Security
Sellers trust Opsenda with their operational data. Here is how that data is protected — stated plainly, without badges.
01
Encryption
All traffic between browsers, the Opsenda application, and marketplace APIs is encrypted with TLS 1.2 or higher. Data is encrypted at rest on Azure storage. There is no unencrypted path for seller data.
02
Marketplace access
Opsenda connects to Amazon and Walmart exclusively through their official APIs using OAuth tokens scoped to what each seller authorized. Marketplace passwords are never seen, requested, or stored. Sellers can revoke access at any time and revocation takes effect immediately.
03
No buyer personal information
The API roles Opsenda requests do not return buyer names, addresses, or contact details, and Opsenda stores none. The blast radius of any incident is limited to seller business data — buyer data cannot leak from a system that never holds it.
04
Access control
Production access is role-based and limited to the personnel who operate the service, with multi-factor authentication required. Each seller workspace is isolated: one seller’s users cannot reach another seller’s data.
05
Infrastructure
Opsenda runs on Microsoft Azure in the East US region — application hosting and data storage. Email for the opsenda.io domain is hosted with GoDaddy and carries no marketplace data. These are the only two infrastructure vendors, which keeps the surface area small and auditable.
06
This website
opsenda.io is a static site with no cookies, no analytics, and no third-party scripts. There is nothing on this site that tracks visitors, and nothing to authenticate into.
07
Incident response
Security events are logged and investigated. If an incident affects seller data, affected sellers are notified by email without undue delay, with what happened, what data was involved, and what has been done about it.
08
Reporting a vulnerability
Found something? Email contact@opsenda.io with the details. Good-faith reports are welcomed, acknowledged, and acted on.
Data handling, retention, and deletion are covered in detail in the privacy policy. Questions about any of the above: contact@opsenda.io.
Opsenda