our systems.
- Read-only, lowest permission. We use a view-only Seller Central user, read-only Selling Partner API roles, and the lowest Amazon Ads permission that does the job.
- Separate credentials for every client. One client's credentials are never used on another client's system.
- Credentials are encrypted. They're kept in a password manager and in encrypted files, and decrypted only to deploy to your server. We never accept or send them by email or chat.
- Multi-factor authentication on every account with access to client systems.
- Encrypted connections. Data moves over HTTPS between Amazon, Google and your server, and Google Cloud encrypts it at rest.
- Access ends with the engagement. We remove our access within five business days of an engagement ending.
What data we access and why is covered on our Privacy page.
Contact
The Goven House Inc., operator of SellerHQ
Security reports: security@sellerhq.com
Everything else: ramon@sellerhq.com