Security
Security at Sapyon
Last Updated September 18, 2026
Sapyon AI is a multi-tenant B2B application operated by VNash Digital Pvt Ltd. This page describes the security practices we actually implement today. We evaluate additional controls as the Service matures. We do not claim ISO, SOC, or similar certifications.
Related contractual terms are in the Terms of Service, DPA, and Privacy Policy. Questions: [email protected].
Data encryption
User access to the production Website and Service is over HTTPS with TLS. Secrets used by the backend (including credentials needed to call connected APIs) are stored in AWS Secrets Manager rather than in application source code.
We do not currently publish a TLS minimum version, encryption-at-rest configuration, encrypted-backup specification, or customer-managed key program on this page. No method of transmission or storage is completely secure.
Access control
- Non-public API routes require authentication when app auth is enabled.
- The Service issues Bearer JWT access tokens from the backend.
- Role-based access control applies (including super admin, account owner, profile grants, and permission codes). Demo-user profiles are restricted.
- Passwords have a minimum length of eight (8) characters. Non-demo users can change their password while authenticated. Google OAuth is offered as an alternative to passwords.
- Certain Selling Partner API connection and retail operations are restricted to super-admin roles.
We do not currently claim organization-wide MFA, a named production jump-host policy, or a public least-privilege matrix. Access is granted according to role and Customer-configured profile permissions.
Amazon credentials
Customers connect Amazon Ads through Login with Amazon (LWA). OAuth tokens are used to call Amazon Advertising APIs on Customer’s behalf, including reads and, where Customer has approved a recommendation or enabled automation, writes.
Server-side secrets are stored in AWS Secrets Manager. The browser stores the User’s Service session (access and refresh tokens) in localStorage. That is not equivalent to httpOnly cookie storage. Users should use a private device, sign out on shared devices, and protect their password and Google account.
We do not ask Customers to paste long-lived Amazon root credentials into the marketing Website. Revoking Login with Amazon stops new ingest and new Sapyon-initiated writes through that connection.
Infrastructure
Production API traffic terminates at an AWS Elastic Load Balancing hostname in us-east-1. Compute runs on AWS ECS. Relational data uses AWS RDS. Advertising report files use S3. Amazon Marketing Stream subscriptions use SQS. The web application is hosted on Netlify, with DNS for sapyon.com on Cloudflare.
We do not offer single-region data residency. Current subprocessors are listed at /subprocessors.
Monitoring
We retain server and security logs for operations and security, typically up to ninety (90) days, unless an incident, dispute, or legal obligation requires longer. We use these logs to debug, monitor reliability, and investigate abuse. We do not currently publish a named SIEM, vulnerability-scan cadence, or bug-bounty program.
In-product Chat sends relevant account context to Google Gemini to generate a reply. Chat action proposals execute only after User confirmation, unless Customer has configured a separate automation.
Employee security
Personnel who can access production systems or Customer Data are limited by role and are under confidentiality obligations. Access is reviewed when people change roles or leave. We do not currently publish a formal security-training curriculum or background-check policy on this page.
Incident response
We maintain an incident-response process: identify, contain, remediate, and notify. If we become aware of a security incident affecting Personal Data, we will notify affected Customers and, where required, individuals or regulators, in accordance with applicable law and the DPA. Privacy contact: [email protected].
Business continuity
Service data is stored in AWS-managed data stores. Backups exist on a rotation cycle; backup copies expire as that cycle turns. After a verified deletion request, production deletion is completed within ninety (90) days, while backups may persist until they rotate. We do not currently publish a quantified RPO/RTO or a multi-region failover SLA.
Customer data
- Customer owns its Customer Data, including Amazon Ads data ingested from connected accounts.
- Sapyon processes that data to provide the Service, including automations and Chat, as described in the Terms and DPA.
- We do not sell Customer Data or Personal Information, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA.
- Retention and deletion are described in the Privacy Policy. Account erasure is requested by email; there is no in-app delete-my-account control.
Related: Privacy Policy · DPA · Subprocessors · Privacy Requests
Ready to Turn Hourly Signals into Higher ROAS?
Real-time analytics, automation, and AI decisions, built specifically for Amazon advertisers. Scale with confidence.
Book a DemoBy booking a demo, you agree to our Privacy policy.