Security and data protection
Our tools work with the inventory and order data your business runs on. This page describes the controls built into them, starting with xCast: how people sign in, how data is encrypted and kept apart, what we ask Amazon for, and what happens if something goes wrong.
Our controls at a glance
A summary of the controls covered in detail below.
Authentication
Every account signs in with a password of at least 12 characters and a code from an authenticator app. Two-step verification cannot be switched off.
Encryption
TLS 1.2 or higher for every connection. AES-256 encryption at rest for the database and stored files.
Access control
Accounts are by invitation only. Each seller's data sits in its own workspace, and people see only the workspaces they are assigned to.
Amazon permissions
xCast asks Amazon for inventory and order reports only. It reads data and never changes anything in a seller's account.
Retention
Amazon data is kept only while a seller uses xCast and is deleted within 30 days of disconnecting or on request.
Monitoring
Sign-ins, failed attempts, lockouts and account changes are recorded with the time and IP address.
Incident response
A documented procedure with named owners, and Amazon and affected sellers told promptly when Amazon data is involved.
Infrastructure
A managed cloud platform with no servers or open ports to maintain, a firewall in front and every release checked before it goes live.
The controls in detail
Each control, what it covers and how it is run.
Two-step verification on every account
After the first sign-in, xCast asks each person to set up an authenticator app before any data opens, and every later sign-in needs a code from it. Recovery codes cover a lost phone. A session that has not been confirmed with a code cannot open seller data.
Passwords and lockouts
Passwords are at least 12 characters, checked against the email address and common choices, and stored only as salted PBKDF2 hashes. Five wrong passwords lock the account for 15 minutes, and the sign-in page is protected against automated attempts.
Sessions and devices
Session cookies are secure and unreadable by scripts. A session ends after two hours without activity or after 12 hours, unless the person chooses to stay signed in on their own computer, and anyone can see and sign out their other devices.
Separate workspaces
Each seller's data is stored and labelled by workspace. A person sees only the workspaces an administrator assigns, and removing that assignment takes effect on their next request. One seller's data is never combined with another's or used for anyone else.
What we ask Amazon for
Through the Selling Partner API, xCast requests two kinds of reports, FBA inventory and orders, under the Inventory and Order Tracking and Amazon Fulfillment roles. Order reports come without buyer names, street addresses, email addresses or phone numbers, and xCast never writes to an Amazon account.
Encryption and secrets
Data in the database and file storage is encrypted at rest with AES-256. The tokens that let xCast read a seller's Amazon reports are encrypted again with AES-256-GCM before they are stored, and application credentials are kept as encrypted secrets, never in code or in the browser.
Activity records
Sign-ins, failed sign-ins, lockouts, changes to two-step verification, passwords and accounts are recorded with the time and IP address and kept for two years. Records never hold passwords, tokens or buyer data.
Retention and deletion
Amazon data is kept only while a seller uses xCast. When a seller disconnects, ends their services with us or asks, their workspace, stored report files and tokens are deleted within 30 days.
Infrastructure and releases
xCast runs on Cloudflare's managed platform, so there are no servers or operating systems for us to patch. Every connection must use TLS 1.2 or higher, which each release checks, and automated crawlers are blocked from the application. A release goes live only after its dependencies pass a vulnerability check and its automated tests pass, and it can be rolled back at once.
Incident response
A documented procedure names an owner for each stage: detection, containment (revoking tokens and sessions, disabling accounts), investigation, recovery and review. If an incident involves Amazon data, we tell Amazon within 24 hours of detecting it, and we tell affected sellers without undue delay and no later than 72 hours after confirming it.
Access reviews
Every quarter, administrators review who has an xCast account and which workspaces each person can open, and remove what is no longer needed. Access ends on the day someone leaves.
Our company programme
The controls that apply to all Xcelerate Brands work, covering people, devices and vendors, are described on the Xcelerate Brands Security page.
Ownership and review
Last reviewed 5 October 2026. Reviewed at least every six months.