Incident Management Policy
Effective date: August 6, 2026
This policy summarizes how Agent SP-API detects, responds to, and communicates about security and availability incidents affecting the Service.
1. Detection and Monitoring
- Production systems are monitored for availability, error rates, and anomalous API usage.
- Every API request carries a unique request ID to support investigation and tracing.
- Authentication failures and rate-limit events are logged and reviewed.
2. Response
- Triage. Reported or detected incidents are assessed for scope, severity, and affected accounts.
- Containment. Compromised credentials or API keys are revoked immediately; affected systems are isolated as needed.
- Remediation. Root cause is identified and fixed; affected data syncs are re-verified.
- Review. Post-incident review documents cause, impact, and preventive actions.
3. Notification
If an incident materially affects the confidentiality or integrity of your data, we will notify affected customers without undue delay after confirming the incident, including what happened, what data was involved, and the steps we are taking. Where an incident involves data obtained through Amazon's Selling Partner API, we also follow Amazon's incident reporting requirements.
4. Reporting an Incident
If you believe you have found a security issue or are experiencing a service incident, contact us immediately through the help page. Please include timestamps, request IDs, and any relevant details.