Announcement for Policy Update
Effective August 25, 2026, we’re updating the agreement and policies that govern how you use the Solution Provider Portal to strengthen security standards. These changes apply to all solution providers. Most formalize existing security expectations, but some may require updates to your current security controls.
What’s changing:
- The Data Protection Policy now requires a web application firewall for internet-facing endpoints, storage encryption on all devices, a 15-minute screen lock, and a 30-minute lockout after ten failed login attempts. You must also designate an Incident Management Point of Contact, encrypt all credentials at rest, delete information within 30 days when required, and meet expanded vulnerability scanning and penetration testing requirements, including for Application Programming Interfaces.
- The Solution Provider Portal Agreement clarifies that actions performed on behalf of customers are accurate, complete, and policy-compliant. We’ve also clarified when you must maintain insurance coverage and revised the Solution Provider Portal Agreement’s reference to the Agent Policy to remove redundancies.
- The Acceptable Use Policy now includes a quality and performance standard for submissions made on behalf of Authorized Users and expands the throttling-circumvention prohibition.
What you need to do:
- Review each policy before August 25, 2026 to understand how these updates apply to your business. To view the updated documents, go to Policies and Agreements.
- Please note that continued use of the Selling Partner API (SP-API) after August 25 means you accept the updated agreement and policies.
We appreciate your partnership in maintaining a secure environment for the customers we both serve.