Vendooly
// Security and data protection

Authorized access. Isolated tenants. Human-controlled writes.

Vendooly is designed to give an AI assistant only the Amazon tools and context needed for the requested operation. Amazon authorization, stored tokens, tenant boundaries and write approvals remain outside the model.

AuthorizationSeller API and Ads API access is granted through Amazon OAuth scopes.
IsolationOrg, user, seller account and marketplace context are validated for each operation.
Write controlA proposed change waits for explicit human confirmation.
Audit trail for operational actions
Core controls

Security boundaries that match the operating flow.

OAuth authorization

Amazon access is granted through the relevant OAuth flow and scopes. Users do not paste Seller Central passwords or raw credentials into ChatGPT or Claude.

Encrypted tokens

Amazon refresh tokens are encrypted at rest and are handled by the connector layer, not inserted into prompts or returned to the browser.

Tenant isolation

Every request is checked against the authorized org, user, seller account and marketplace so that one tenant cannot select another tenant’s context.

Data minimization

Tools return the operating context required for the requested task. Vendooly does not treat a full seller-account export as the default model context.

Human approval

Writes to listings, prices, feeds, bids, budgets or campaigns require an explicit confirmation. Vendooly is not presented as an unattended autopilot.

Logging and review

Operational and administrative actions are logged so activity can be reviewed. Sensitive customer data is not used as public proof without documented consent.

Data flow

The AI provider and the Amazon connector stay separate.

The assistant requests a defined tool. Vendooly validates authorization, calls the relevant Amazon API and returns the minimum result needed. Amazon tokens remain in the connector environment.

01

User and org session

The user signs in and operates within an org. Access to seller accounts is checked on the server.

02

Scoped Amazon request

The connector resolves the authorized seller account, marketplace and API region before making a request.

03

Minimal response or proposal

The assistant receives the tool result. If a write is proposed, the responsible user reviews the exact scope before confirmation.

Customer responsibilities

Safe use is shared.

Grant only needed scopes

Connect the Seller API and Ads API capabilities required for the workflow and review access when responsibilities change.

Review proposed changes

Check the seller account, marketplace, affected records and operating constraints before approving a write.

Report access changes

Remove users who no longer need access and contact support promptly if you suspect an authorization issue.

Security questions and responsible disclosure: security@vendooly.com. Privacy and processing terms are maintained in the Privacy Policy and Data Processing Agreement.

Evaluate the controls before connecting Amazon.

Review the authorization model, tenant boundary and write-confirmation flow, then start with one bounded operating question.

See the MCP flow