Security

A narrow, read-only product boundary.

Catalog Guard is built to analyse product requirements and catalogue data without making marketplace changes. These are the safeguards currently built into the product.

Read-only Amazon design

Catalog Guard is designed for Product Type Definitions and Listings Items read operations. Listing, feed, price, inventory, and offer changes are not implemented.

Credentials stay on the backend

Amazon client secrets and refresh tokens are handled by the backend. The browser receives connection status, never the secret values.

File validation

Uploads have size limits and are parsed as data. Executable content is not run, and remote references in requirement files are rejected.

Safer spreadsheet exports

Text that could be interpreted as a spreadsheet formula is escaped before CSV and XLSX export to reduce formula-injection risk.

Redacted diagnostics

Authentication, access, throttling, malformed-response, and service errors are translated into useful messages without exposing credential values.

Deterministic evidence

Each catalogue is checked against the same defined rules. Review notes stay separate from the original finding so the evidence remains traceable.

Scope of these claims

This page does not claim SOC 2, ISO 27001, penetration testing, an independent security audit, or guaranteed security. Catalog Guard is in private beta, and access or availability may be limited while operational controls continue to mature.

Report a security issue

Contact and use “Security report” in the subject. Do not send credentials, passwords, or sensitive seller data in the first message.