Our agency will perform amazon sp API penetration testing

CREST accredited security testing for high trust organisations
Selezionato da Fiverr Pro
REDSECLABS selezionato dal team Fiverr Pro per la sua esperienza.
Selezionato per
Sicurezza informatica
Informazioni su questo servizio
Vetted Pro
RedSecLabs is a UK-based, CREST-accredited cybersecurity firm and PCI QSA company, delivering penetration testing, PCI DSS, SOC 2, ISO/IEC 27001 readiness, incident response, and security advisory services.
We perform Amazon Data Protection Policy (DPP) penetration testing and compliance assessments for Selling Partner API (SP-API) applications. These assessments are required annually for Restricted Role access and are reviewed by Amazon.
WHAT WE TEST
- Login with Amazon (LWA) OAuth
- Selling Partner API (SP-API) authentication and authorization
- Restricted Data Tokens (RDT)
- AWS IAM, STS, and least-privilege controls
- Secrets management and credential security
- API authorization and business logic
- PII handling, encryption, and retention
- Role-based access control (RBAC)
- Multi-tenant SaaS isolation
- Logging, monitoring, and audit trails
- Incident response and DPP controls
- Infrastructure vulnerability assessment
- Manual penetration testing (OWASP)
Expertise:
Audit
•
Gap analysis
•
Valutazione del rischio
Tecnologia:
Cloud - IaaS
•
Firewall
•
Altro
Clienti con cui abbiamo lavorato
Bykea
Mobile App Development
Provided cyber security consulting for Bykea to strengthen their overall security posture. Developed a Cyber Security Framework specifically for developers, integrated DevSecOps practices, and significantly improved their Vulnerability Disclosure.
feb 2023
Portfolio
Altri servizi della categoria Sicurezza informatica offerti da noi
FAQ
Why does an SP-API application need a penetration test?
Amazon's Data Protection Policy requires an annual penetration test for applications performing restricted operations (anything touching PII). It also requires vulnerability scans every 180 days. Without these, restricted role access can be revoked.
Will Amazon's review team accept the report?
To date, we have maintained a 100% acceptance rate for completed Amazon DPP assessments. Our reports are specifically structured to align with Amazon's DPP security review requirements. Final approval remains at Amazon's discretion.
Do you cover the application and the AWS infrastructure behind it?
Yes. Both are tested. The LWA OAuth flow, RDT handling, refresh token storage, IAM, KMS, S3, Lambda execution roles and data egress paths.
We failed Amazon's security review, can you help us recover?
Yes. We audit against the specific failure points Amazon flagged, support remediation and produce a submission-ready report.
Do you cover both seller-side and vendor-side SP-API integrations?
Yes. Including hybrid implementations and delegatee applications using RDTs received from a delegator.
We have no restricted operations, do we need this?
If you do not perform restricted operations, the annual DPP pentest is not required. We will confirm this in scoping and not sell you something you do not need.

