Brands trust Nectar with access to their Amazon Seller and Vendor Central accounts, advertising platforms, sales data, and customer information. We treat that access as a responsibility, not a convenience. This page describes the specific controls we operate to protect client and customer data — how we authenticate, how we encrypt, who can see what, and what happens if something goes wrong.
Last reviewed: September 8, 2026. Reviewed at least annually.
A quick summary of the controls covered in detail below — authentication, encryption, access, people, vendors, incident response, governance, and our AI assistant connector.
Every account used to access client data requires a second factor. This includes company email and productivity accounts, Amazon Seller Central and Vendor Central, Amazon Ads and other advertising platforms, our analytics infrastructure including iDerive, and all internal business systems. Accounts that cannot enforce MFA are not approved for use with client data.
Company accounts are centralized behind single sign-on where the platform supports it. Where it doesn't, credentials are generated and stored in a company-managed password manager with enforced complexity requirements. Employees do not store client credentials in browsers, spreadsheets, shared documents, or personal password tools.
Wherever a platform supports it, we work inside your account under our own named user with a defined permission level — we do not ask you to share a password. On Amazon that means user permissions in Seller Central or Vendor Central; on advertising and analytics platforms it means account-level user invitations. This keeps every action attributable to an individual and lets you revoke our access instantly, without changing your own credentials.
Access is provisioned by role. New access is scoped to the narrowest level that allows the work to be done, and requires approval from the account lead.
We review who has access to which client accounts and internal systems on a recurring schedule and remove permissions that are no longer required. When an employee or contractor leaves, their access to company systems and all client platforms is revoked as part of a documented offboarding checklist completed on their final day.
All traffic to our website, client-facing dashboards, and analytics platform is encrypted using TLS 1.2 or higher. Data moving between our systems and third-party platforms travels over encrypted connections.
Client data stored in our cloud infrastructure, databases, and file storage is encrypted at rest using AES-256. Company laptops are protected with full-disk encryption, so data on a lost or stolen device is unreadable.
Company devices run current operating systems with automatic security updates, endpoint protection software, screen lock timeouts, and remote wipe capability.
We request only the data and platform permissions the engagement requires. We do not download or retain customer personally identifiable information beyond what is necessary to deliver the service, and we do not use client data to train external models or to benefit other clients.
Employees complete background screening before starting. Every employee and contractor signs a confidentiality agreement covering client data, and we enter into data processing agreements with clients where their data protection obligations require one.
All staff complete security training at onboarding and on a recurring basis. Training covers phishing and social engineering, credential hygiene, safe handling of client data, and how to escalate a suspected incident.
Every employee knows how to report a suspected security issue and is expected to report immediately rather than investigate alone.
Nectar uses established third-party platforms to deliver services — cloud infrastructure, analytics, communication, and project management tools. Before a vendor is approved to handle client data, we review its security posture, its published certifications, and its data handling and retention terms, and we put a written data processing agreement in place where required.
We maintain an inventory of vendors that process client data. Clients under agreement can request the current list, along with our security documentation, from their account lead.
We maintain a documented incident response procedure with named owners at each stage: detection and triage, containment, investigation, remediation, client notification, and post-incident review.
Notification commitment. If we identify a security incident affecting a client's data, we notify the affected client without undue delay and no later than 72 hours after confirming the incident, and we provide what we know about scope, impact, and remediation as the investigation progresses. The procedure is reviewed and tested annually.
Client data held in our systems is backed up on a recurring schedule, with backups encrypted and stored separately from production systems. Our critical platforms run on major cloud providers with redundancy and documented recovery objectives, and we maintain a continuity plan so client work continues through a disruption.
Nectar has completed a SOC 2 Type II audit covering the Trust Services Criteria for Security, Availability, and Confidentiality. The audit was performed by an independent CPA firm and confirms that the controls described on this page are in place and operated effectively throughout the audit period. Clients and prospective clients can request a copy of the report under NDA from security@thinknectar.com or their account lead. We undergo SOC 2 examination annually to keep the report current.
We handle personal information in line with applicable privacy law, including the GDPR and the CCPA/CPRA, and we support clients in meeting their own obligations as data controllers. Our Privacy Policy describes what we collect and why.
Nectar's Analytics MCP is a service that lets authorized users query Nectar's analytics data through a connected AI assistant (such as ChatGPT, Claude, Microsoft Copilot, or Gemini). This section explains what the Analytics MCP collects and how it's handled, in addition to the general practices described elsewhere on this page and in our Privacy Policy.
To authenticate you, confirm which client data you're allowed to see, run the query you asked for, and return the result through the AI assistant you're using. We also use limited technical information (like error messages) to keep the service running correctly and securely.
You can end your session or ask us to revoke a personal access token at any time by contacting security@thinknectar.com.
Security is owned at the leadership level and is not delegated to a single individual as a side responsibility. Our policies are reviewed at least annually and updated when our systems, vendors, or obligations change.
