Skip to content
Security · risk management · responsible reporting

PROTECT THE WORK.

SMAT Designs maintains internal security and risk-management procedures for services and systems that may process authorized Amazon seller information. Report suspected vulnerabilities or sensitive disclosures privately; do not post customer evidence in public repositories.

Report a security concernPrivacy information

Security Reporting and Contact

Business and incident management contact: sm@smatdesigns.com. Include an affected product, a minimal reproducible description, a date/time, and a safe contact method. Do not send Amazon login credentials, tokens, buyer information or raw seller account records through ordinary email. Ask for secure evidence transfer if sensitive details are necessary.

We investigate reported vulnerabilities and suspected incidents, determine affected services and data classes, minimize potential exposure, and coordinate containment and corrective actions with service providers when needed. Our public support repository is for sanitized knowledge and must not be used for private incident reports.

Public EzSeller support documentation · EzSeller product security page

Operating procedures

Risk Assessment & Incident Response

Assess

Identify business and data-handling risks, assign responsible owners, score likelihood/impact, document mitigation and track unresolved issues. Review at least annually and after material changes or incidents.

Detect

Review production endpoint observations, authorization failures, deployment results, service logs, account audit signals and third-party reports. Investigate unexpected behavior and verify findings independently.

Respond

Document the incident, contain access where appropriate, preserve evidence, isolate credentials or affected connections, investigate root cause, restore only after verification and record corrective controls.

Our internal runbook defines preparation, identification, containment, eradication, recovery and lessons learned, an incident contact/escalation owner, and a six-month review cadence. For a real security incident involving Amazon information, our procedure requires notification to Amazon's security contact within 24 hours of detection. We do not send incident reports to Amazon for simulated exercises.

This is a description of organizational procedures, not an independent audit, a guarantee of zero incidents or an assertion that every Amazon DPP control has already passed an external assessment.

Data Practices and Service Boundaries

SMAT's general business website does not request Seller Central credentials. EzSeller is a separately operated software product with product-specific authorization, privacy and security notices; it must not be considered Amazon-approved solely because the website is available. Only the minimum seller permissions necessary for a granted service should be requested.

EzSeller privacy · EzSeller security · SMAT terms · Company contact