A simple security principle
Only the access you approve. Only the data you need. Clear ownership when something goes wrong.
Operating boundary
Choose where control and responsibility sit
Self-hosted keeps the environment under your control. Managed Delivery puts the agreed day-to-day operation with us. In both cases, the contract makes responsibility for incidents, updates, retention, and recovery clear before you start.
Control areaSelf-hostedManaged Delivery
EnvironmentClairInsights runs in your AWS account under your controls.ClairInsights runs the agreed delivery environment for you.
Amazon accessCredentials stay in your environment and remain limited to approved roles.Only the approved accounts and roles are used.
Failures and Amazon changesYour team and ClairInsights share responsibility as agreed.ClairInsights operates the agreed delivery scope.
Retention and deletionYour policies govern data stores and logs.The service agreement defines retention and deletion.
Your approved scope stays visible
Seller/Vendor Central account, Amazon Ads profile, marketplace, and role boundaries remain attached to every data delivery.
Each service receives limited access
IAM permissions cover only the queues, buckets, keys, secrets, and functions that service needs.
Credentials are never placed in code
Application and database credentials use AWS Secrets Manager; Amazon refresh tokens are protected with AWS KMS.
Amazon tokens are encrypted
Refresh tokens use dedicated AWS KMS keys with rotation enabled in the infrastructure.
Report storage blocks public access
Report buckets use server-side encryption and block public access. Queues use managed or KMS encryption.
The database stays private
The application database is not publicly accessible, is encrypted at rest, and is reached through private application networking.
03 / Operations
A missing delivery can be found and recovered
A failed Amazon delivery should be visible before it affects a report or decision. ClairInsights shows the missing period, keeps credentials out of logs, and isolates failed work for safe recovery.
Every delivery leaves evidence
Status, covered periods, destination objects, and errors show where a delivery is missing.
Logs are not kept indefinitely
Deployed modules give log groups and queue messages explicit retention periods.
Repeated failures are isolated
Encrypted dead-letter queues hold repeatedly failing work for investigation and controlled recovery.
04 / Change
Amazon changes do not become invisible data gaps
When Amazon changes a report, ClairInsights helps you find the affected periods and correct them. Original deliveries remain available for recovery instead of leaving a silent gap in the business view.
New fields do not stop the full delivery
Added fields can continue into source storage while invalid data is isolated before business use.
Original deliveries support recovery
Preserved source files allow corrections and rebuilds without unnecessary requests back to Amazon.
Someone is clearly accountable
The selected contract defines who monitors, applies releases, responds to incidents, and recovers affected periods.
Data-minimal analytics
We measure the website journey—not your inquiry
Website analytics use selected anonymous events with memory-only persistence. We do not enable autocapture, cookies, person profiles, session recording, heatmaps, surveys, or automatic exception capture.
- No form values
- No names or email addresses
- No message text
- No full referrer URLs or query strings
- No cross-page identity persistence
FAQ
Security questions
Is ClairInsights certified by Amazon?
This page does not claim Amazon certification. ClairInsights is designed around Amazon developer security guidance and verified AWS controls; actual access remains subject to Amazon authorization and the deployed environment.
Where do Amazon credentials live?
With Self-hosted, credentials remain in your AWS environment. With Managed Delivery, ClairInsights uses only the access approved for your accounts, with storage and responsibility defined in the agreement.
Who responds to a failure or Amazon change?
The agreement makes this clear. It identifies who monitors deliveries, applies changes, responds to incidents, and recovers affected periods for your chosen service.