Help get our Amazon SP-API approved (for Restricted Access)

Job ID: 36087559

Budget: $15 – $25 USD

Hello.. I am building a Private app using Amazon's SP-API services. However, because of the functionality we need access to restricted Apis. These apis require us to fill out a "security" form to validate how we comply with things like data access, privacy, infrastructure, development, etc.

We've submited this form dozens of times. The questionnaire is aprox 15 questions that require specific short answers. However we keep getting rejected no matter what we answer. Even if we follow Amazon's own recommendation and documents.

We need help from someone that has experience getting approved for the Restricted Access APIS provided by Amazon SP-API (seller central). So that we can finish the integration of our app by consuming specifically the Orders API.

To provide some background we simply want to automate delivering message to our customers with digital content that is provided as part of the product they ordered. For this we need access to the orders API at the very least but you will see that because of Personal Information this API is "restricted" and requires such clearance (and authentication through secondary tokens).

Help please!! we need somebody to help us write these responses based on best practices that guarantee getting our app approved. Even if this implies having to update our operating processes and security policies.

Some of the bullets we are being rejected on are:

UP - Acceptable Use Policy

https://sellercentral.amazon.com/mws/static/policy?documentType=AUP&locale=us_US

- Data usage 4.1.
Question - Describe why you require Personally Identifiable Information to build your application or feature.


RDA - Restricted Data Access

https://sellercentral.amazon.com/mws/static/policy?documentType=DPP&locale=us_US

- Access Management 1.2 and Least Privilege Principle 1.3.
Question - Describe how your organization individually identifies employees who have access to Amazon information, and restricts employee access to Amazon information on a need-to-know basis.

- Asset Management 2.3.
Question - Describe the mechanism your organization has in place to monitor and prevent Amazon Information from being accessed from employee personal devices (such as USB flash drives, cellphones) and how are you alerted in the event such incidents occur.

- Encryption at Rest 2.4
Question - Describe where your organization stores Amazon Information at rest and provide details on any encryption algorithm used.

- Data Retention 2.1
Question - Describe how your organization backups or archives Amazon Information and provide details on any encryption algorithm used.

- Logging and Monitoring 2.6
Question - Describe how your organization monitors, detects, and logs malicious activity in your application(s).

- Risk Management and Incident Response Plan 1.6
Question - Summarize the steps taken within your organization's incident response plan to handle database hacks, unauthorized access, and data leaks.

- Secure Coding Practices 2.5
Question - How is Personally Identifiable Information (PII) protected during testing?

- Secure Coding Practices 2.5
Question - What measures are taken to prevent exposure of credentials?

- Vulnerability Management 2.7
Question - How do you track remediation progress of findings identified from vulnerability scans and penetration tests?

- Vulnerability Management 2.7
Question - How do you address code vulnerabilities identified in the development lifecycle and during runtime?