1stPage.
Sign up
1stPage.

Trust & Security

Who can see your Amazon data, and how we protect it

This is what's in 1stPage today and we checked every line against our code and our AWS account. If your security team needs more than this page, request the packet and we'll work through their questionnaire with you.

Sign-in

  • Single sign-on with Microsoft Entra ID. An admin connects your tenant once and verifies your email domains, and can choose to add teammates automatically on first sign-in with a set role and account access.
  • Every password sign-in needs a second step: a code from an authenticator app, with recovery codes, or a code sent by email. A user can choose to trust a device for 30 days.
  • Sessions end 12 hours after sign-in. Ten failed attempts lock an account for 30 minutes, and passwords must be at least 12 characters.
  • Sign-in and verification endpoints are rate limited against brute-force attempts.

Access inside your workspace

  • Owner, admin and member roles. Members see only the Amazon accounts they're given.
  • AMC, product cost edits and Listing Quality changes each need their own permission.
  • Nothing in Listing Quality reaches Amazon until someone with that permission approves it.
  • AI chat and MCP answers only read the accounts the signed-in person can open.

API, MCP and data push

  • Claude, ChatGPT and other MCP clients connect with OAuth 2.1, PKCE and dynamic client registration. Access tokens last an hour and refresh tokens rotate.
  • Platform API keys are stored only as a hash and shown once. They're read-only by default, can be rotated or revoked, expire after a year, and stop working when the user is deactivated.
  • On request, we push your 1stPage data to your own S3 bucket or Snowflake account on a schedule.

Where your data lives

  • Hosted on AWS in the US (us-east-1). Analytics data is in ClickHouse Cloud on AWS, reached over a private network link.
  • The database, file storage and cache are encrypted at rest.
  • Amazon authorization tokens are encrypted a second time in the application.
  • The app is served only over HTTPS, with TLS 1.2 or higher.

Amazon data and AI

  • Amazon data is used only to run 1stPage for the customer who connected it. We don't sell it.
  • AI features run on OpenAI and Anthropic through their commercial APIs. They don't train models on your data, and neither do we.
  • The full list of providers that process data for us is in section 5 of our privacy policy.

Logging and monitoring

  • Sign-ins, failed sign-ins, role and membership changes, SSO changes, OAuth consents and API key changes are logged with IP address and kept for at least a year.
  • Every code change is scanned for vulnerabilities, vulnerable dependencies and leaked secrets, and the production image is scanned weekly.
  • AWS CloudTrail and GuardDuty watch the infrastructure.

For enterprise reviews

Request the security packet

Tell us what your review needs and someone on our team will email you back.

Tell us about your review

What does your review need?