Skip to main content
Skip to content
Trust & Security

Your data lives on our machines

We own the servers, the network and the GPUs behind Shurq. Here is exactly how we protect your Amazon data, stated plainly, including what is still in progress.

We own the hardware

Your Amazon data is stored and processed on servers we own and operate, on our own private network. It does not sit on rented space inside a shared public cloud.

Our AI runs on our own GPUs

Most Shurq AI features run on models we host ourselves, on graphics hardware we own. Your numbers are answered in house rather than shipped to an outside model provider.

You hold the keys

We connect through Amazon's official authorization only. We never ask for or store your Seller Central password, and you can withdraw our access at any moment.

Table of Contents

1. Where We Stand Today

This page describes what we actually do to protect your data, not what we intend to do. We have written it plainly, including the parts that are still in progress, because a security page that overstates is worse than no security page at all.

GDPR / UK GDPRObligations apply today

We act as a processor for customer data. Our sub-processor register, Privacy Policy and Cookie Policy are published and kept current.

SOC 2Program in progress, not yet held

Our internal control program is being built to SOC 2 criteria. Only a licensed CPA firm can issue a SOC 2 report, and no report has been issued to us.

ISO 27001Not held

We do not hold ISO 27001 certification. Only an accredited certification body can grant it. We will publish here if that changes.

In short: we do not currently hold SOC 2 or ISO 27001 certification, and we will not imply otherwise. The controls described below are in place today.

2. We Run Our Own Infrastructure

Most analytics tools are a thin layer on top of somebody else's cloud. Shurq is not. We own and operate the machines your data lives on, we run our own network, and we run our own graphics hardware for the AI features. When we say your data is on our servers, we mean servers we bought, racked and administer.

2.1 What that changes for you

  • No shared tenancy for your data. Your Amazon reporting data is not sitting on multi tenant infrastructure alongside thousands of unrelated companies.
  • Your questions stay in house. Because we run our own models on our own GPUs, most AI answers are produced without your business data leaving our systems.
  • We control the whole path. Storage, processing, backups and the AI layer are all administered by our own team, so there is no third party quietly deciding how your data is handled.

2.2 What we do use from third parties

Being precise matters more here than sounding absolute. A small number of outside services sit at the edges of our system:

  • A content delivery and security network in front of our servers, which all web traffic passes through.
  • Email delivery and message queueing services.
  • A small number of AI providers used for specific features and as a fallback, described in section 8.

Each one is named in our sub-processor list together with exactly what it receives. If it is not on that list, it does not touch your data.

3. How We Connect to Amazon

We connect to Amazon exclusively through Amazon's official authorization process (OAuth). We never ask for, receive, or store your Seller Central username or password.

The authorization you grant is yours to withdraw. You can revoke Shurq's access at any time from within Seller Central or the Amazon Ads console, and our access ends immediately when you do.

4. Keeping Customer Data Separate

Every request for data is checked against the specific Amazon accounts your sign-in is authorized to see. If that check cannot be completed for any reason, the request is denied rather than allowed. The system fails closed, not open.

This applies to every surface equally: the dashboards, the reporting APIs, the AI assistant, and the connector that lets you query your data from external AI tools. Each is scoped to the accounts the signed-in user owns.

4.1 The AI connector

Our connector for external AI assistants uses a standard authorization flow with your own sign-in, is limited to read-only access, and returns only the accounts linked to your Shurq user. It can be disconnected from either side at any time.

5. Encryption

5.1 In transit

All traffic to and from Shurq is encrypted using TLS. Our application sends strict transport security headers, so browsers are instructed to refuse unencrypted connections to our domains.

5.2 At rest

Data stored by Shurq sits on encrypted infrastructure. Storage volumes and backups are encrypted at the platform level.

We describe this precisely rather than broadly, because "encrypted at rest" is often used to mean more than it does. Additional application-level encryption of stored Amazon authorizations is described in section 9.

6. Accounts & Access

  • Two-factor authentication is available on Shurq accounts, covering both password and Google sign-in.
  • Role-based access within organisations and teams determines which accounts and marketplaces a user can see.
  • Sensitive actions are logged to an audit trail, including changes made through the AI assistant.
  • Changes to your advertising made by our automation are recorded, attributable, and subject to limits you configure.

7. How We Test Our Own Security

We run in-depth reviews of our own code, including adversarial reviews whose explicit goal is to find ways in. Attempts to read another customer's data, bypass authorization, or reach data without signing in. Findings are triaged by severity and fixed, and the fixes are re-tested against the live system.

We have not yet commissioned a third-party penetration test. When we do, we will say so here.

8. AI Features & Your Data

Most of Shurq's AI features run on models we host on our own hardware, which means the data those features use does not leave our systems.

Some AI features use external model providers, either for specific capabilities or as a fallback if our own models are unavailable. Where they do, those providers are listed in our sub-processor list alongside what is sent to them. We do not send Amazon credentials or access tokens to any AI provider.

9. What We're Working On

We would rather tell you what is coming than imply it is already done. These are active, and this section will be updated as each lands:

  • A formal SOC 2 program, including independent audit.
  • Additional encryption of stored Amazon authorizations, so that they remain unreadable even to someone holding a copy of the underlying database.
  • Expanding database-level separation of customer data as a second layer beneath the application checks described in section 4.
  • A third-party penetration test.

10. Reporting & Incident Response

10.1 Telling us about a problem

If you believe you have found a security issue in Shurq, please tell us at [email protected]. Please include enough detail to reproduce the issue.

We will acknowledge your report, keep you updated while we investigate, and we will not pursue legal action against researchers who report issues in good faith, act only against their own account, and give us reasonable time to fix the problem before disclosing it.

10.2 Telling you about a problem

If a security incident affects your data, you will hear it from us. We notify affected customers without undue delay, and no later than 72 hours from the point we become aware of a personal data breach, with a named person accountable for running the response.

We would rather tell you early with an incomplete picture than tell you late with a tidy one, so an early notice may be followed by updates as we learn more.

11. Requesting Documentation

If your security or procurement team needs more than this page, such as a completed security questionnaire, a Data Processing Agreement, or details of our controls, contact [email protected] and we will respond directly. Some documentation is shared under NDA.

Security review or questionnaire?

Our team will work through it with you directly