Security & Trust
Last updated: August 27, 2026
Lumipricer receives authorized access to seller marketplace accounts and can submit prices after a seller deliberately enables Live mode. We treat both capabilities as sensitive. This page describes controls the product and operating process can evidence today. Security questions and reports can be sent to hello@lumipricer.com with the subject "SECURITY".
1. Marketplace access model
- Amazon connections use Amazon's supported Seller Central authorization flow. Lumipricer receives an authorization result and does not ask for the seller's Amazon password.
- Walmart connections currently use a Production API Client ID and Client Secret generated by the seller in Walmart Seller Center. Lumipricer validates the credentials before accepting the store and does not ask for the seller's Walmart password.
- Marketplace credentials are held by the pricing service rather than exposed to the browser dashboard.
- A seller can revoke Amazon access in Seller Central or revoke and replace the applicable Walmart API key in Seller Center. Marketplace-side revocation prevents further API access independently of Lumipricer.
2. Credential and secret handling
- Marketplace client secrets, refresh tokens, webhook secrets, cached access tokens, and other protected connection values are encrypted with authenticated encryption before storage. A modified encrypted value fails verification rather than decrypting into a value the service would use.
- Encryption keys and marketplace-writing credentials are restricted to the services and hosts that require them. The seller dashboard does not contain the engine's privileged database or marketplace credential key.
- Sensitive values are not intentionally written to application logs. Automated tests use sentinel values to detect accidental secret exposure across response and serialization boundaries.
- Connections use TLS in transit. Administrative access and production credentials are limited to the people and automated processes required to operate the Service.
3. Seller and tenant isolation
- Seller data is identified by tenant, store, and listing boundaries. A marketplace listing is not joined by title; product operations use the seller-owned store and SKU identity.
- The dashboard authorizes the signed-in person, verifies membership and role, and restricts seller-visible reads and writes to the stores assigned to that membership.
- Database identities are scoped to their role. The dashboard and pricing engine do not share an unrestricted database identity, and row-level policies protect seller-facing tables where applicable.
- One seller's private catalog, credentials, costs, orders, strategies, and pricing history are not shared with another seller or used to set another seller's prices.
4. Pricing-write safety
- Listings have explicit Off, Preview, and Live modes. Preview calculates and records a decision while removing marketplace submission from the path.
- Changing automation state goes through a guarded database function that enforces seller ownership, entitlement, plan limits, and Live-readiness checks.
- Live pricing refuses to guess required economics. Missing authoritative cost, unknown fulfillment, inconsistent minimum or maximum boundaries, expired economics, unavailable safety state, or other required evidence can stop a write.
- The price requested from a marketplace and the price later confirmed by that marketplace remain separate states. Lumipricer does not treat a submitted request as an accepted live price.
- Pricing operations use deadlines, idempotency controls, reconciliation, and readback so a timeout or retry is not silently treated as success.
- Account, store, and global controls can stop real price writes. The send gate fails closed when required safety configuration cannot be read.
5. Logging, monitoring, and change control
- Pricing decisions and price-change attempts are recorded with the relevant listing, time, inputs, decision reason, simulation state, submission state, and marketplace outcome available to the system.
- Administrative and operational actions are logged to support diagnosis, reconciliation, and incident review.
- Pull requests and releases run type checking, production builds, dependency auditing, pricing and safety suites, migration hygiene, and schema replay. Automated CI uses synthetic credentials rather than production marketplace credentials; database-writing suites run against a throwaway local Supabase/Postgres environment.
- Production releases select an exact reviewed commit, serialize deployment, apply and verify required schema state, restart the service, and perform health checks. The deployed application exposes a non-secret build identifier for release verification.
- Marketplace behavior is tested at contract boundaries, including costless Preview, no-send gates, strategy edges, marketplace confirmation, inventory handling, billing entitlement, and migration upgrades.
6. Availability and failure behavior
- Secondary reporting data may be shown as unavailable or unknown without erasing the authoritative catalog or converting a failed read into zero.
- Marketplace and database calls use bounded deadlines. Slow or unavailable dependencies must not leave an unbounded pricing operation running.
- Recovery and reconciliation jobs distinguish retryable failures, permanent marketplace refusals, pending outcomes, and confirmed results.
7. Incident response
- We maintain an incident process covering detection, severity assessment, containment, evidence preservation, remediation, recovery, and post-incident review.
- Containment comes before a speculative diagnosis. Price-writing controls can be disabled while the cause or scope remains unknown.
- Affected sellers and relevant marketplaces are notified according to applicable law, contract, and marketplace policy.
- Credentials are revoked or rotated when exposure is suspected, and marketplace readback is used to verify resulting state after containment.
8. Vulnerability reporting
We welcome good-faith security research. Email hello@lumipricer.com with subject "SECURITY" and include the affected URL or component, reproducible steps, impact, and any safe evidence. We aim to acknowledge a report within two business days. Please avoid accessing another seller's data, changing marketplace prices, degrading availability, or publicly disclosing an unresolved issue before we have had a reasonable opportunity to investigate and remediate it.
9. Subprocessors and data handling
Lumipricer uses cloud infrastructure, database, network, email, monitoring, and billing providers to operate the Service. These providers process data on our behalf under their applicable contractual and security terms. Stripe hosts subscription checkout and the customer billing portal. Approved referral partners receive aggregate attribution and commission information only, not seller credentials or operating data. More detail appears in the Privacy Policy; a current subprocessor list is available on request.
10. Data retention and deletion
Marketplace data is retained only as needed to provide the Service, maintain security and audit evidence, comply with platform policy, and resolve disputes. On store disconnection or account closure, associated marketplace data is deleted from active systems within 30 days and residual encrypted backups are purged on a rolling schedule within 90 days, except where law, fraud prevention, payment disputes, or a legal hold requires longer retention.
11. Contact
Aurora PowerUp LLC
1603 Capitol Ave Ste 415 PMB 923143, Cheyenne, WY 82001, US
Security contact: hello@lumipricer.com (subject "SECURITY")