Security
ChannelsHub is a product of ZBK Yazılım ve Bilgi Sistemleri A.Ş.
Security is an integral part of the ChannelsHub platform and its development and operational processes. ZBK Yazılım ve Bilgi Sistemleri A.Ş. applies technical and organizational controls designed to protect merchant information, marketplace information and personal information against unauthorized access, disclosure, alteration and loss.
1. Access Control
Access to production systems and sensitive information is restricted to authorized individuals and services.
- Individual user identification
- Role-based access control
- Least-privilege principles
- Need-to-know access
- Multi-factor authentication
- Controlled administrative access
Access rights are reviewed and adjusted when responsibilities change.
2. Authentication
Accounts with access to sensitive systems are protected by strong authentication controls.
Password policies enforce minimum length, complexity, password history and lifecycle requirements.
Multi-factor authentication uses approved second-factor mechanisms such as authenticator applications or hardware-based authentication where applicable.
Authentication attempts and security events are monitored.
3. Network Protection
Production systems and databases are protected through network segmentation and access-control mechanisms.
Databases and internal services are not directly exposed to the public Internet.
Public access is restricted to required application services.
Administrative access is performed through controlled and authenticated channels.
External communications use encrypted protocols such as TLS.
4. Data Encryption
Sensitive information is protected using encryption at rest and encryption in transit.
Sensitive stored information, including Amazon Information and other personal information, is protected using application-level encryption based on industry-standard cryptographic algorithms, at a minimum AES-128 or RSA-2048.
Data transmitted between systems is protected using TLS 1.2 or higher where applicable.
Encryption keys and sensitive credentials are restricted to authorized systems and personnel.
5. Credential Protection
API credentials, access tokens and other secrets are treated as confidential information.
Credentials are encrypted when stored, protected by access controls and are not stored in source repositories.
Credentials are rotated according to applicable security requirements and are revoked or replaced when compromise is suspected.
6. Logging and Monitoring
Security-relevant activities are logged and monitored.
- Authentication activity
- Administrative activity
- API activity
- Application events
- Data-access activity
- Security events
Automated monitoring is used to identify suspicious authentication, access and data-transfer activity.
Security events are investigated according to our incident response procedures.
7. Vulnerability Management
We perform periodic vulnerability assessments and security testing.
Vulnerability scanning is performed at least every 30 days and additional assessments may be performed following significant changes.
Application code is scanned before production releases.
Security findings are prioritized according to severity. Critical vulnerabilities are targeted for remediation within 7 days and high-risk vulnerabilities within 30 days, subject to the nature and applicability of the finding.
8. Secure Development
Security is incorporated into the software development lifecycle.
Code changes undergo review and security validation before production deployment.
Identified vulnerabilities are prioritized, remediated and validated before release where appropriate.
9. Backup and Recovery
Business-critical information is protected through backup and recovery procedures.
Backups are protected using appropriate access controls and encryption.
Restoration procedures include integrity verification and controlled recovery testing.
Recovery objectives are established according to service criticality.
10. Data Protection
Personal information and marketplace information are classified and handled according to their sensitivity.
Production PII is not intentionally used in development or testing environments.
Where required, synthetic, masked or anonymized data is used for testing.
11. Endpoint Protection
Access to sensitive production information is restricted to authorized and controlled endpoints.
Controls are implemented to reduce the risk of unauthorized copying or transfer of protected information through removable media or personal devices.
12. Incident Response
ZBK maintains an incident response process covering:
- Detection
- Triage
- Containment
- Investigation
- Remediation
- Recovery
- Post-incident review
Security incidents involving unauthorized access, credential compromise or data leakage are investigated according to their severity.
Where required, relevant customers, authorities and platform providers are notified within applicable contractual and regulatory timeframes.
Where a security incident affects Amazon Information, ZBK notifies Amazon at [email protected] within 24 hours of detection, consistent with Amazon's Data Protection Policy.
13. Personnel Security
Access to sensitive information is limited according to job responsibilities and business necessity.
Personnel with access to protected information are subject to confidentiality obligations.
Security responsibilities are incorporated into applicable organizational and contractual processes.
14. Third-Party Security
Third-party services that may process information are selected and used according to the nature of the service and information involved.
Where appropriate, contractual, technical and organizational safeguards are applied.
Security Contact
Security-related questions or reports may be submitted to:
ZBK Yazılım ve Bilgi Sistemleri A.Ş.
ChannelsHub
Email:
[email protected]