Security & Data Protection Controls

How KingKung (operated by Zhengzhou Jindouyun Industrial Co., Ltd.) protects Amazon seller data accessed through the Selling Partner API. This page maps to the SP-API Key Security Control guidance and supports the Acceptable Use Policy (AUP) and Restricted Data Access (RDA) requirements. Related: privacy.html.

AUP 4.1 — Data Usage

Why we require Direct-to-Consumer Shipping (Restricted)

KingKung requests the Direct-to-Consumer Shipping (Restricted) role, together with the general Inventory and Order Management role, only to obtain Restricted Data Tokens for the buyerInfo and shippingAddress fields returned by the Orders API for the connected seller’s merchant-fulfilled orders. Buyer name, shipping address, and phone number where Amazon provides it are required to:

  • generate pick / pack lists and shipping-label workflows for the seller’s pending orders
  • display the delivery destination and fulfillment status per order
  • support returns and after-sales handling that require confirming the shipping address

Buyer PII is used only for the connected seller’s fulfillment workflow and is not used for marketing, advertising, profiling, resale, or cross-customer purposes. Retention and deletion are described in the Privacy & Data Protection Policy.

Network Protection 1.1

Restricting public access to production systems

  • Production services use controlled cloud network infrastructure. Database and object-storage access is limited to approved application services and authorized administrators and is not exposed as a public application endpoint.
  • Network rules allow only required service connections. Administrative access is limited to authorized personnel using individual accounts and assigned permissions.
  • Public application traffic uses HTTPS, and relevant access events are logged for investigation of unauthorized-access attempts.
Asset Management 2.3

Preventing access from personal devices and removable media

  • Systems handling Amazon Information are accessible only to authorized personnel using approved company-managed endpoints and individual accounts.
  • Personal computers, personal mobile devices, and removable media such as USB storage are not authorized to access, download, or store Amazon Information.
  • Authentication, administrative access, and relevant application activity are logged and monitored. Unauthorized attempts or suspected transfers are reviewed and handled through access restriction and the incident-response process where appropriate.
Encryption at Rest 2.4

Protecting stored Amazon information

  • Amazon Information stored in production databases, object storage, exports, and backups is encrypted at rest.
  • Encryption-key access is limited through assigned cloud permissions and authorized service access.
Data Retention 2.1 — Backup & Restore

Encrypted backups and service recovery

  • Encrypted production backups are maintained in a geographically separate location with access limited to authorized services and personnel.
  • Documented recovery objectives and procedures support restoration of data and service.
  • Recovery consists of selecting an approved recovery point, restoring the data and service, verifying integrity and access, and returning the service to operation.
Logging and Monitoring 2.6

Security logging, monitoring, and investigation

  • Centralized logs cover authentication, administrative actions, application activity, database events, and relevant SP-API request metadata.
  • Monitoring is used to identify repeated authentication failures, unexpected privilege changes, unusual administrative access, abnormal API activity, and unusual order-data exports.
  • Suspected events are investigated using the relevant logs to determine affected accounts, systems, and data, followed by containment, remediation, and documented closure.
Risk Management & Incident Response 1.6

Handling security incidents

KingKung maintains an internal process for responding to suspected security incidents involving its systems or Amazon Information.

  • Identify: review alerts, reports, or other indications of unauthorized access or data exposure.
  • Contain: restrict affected accounts, credentials, systems, or data access as appropriate.
  • Investigate: review available logs and application records to determine scope and root cause.
  • Remediate: correct the underlying issue and restore normal service operations.
  • Notify: communicate with affected parties and Amazon when notification is required under applicable agreements, policies, or law.
  • Review: document corrective actions and update operational controls where appropriate.
Credential Management 1.4

Password management

  • Systems handling Amazon Information use individual named accounts and enforce password length and complexity requirements.
  • Password expiration and reuse restrictions are applied according to the organization’s credential-management policy.
Vulnerability Management 2.7

Tracking remediation progress

  • Each identified security finding is recorded with the affected asset, severity, responsible owner, target completion date, current status, and verification result.
  • Open and overdue findings are reviewed according to severity, and overdue high-risk items are escalated to responsible technical management.
  • A finding is closed after the remediation or approved mitigation has been completed and verified.
Vulnerability Management 2.7 — Development & Runtime

Remediating code vulnerabilities

  • Code and dependency issues identified during development are assessed by severity, assigned for remediation, and reviewed before the related change is released.
  • Issues identified during runtime are assessed for production impact and handled through the same tracked remediation process.
  • Corrective changes are reviewed and verified before the finding is closed.
Related: Privacy & Data Protection Policy · Last updated: August 2026.