TRUST CENTER
Security Practices
Reviewed August 9, 2026
Security ownership
Jakob Nelson, Owner, is the designated Security Owner and incident-response executive approver for MarginAIO.
Access protection
- Administrative access is restricted and protected by multi-factor authentication where supported.
- Permissions follow least-privilege principles and marketplace scopes are limited to reporting needs.
- Marketplace passwords are never requested or stored; authorization tokens remain server-side.
Infrastructure and endpoint protection
- Production traffic uses HTTPS through CloudFront and AWS WAF protections.
- Production information is hosted in AWS and encrypted at rest with AWS KMS; credentials and refresh tokens are stored in AWS Secrets Manager.
- Administrative workstations do not store production marketplace credentials or Amazon Information. Endpoint controls include Microsoft Defender, Windows Firewall, automatic security updates, and tamper protection.
Data protection
Sensitive configuration is kept out of browser code, source control, and administrative workstations. Production Amazon Information and marketplace credentials remain inside the encrypted AWS environment. Production access is authenticated with MFA, limited by least privilege, tenant-scoped, logged, and reviewed for operational need.
Vulnerability and incident response
Code, dependencies, and secrets are checked before release. MarginAIO maintains incident procedures for identification, containment, remediation, recovery, evidence preservation, and notifications. Incidents involving Amazon information are escalated for Amazon notification within 24 hours as required.
Report a concern
Email playbacksupply@gmail.com with “MarginAIO security report” in the subject, or call (602) 206-6938. Do not include credentials or buyer information.