Amazon Business Data Protection and Security Policy for Integrations

This Amazon Business Data Protection and Security Policy for Integrations ("Policy") establishes mandatory security requirements for Platform Providers, Resellers, and Direct Integrators ("Integrators") that integrate with Amazon Business technology features ("AB Technology"). These features include but are not limited to e-Invoicing, Punchout, Punch-in, application programming interfaces ("APIs") such as Product Search, Ordering, Reconciliation and Reporting APIs and other software or technology made available by Amazon in connection with the foregoing.

1. Network Protection and Infrastructure Security

a. Integrators must implement controls to restrict access to integration endpoints receiving Amazon Business Information. Network-level controls may include but are not limited to firewall rules, IP whitelisting, network access control lists (ACLs), VPN requirements, or private network placement.

b. Integrators must implement Distributed Denial of Service (DDoS) protection mechanisms (such as cloud-based DDoS protection, on-premise DDoS appliances, or rate limiting) for all integration endpoints.

c. Integrators must be able to detect and mitigate unauthorized attempts to access integration endpoints (e.g., by monitoring network traffic to and from Amazon Business endpoints for anomalies).

d. Integrators must implement Web Application Firewall (WAF) or similar protection for user-facing applications that display Amazon Business Information.

e. Integrators must prevent automated scraping, extraction, or replication of Amazon Business Information by implementing controls such as bot detection and prevention mechanisms.

2. Identity, Authentication and Access Management

a. Integrators must implement appropriate authentication mechanisms for integrations, including OAuth 2.0 for API integrations and cXML authentication or client certificate authentication (mTLS) for e-procurement integrations.

b. Integrators must protect integration endpoints against spoofed identities:

i. If using Identity Federation, Integrators must use industry-standard protocols along with token expiration policies.

ii. If using client certificate authentication, Integrators must validate client certificates against the complete certificate chain and check certificate revocation status using Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP). Integrators must maintain a certificate rotation policy and notify Amazon Business at least 30 days before certificate expiry.

c. Integrators must limit user access to Amazon Business Information on a need-to-know basis by:

i. Implementing role-based access control (RBAC) to restrict which users within Integrator's organization can access Amazon Business integrations and which end-user buyers can access Amazon Business Information.

ii. Implementing fine-grained access controls to ensure users only access data they are authorized to view.

d. Integrators must protect Amazon Business Information from overly permissive access by ensuring each business function operates with only the minimum permissions necessary, with documented justification for each OAuth scope granted by Amazon Business (e.g., by assigning unique service accounts per business function).

e. Integrators must require Multi-Factor Authentication (MFA) for all administrative accounts with access to Amazon Business integration configurations or credentials.

3. Credential and Secret Management

a. Integrators must ensure that Amazon Business credentials and secrets are protected from unauthorized disclosure by:

i. Storing credentials in dedicated secrets management solutions and never in plain text or hardcoded.

ii. Stripping or masking credentials before sending data to analytics platforms, business intelligence tools, or monitoring systems.

b. Integrators must ensure continuity of integrations during credential rotation by:

i. Acting on credential rotation notifications from Amazon Business within the required timeframe.

ii. Being able to update systems within 7 days of credential rotation without downtime.

4. Encryption in Transit

a. Integrators must ensure that Amazon Business Information is protected from interception or tampering in transit by:

i. Encrypting all communications using TLS 1.2 or higher.

ii. Rejecting connections using deprecated protocols (SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1).

b. For e-procurement integrations, Integrators must ensure that BrowserFormPost (hook) URLs are served exclusively over HTTPS.

5. Transaction Integrity and Message Validation

a. Integrators must ensure that only well-formed, schema-compliant messages are exchanged with Amazon Business by:

i. Validating all request parameters and message structure against defined schemas before transmitting to Amazon Business.

ii. Validating messages received from Amazon Business against schemas.

iii. Enforcing input validation and sanitization to prevent input tampering attacks.

b. Integrators must ensure that each message exchanged with Amazon Business is uniquely identifiable and cannot be replayed by:

i. Generating unique message identifiers for each outbound message.

ii. Validating the uniqueness of message identifiers in inbound messages to prevent replay attacks.

c. Integrators must ensure that inbound messages from Amazon Business originate from an authenticated and authorized source by:

i. Validating authentication credentials in all inbound messages from Amazon Business.

ii. Validating that user identity in messages matches the authenticated user in Integrator's system.

d. Integrators must ensure that data cannot be tampered with between user sessions and message transmission.

e. Integrators must ensure that connections are established only with verified, trusted endpoints by:

i. Validating that certificates match the hostname.

ii. Rejecting self-signed or expired certificates.

6. Incident Response and Notification

a. Platform Providers and Resellers must ensure that Security Incidents involving Amazon Business Information are responded to in a timely, structured manner by maintaining an incident response plan that identifies roles, responsibilities, incident types, response procedures, and escalation paths.

b. Platform Providers and Resellers must ensure that Amazon Business is made aware of any Security Incident involving its data by notifying Amazon Security promptly via email to [email protected].

c. Platform Providers and Resellers must ensure that each Security Incident is fully resolved and recurrence is prevented by investigating the incident and documenting the incident description, remediation actions, and corrective controls.

7. Data Minimization

Integrators must ensure that only the minimum Amazon Business Information necessary for the stated business use case is collected, processed, and stored.

8. Logging, Monitoring and Alerting

a. Platform Providers and Resellers must ensure that security-related events are recorded with sufficient information to determine when the event occurred, who initiated the action, what was accessed or modified, and the result of the request.

b. Platform Providers and Resellers must ensure end-to-end traceability across transaction lifecycles by maintaining correlation IDs across all systems involved in the integration.

c. Platform Providers and Resellers must ensure that logs are protected from unauthorized access or tampering by:

i. Implementing access controls to prevent unauthorized log access or modification.

ii. Redacting or masking sensitive data in logs.

d. Platform Providers and Resellers must be able to detect and respond to suspicious or anomalous activity related to integrations (e.g., by implementing monitoring alarms for unauthorized calls, unexpected request rates, unusual data retrieval volumes, failed authentication attempts, configuration changes, or credential exposure).

e. Platform Providers and Resellers must ensure that triggered alarms are investigated and documented in accordance with the incident response plan.

9. Third-Party Risk and Subprocessor Management

a. If Platform Providers and Resellers use Subprocessors to facilitate integration with Amazon Business, Platform Providers and Resellers must ensure that Amazon Business Information processed by Subprocessors is subject to equivalent security protections by:

i. Maintaining written data processing agreements with all Subprocessors.

ii. Including contractual provisions that explicitly limit downstream data use and prohibit sharing with fourth parties.

b. Platform Providers and Resellers must ensure that Subprocessors maintain an acceptable security posture on an ongoing basis by conducting security assessments of Subprocessors at least annually.

c. Platform Providers and Resellers must ensure that Subprocessors implement adequate technical controls to protect Amazon Business Information, including:

i. Encryption at rest and access controls.

ii. Audit logging and regular security assessments.

iii. Strong authentication for integration points (e.g., Mutual TLS, OAuth, or equivalent).

10. Security Assessment

An Integrator must undergo a security assessment prior to integrating with AB Technology. Amazon Business may conduct periodic assessments of Integrator's compliance with this Policy, and Integrator must cooperate with Amazon Business in connection with the assessment. If the assessment reveals deficiencies and/or failures to comply with our terms, conditions, or policies, the Integrator must, at its sole cost and expense, take all actions reasonably necessary to remediate those deficiencies within the time frame requested by Amazon Business.

11. Definitions

"Amazon Business Information" means any information that is exposed through AB Technology or Amazon's publicly facing websites, including but not limited to product catalog data, pricing information, seller information, availability data, shopping cart data, product classifications, certifications, as well as any customer data such as order status, shipment tracking, and invoice data.

"Direct Integrator" means an Amazon Business customer that integrates directly with AB Technology for its own internal business use.

"Platform Provider" means a third-party e-procurement platform, expense reimbursement system or other platform/system integrated with AB Technology to offer services to other Amazon Business customers.

"Reseller" means a third-party entity that resells Amazon Business products or services to end customers through integration with Amazon Business.

"Security Incident" means actual or suspected unauthorized access, use, disclosure, modification, or destruction of Amazon Business Information, or interference with system operations.

"Subprocessor" means an external third-party middleware platform or intermediary.

Last Updated: July 26, 2026