Status distinction. This page separates what is deployed today from controls proposed for a future beta. Proposed controls are not represented as implemented, audited, or certified.
1 · Current state
- Public surface. holona.io is a static site delivered over HTTPS by Vercel.
- Application data. The beta form is disabled and has no configured submission endpoint.
- Amazon data. The public prototype is not connected to Seller Central, SP-API, Ads API, or customer marketplace data.
- Commercial data. The site has no customer account system, billing integration, or application database.
2 · Proposed beta readiness gates
Before handling seller data, the beta must implement and verify:
- least-privilege identity and role-based access;
- tenant isolation at storage, query, job, and audit boundaries;
- encryption in transit and at rest with documented key ownership;
- field-level data classification, retention, deletion, and export procedures;
- tamper-evident audit records for recommendations, approvals, and external actions;
- incident detection, escalation, notification, and recovery runbooks;
- vendor inventory and signed data-processing terms where applicable.
3 · Amazon data boundary
The intended path is official Amazon authorization only, with the smallest practical scopes and a read-only shadow phase before any write capability. No scraping, credential sharing, or browser automation is planned for seller-account access. OAuth revocation and deletion behavior must be tested before pilot onboarding.
4 · Verification before claims
Specific technologies, retention periods, regional residency, incident-notification windows, API headers, and certifications will be published only after they are implemented and evidenced by configuration, tests, or an independent review. Until then, homepage security language describes architecture targets.
5 · Contact
Security and architecture questions can be sent to contact@holona.io.