ClairInsights

Security center

Protect your Amazon business without giving up control.

Stay in control of who can reach your Amazon data, where it is stored, and who responds when something goes wrong—whether ClairInsights runs in your AWS account or we manage it for you.

Controls and sources reviewed 3 September 2026
A protected data core surrounded by layered green security and privacy boundaries.

A simple security principle

Only the access you approve. Only the data you need. Clear ownership when something goes wrong.

Operating boundary

Choose where control and responsibility sit

Self-hosted keeps the environment under your control. Managed Delivery puts the agreed day-to-day operation with us. In both cases, the contract makes responsibility for incidents, updates, retention, and recovery clear before you start.

Control areaSelf-hostedManaged Delivery
EnvironmentClairInsights runs in your AWS account under your controls.ClairInsights runs the agreed delivery environment for you.
Amazon accessCredentials stay in your environment and remain limited to approved roles.Only the approved accounts and roles are used.
Failures and Amazon changesYour team and ClairInsights share responsibility as agreed.ClairInsights operates the agreed delivery scope.
Retention and deletionYour policies govern data stores and logs.The service agreement defines retention and deletion.

01 / Access

Only approved Amazon information can be reached

You choose the Amazon accounts and roles ClairInsights may use. That approval stays visible and access follows least privilege, so it does not quietly become broader.

Your approved scope stays visible

Seller/Vendor Central account, Amazon Ads profile, marketplace, and role boundaries remain attached to every data delivery.

Each service receives limited access

IAM permissions cover only the queues, buckets, keys, secrets, and functions that service needs.

Credentials are never placed in code

Application and database credentials use AWS Secrets Manager; Amazon refresh tokens are protected with AWS KMS.

02 / Protection

Credentials and stored information stay protected

Encryption at rest and encryption in transit protect sensitive application data and Amazon reports. Credentials stay out of code, and report storage is not public.

Amazon tokens are encrypted

Refresh tokens use dedicated AWS KMS keys with rotation enabled in the infrastructure.

Report storage blocks public access

Report buckets use server-side encryption and block public access. Queues use managed or KMS encryption.

The database stays private

The application database is not publicly accessible, is encrypted at rest, and is reached through private application networking.

03 / Operations

A missing delivery can be found and recovered

A failed Amazon delivery should be visible before it affects a report or decision. ClairInsights shows the missing period, keeps credentials out of logs, and isolates failed work for safe recovery.

Every delivery leaves evidence

Status, covered periods, destination objects, and errors show where a delivery is missing.

Logs are not kept indefinitely

Deployed modules give log groups and queue messages explicit retention periods.

Repeated failures are isolated

Encrypted dead-letter queues hold repeatedly failing work for investigation and controlled recovery.

04 / Change

Amazon changes do not become invisible data gaps

When Amazon changes a report, ClairInsights helps you find the affected periods and correct them. Original deliveries remain available for recovery instead of leaving a silent gap in the business view.

New fields do not stop the full delivery

Added fields can continue into source storage while invalid data is isolated before business use.

Original deliveries support recovery

Preserved source files allow corrections and rebuilds without unnecessary requests back to Amazon.

Someone is clearly accountable

The selected contract defines who monitors, applies releases, responds to incidents, and recovers affected periods.

Data-minimal analytics

We measure the website journey—not your inquiry

Website analytics use selected anonymous events with memory-only persistence. We do not enable autocapture, cookies, person profiles, session recording, heatmaps, surveys, or automatic exception capture.

Evidence

The guidance behind these protections

The controls above are checked against current Amazon and AWS guidance. ClairInsights does not claim Amazon certification, and your security team should still review the deployed environment and agreement.

  1. SP-API registration overview and required security guidanceAmazon Selling Partner API
  2. Roles in the Selling Partner APIAmazon Selling Partner API
  3. Credential security clarificationAmazon Selling Partner API
  4. AWS architecture for Amazon Ads and SP-API dataAmazon Web Services
  5. AWS KMS best practicesAmazon Web Services

FAQ

Security questions

Is ClairInsights certified by Amazon?

This page does not claim Amazon certification. ClairInsights is designed around Amazon developer security guidance and verified AWS controls; actual access remains subject to Amazon authorization and the deployed environment.

Where do Amazon credentials live?

With Self-hosted, credentials remain in your AWS environment. With Managed Delivery, ClairInsights uses only the access approved for your accounts, with storage and responsibility defined in the agreement.

Who responds to a failure or Amazon change?

The agreement makes this clear. It identifies who monitors deliveries, applies changes, responds to incidents, and recovers affected periods for your chosen service.

Review your requirements

See exactly where your data, credentials, and responsibilities would sit.

Bring your security requirements. We will map access, deployment, destination, retention, and incident ownership to your environment and policies.

Discuss your security needs