Skip to main content

Security and data protection at Terra PPC

Terra PPC is designed around authorized access, account scoping, data minimization, secure transport, operational traceability and documented data lifecycle controls.

Terra PPC is a software product operated by ĐT ORGANIC COMPANY LIMITED.

Legal operator
CÔNG TY TNHH ĐT ORGANIC
Registered foreign-language name (English)
ĐT ORGANIC COMPANY LIMITED
Enterprise Registration No.
5901217159
Country of incorporation
Vietnam

Security principles

Six principles shape how Terra PPC handles access and data. Statements on this page describe design principles and intended controls unless they refer to this public website.

Authorized access
Account connections are designed around Amazon-provided authorization mechanisms, never shared passwords.
Least privilege
People and services receive only the access their legitimate function requires.
Account isolation
Operations stay tied to the relevant organization, account, advertising profile, seller connection and marketplace.
Data minimization
Only data needed for enabled functionality is accessed and retained.
Operational traceability
Important automation and operational actions are designed to be recorded for review.
Data lifecycle
Retention is limited, and a documented process handles account-data deletion requests.
Conceptual security route for one request. In order: Authorized access: The request uses the authorization the customer granted on Amazon — never a password. Least privilege: The reporting service can read performance data; it cannot change bids. Account isolation: Context is limited to ORG → ACCT A → US. Data minimization: Only the fields this view needs are read. Traceability: The access and its result are recorded. Data lifecycle: Data is kept while needed and can be deleted on request.

One request, six interlocks

Request: read campaign metrics for ACCT A · US

Authorization

Terra PPC is designed to connect to Amazon accounts through Amazon-provided authorization mechanisms. For the Amazon Ads API this is Login with Amazon consent; for public Selling Partner API applications it is Amazon's OAuth-based authorization workflow. The account owner approves access on Amazon, and Terra PPC receives authorization only for the approved scope.

Advertising and seller-business access represent separate authorization contexts. Authorizing advertising access does not grant seller-business access, and the reverse is also true. Each has its own scope and can be revoked on its own.

Terra PPC does not ask customers to provide their Amazon password directly to Terra PPC, and it never asks for multi-factor authentication codes. Authorization can be revoked through the applicable Amazon account settings, or by asking Terra PPC to disconnect the account.

Conceptual authorization model. The customer grants two separate authorizations on Amazon: advertising authorization through Amazon-provided consent for the Amazon Ads API, which covers an advertising account or profile, and seller authorization through SP-API OAuth, which covers a selling partner and marketplace. Access to one does not grant access to the other. Terra PPC scoped services use each connection only for the functionality it authorizes. No Amazon password is entered into Terra PPC.

ConceptualConceptual architecture. No Amazon login screen is shown or imitated.

Credential and token protection

Authorization tokens and application credentials are treated as secrets. Terra PPC's production architecture is designed so that they are:

  • kept on the server side only — never in the browser or in website code;
  • never displayed on the website, placed in URLs or written to general-purpose logs;
  • available only to the services that need them to call Amazon APIs;
  • replaceable, so a credential can be rotated or revoked if exposure is suspected.

About this website: the public Terra PPC website contains no Amazon client credentials, refresh tokens or other secrets, and it does not display tokens or account identifiers.

Data in transit

Production web services are designed to use HTTPS/TLS for network transport. This website is intended to be served over HTTPS only and instructs browsers to keep using HTTPS for the domain. Connections to Amazon APIs use Amazon's HTTPS endpoints.

Data at rest

Terra PPC's production architecture is designed to store customer data with encryption at rest and with access restricted to the services that need it. This page does not name specific algorithms, key-management products or hosting regions.

Tenant and account isolation

Terra PPC is designed to keep customer operations logically scoped to the relevant organization, authorized account, profile and marketplace. Every rule, recommendation, action and AI-assisted request is designed to carry its scope and to be validated against it before it runs.

ORGAccountProfileSeller connectionMarketplaceOrganization, then account, then advertising profile and seller connection, then marketplace.

Scope hierarchy: an organization contains Authorized Account A, with a US advertising profile, a US seller connection and the US marketplace, and Authorized Account B, with a CA advertising profile, a CA seller connection and the CA marketplace. The selected context is Account A, US. A request for Account B from that context is out of scope and is not executed.

Least privilege

Access only where it is needed. Terra PPC is designed so that:

People
Team members receive only the access their role requires. Access to customer data is limited to legitimate support, operational and security needs.
Services
System components receive only the permissions their function requires, including access to Amazon-related data.
Customer users
Users inside a customer organization can be given role-appropriate permissions, and sensitive operations require appropriate authorization.

Amazon data handling

Terra PPC uses authorized data only for approved functionality and applicable account context, subject to Amazon permissions and requirements. Three kinds of data are kept apart, and each figure in the product shows which kind it comes from.

  • Advertising data

    ADS: advertising data (Amazon Ads API context)

    Amazon Ads API, where authorized

    • Campaigns
    • Targets
    • Keywords
    • Search terms
    • Performance
  • Seller business data

    SELLER: seller-business data (SP-API context, where authorized)

    Selling Partner API, where authorized

    • Marketplace information
    • Sales
    • Financial context
    • Inventory
    • Listings
    • Fulfillment
    • Retail analytics
  • Customer-provided inputs

    ASSUMPTION: customer-configured input, not provided by Amazon

    Configured by the customer in Terra PPC

    • COGS
    • Other costs
    • Desired margin

Customer-configured inputs such as COGS never come from Amazon. Terra PPC's analytics are designed without buyer names, email addresses, phone numbers or shipping addresses.

  • Minimum necessary data. Only what enabled functionality needs.
  • Authorized functionality only. Used to provide the features the customer enabled.
  • Need-to-know access. Limited to people and services with a legitimate reason.
  • No public publication. Amazon-related data is not published or made publicly available.
  • No data selling. It is not sold, resold or offered as a standalone dataset.

Missing does not mean zero

A data source that is not authorized or not available is treated as unavailable, never as a zero. Results that depend on it are marked, and safeguards that need it report an unknown outcome instead of passing silently.

When a data source is unavailable, Terra PPC marks the result instead of treating it as zero. Finance unavailable: Profitability marked partial — Modeled Net Result shows —, never a partial total. Seller revenue unavailable: TACoS unavailable — Shown as —, never as 0%. Inventory unavailable: Inventory Guard not evaluated — Outcome is unknown and does not pass silently.

Unavailable is not zero

How a missing source changes the result

AI/MCP security

AI and MCP are interaction layers, not data access. Terra PPC AI/MCP is designed so that an AI client receives scoped context for the selected organization, account, profile and marketplace — never unrestricted raw database access. A policy layer decides which tools and action types are available, and any change still passes the configured mode and guardrails.

Conceptual Terra PPC AI/MCP workflow. The request “Show campaigns above modeled break-even ACoS.” passes, in order, through: User request, Terra PPC AI / MCP, Authentication & authorization, Scope, Decision context, Decision engine, Execution planner & guardrails, Manual / Review / Auto, Audit. The read-only answer: 1 of 7 campaigns is above its modeled break-even ACoS. SP | Competitor Product Targeting has an ACoS of 52.1% against a modeled break-even of 37.0%. Sources: advertising data, customer-configured assumptions and derived values. Nothing was changed.
Terra PPC AI/MCP in detail

Automation safety

Automation runs in one of three modes — Manual, Review or Auto — and no mode bypasses authorization, scope, guardrails, permissions or audit logging. Guardrails such as bid floors and ceilings, change caps, cooldowns and action limits apply to every automated or recommended change, and conflicting rules are designed to resolve deterministically, with the outcome recorded.

Every automation cycle follows the execution planner's fixed order — scope and data readiness, safety, proposals, conflicts and limits — before the mode decides anything. A circuit breaker routes Auto actions to review when a cycle would exceed its limits, emergency controls can stop increases for a whole scope, and applied changes keep their previous value so they can be undone.

Logging

Terra PPC is designed to record:

Operational events
Account connections and disconnections, data synchronization and processing outcomes.
Security-relevant events
Sign-ins, permission and authorization changes, and access to sensitive functions.
Automation actions
Evaluations, recommendations, approvals, rejections, applied changes and blocked actions.

Logs are designed to exclude secrets such as tokens and passwords, and to be kept only as long as needed for security, operations and applicable obligations.

Data retention and deletion

Customer data is retained only as long as needed for enabled functionality, the customer relationship and applicable legal obligations. When an account is disconnected or a deletion request is approved, eligible data is designed to be deleted or de-identified according to applicable requirements.

Conceptual data lifecycle: Authorize: The customer grants advertising and seller authorization on Amazon — separately. Use: Only the fields enabled functionality needs, inside the authorized scope. Retain: Kept only as long as enabled functionality and the customer relationship need it. Revoke: Either authorization can be revoked on its own. Delete: A deletion request is verified and scoped, then eligible data is deleted or de-identified. Limited retention: Only records required for legal, security, fraud-prevention or dispute obligations. Revoking advertising authorization stops new advertising data; revoking seller authorization stops new seller-business data; a deletion request is a separate process.

Data lifecycle

From authorization to deletion
How to request data deletion

Incident reporting

If you believe you have found a vulnerability, suspect misuse of Amazon-related data, or see exposed credentials, report it through the security reporting page. Reports are reviewed and investigated, and confirmed incidents involving Amazon-related data are handled in line with applicable Amazon requirements, including notification obligations.

Security controls evolve

Security controls may evolve as Terra PPC's production infrastructure, product functionality and applicable requirements change.

This page describes design principles and intended controls. It does not claim third-party security certification.

Terra PPC is a software product operated by ĐT ORGANIC COMPANY LIMITED.