Trust

Security at Hive Mind Nestor

You are giving software access to the account your business runs on. This page says plainly what we do to protect it — and what we don't claim.

Last updated: September 14, 2026

We never ask for your Seller Central password

Hive Mind Ad Optimizer connects to Amazon only through Amazon's official authorization flows — the Selling Partner API and the Amazon Ads API. You sign in on Amazon's own page and approve the access; we receive a token, never your password. You can revoke that access at any time from Seller Central (Settings → User Permissions → Manage Your Apps), and we stop calling Amazon on your behalf immediately.

Your Amazon tokens are encrypted at rest

Amazon refresh tokens and connection details are encrypted before they are written to the database, using AES-256-GCM with a random salt and IV per record and a key derived with PBKDF2. The master key lives in the hosting platform's encrypted environment, never in source control, and can be rotated. Passwords for the optimizer itself are stored only as bcrypt hashes.

Your data is walled off from every other seller

Every database query made on your behalf is scoped to your organization by a guard that runs in strict mode in production: a query that does not name an organization is refused, not answered. Your advertising data is never pooled with another seller's, shared, or sold.

No public door to the database

All traffic uses HTTPS. The database and job queue sit on a private network with no public endpoint, so they cannot be reached from the internet — only from the application itself.

The AI starts by watching, not acting

Every connected account starts in shadow mode: the optimizer reviews your campaigns and records what it would change — negative keywords, keyword promotions — but applies nothing. It acts on your live ads only after someone in your account switches it to live, and it drops back to shadow on its own if your subscription lapses. Every keyword it does add is recorded so it can be reverted.

We keep less, for less time

  • Raw Amazon report payloads are cleared after 30 days.
  • Account activity logs are deleted after 180 days.
  • When you close your account, or ask us to, your Amazon data is deleted within 30 days — see the Data Protection Notice.

Payments

Subscriptions are billed through Razorpay, a PCI DSS compliant payment gateway that also supports UPI. Card and UPI details are entered on Razorpay's checkout; we never see or store them. We are an Indian company — Hive Mind Nestor Private Limited, Agra — and issue GST invoices, with your GSTIN on them if you add it.

If something goes wrong

We maintain a written incident response plan. If a confirmed security incident affects your data, we notify Amazon and you within 24 hours of discovery.

Incident Response Plan (PDF) · Security Incident Reporting (PDF)

What we don't claim

We are a small team and we do not hold a SOC 2 or ISO 27001 certification. What we offer instead is the list above, each item true of the running system today. If your business needs something we haven't covered, ask — we will answer specifically.

Report a vulnerability or ask a question

Email info@hivemindnestor.com. We reply to security reports within one business day.

Start a 14-day free trial — no card needed