Our agency will perform amazon sp API penetration testing

CREST accredited security testing for high trust organisations
Vetted by Fiverr Pro
REDSECLABS was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
RedSecLabs is a UK-based, CREST-accredited cybersecurity firm and PCI QSA company, delivering penetration testing, PCI DSS, SOC 2, ISO/IEC 27001 readiness, incident response, and security advisory services.
We perform Amazon Data Protection Policy (DPP) penetration testing and compliance assessments for Selling Partner API (SP-API) applications. These assessments are required annually for Restricted Role access and are reviewed by Amazon.
WHAT WE TEST
- Login with Amazon (LWA) OAuth
- Selling Partner API (SP-API) authentication and authorization
- Restricted Data Tokens (RDT)
- AWS IAM, STS, and least-privilege controls
- Secrets management and credential security
- API authorization and business logic
- PII handling, encryption, and retention
- Role-based access control (RBAC)
- Multi-tenant SaaS isolation
- Logging, monitoring, and audit trails
- Incident response and DPP controls
- Infrastructure vulnerability assessment
- Manual penetration testing (OWASP)
Expertise:
Audit
•
Gap analysis
•
Risk assessment
Technology:
Cloud - IaaS
•
Firewalls
•
Other
Clients We’ve worked with
Bykea
Mobile App Development
Provided cyber security consulting for Bykea to strengthen their overall security posture. Developed a Cyber Security Framework specifically for developers, integrated DevSecOps practices, and significantly improved their Vulnerability Disclosure.
Feb 2023
Portfolio
Other Cybersecurity Services we Offer
FAQ
Why does an SP-API application need a penetration test?
Amazon's Data Protection Policy requires an annual penetration test for applications performing restricted operations (anything touching PII). It also requires vulnerability scans every 180 days. Without these, restricted role access can be revoked.
Will Amazon's review team accept the report?
To date, we have maintained a 100% acceptance rate for completed Amazon DPP assessments. Our reports are specifically structured to align with Amazon's DPP security review requirements. Final approval remains at Amazon's discretion.
Do you cover the application and the AWS infrastructure behind it?
Yes. Both are tested. The LWA OAuth flow, RDT handling, refresh token storage, IAM, KMS, S3, Lambda execution roles and data egress paths.
We failed Amazon's security review, can you help us recover?
Yes. We audit against the specific failure points Amazon flagged, support remediation and produce a submission-ready report.
Do you cover both seller-side and vendor-side SP-API integrations?
Yes. Including hybrid implementations and delegatee applications using RDTs received from a delegator.
We have no restricted operations, do we need this?
If you do not perform restricted operations, the annual DPP pentest is not required. We will confirm this in scoping and not sell you something you do not need.

