Brands trust Nectar with access to their Amazon Seller and Vendor Central accounts, advertising platforms, sales data, and customer information. We treat that access as a responsibility, not a convenience. This page describes the specific controls we operate to protect client and customer data — how we authenticate, how we encrypt, who can see what, and what happens if something goes wrong.
Last reviewed: August 6, 2026. Reviewed at least annually.
A quick summary of the controls covered in detail below — authentication, encryption, access, people, vendors, incident response, and governance.
Every account used to access client data requires a second factor. This includes company email and productivity accounts, Amazon Seller Central and Vendor Central, Amazon Ads and other advertising platforms, our analytics infrastructure including iDerive, and all internal business systems. Accounts that cannot enforce MFA are not approved for use with client data.
Company accounts are centralized behind single sign-on where the platform supports it. Where it doesn't, credentials are generated and stored in a company-managed password manager with enforced complexity requirements. Employees do not store client credentials in browsers, spreadsheets, shared documents, or personal password tools.
Wherever a platform supports it, we work inside your account under our own named user with a defined permission level — we do not ask you to share a password. On Amazon that means user permissions in Seller Central or Vendor Central; on advertising and analytics platforms it means account-level user invitations. This keeps every action attributable to an individual and lets you revoke our access instantly, without changing your own credentials.
Access is provisioned by role. New access is scoped to the narrowest level that allows the work to be done, and requires approval from the account lead.
We review who has access to which client accounts and internal systems on a recurring schedule and remove permissions that are no longer required. When an employee or contractor leaves, their access to company systems and all client platforms is revoked as part of a documented offboarding checklist completed on their final day.
All traffic to our website, client-facing dashboards, and analytics platform is encrypted using TLS 1.2 or higher. Data moving between our systems and third-party platforms travels over encrypted connections.
Client data stored in our cloud infrastructure, databases, and file storage is encrypted at rest using AES-256. Company laptops are protected with full-disk encryption, so data on a lost or stolen device is unreadable.
Company devices run current operating systems with automatic security updates, endpoint protection software, screen lock timeouts, and remote wipe capability.
We request only the data and platform permissions the engagement requires. We do not download or retain customer personally identifiable information beyond what is necessary to deliver the service, and we do not use client data to train external models or to benefit other clients.
Employees complete background screening before starting. Every employee and contractor signs a confidentiality agreement covering client data, and we enter into data processing agreements with clients where their data protection obligations require one.
All staff complete security training at onboarding and on a recurring basis. Training covers phishing and social engineering, credential hygiene, safe handling of client data, and how to escalate a suspected incident.
Every employee knows how to report a suspected security issue and is expected to report immediately rather than investigate alone.
Nectar uses established third-party platforms to deliver services — cloud infrastructure, analytics, communication, and project management tools. Before a vendor is approved to handle client data, we review its security posture, its published certifications, and its data handling and retention terms, and we put a written data processing agreement in place where required.
We maintain an inventory of vendors that process client data. Clients under agreement can request the current list, along with our security documentation, from their account lead.
We maintain a documented incident response procedure with named owners at each stage: detection and triage, containment, investigation, remediation, client notification, and post-incident review.
Notification commitment. If we identify a security incident affecting a client's data, we notify the affected client without undue delay and no later than 72 hours after confirming the incident, and we provide what we know about scope, impact, and remediation as the investigation progresses. The procedure is reviewed and tested annually.
Client data held in our systems is backed up on a recurring schedule, with backups encrypted and stored separately from production systems. Our critical platforms run on major cloud providers with redundancy and documented recovery objectives, and we maintain a continuity plan so client work continues through a disruption.
Nectar's security program is built and documented against the SOC 2 Trust Services Criteria for Security, Availability, and Confidentiality. We are currently working through a formal SOC 2 Type II audit and will publish the outcome here on completion. In the meantime, clients and prospective clients under NDA can request our current security documentation and control descriptions.
We handle personal information in line with applicable privacy law, including the GDPR and the CCPA/CPRA, and we support clients in meeting their own obligations as data controllers. Our Privacy Policy describes what we collect and why.
Security is owned at the leadership level and is not delegated to a single individual as a side responsibility. Our policies are reviewed at least annually and updated when our systems, vendors, or obligations change.
