Tradebox Tradebox Helpdesk

Latest version of Tradebox is V2.0.260730.0 published on 30/07/2026

Amazon SP-API Security Hardening Guide

To use the Amazon integration within Tradebox One, your business must comply with Amazon’s global Data Protection Policy (DPP). Because Tradebox is a local Windows desktop application, Amazon data is stored securely on your own hardware rather than our servers.

To satisfy Amazon’s strict compliance audits, your IT administrator or partner must ensure that every PC or local server running Tradebox or hosting its SQL Express database adheres to the following four endpoint security rules:

1. Turn on Full Disk Encryption (BitLocker)

All drives hosting Tradebox data must be encrypted to protect data at rest.

  • How to comply: In Windows, open Control Panel > BitLocker Drive Encryption and click Turn on BitLocker for your primary operating system and data drives (C:, etc.).

2. Restrict Local Administrator Privileges

Users should not log into Windows using full Administrator accounts for day-to-day work. This prevents unauthorized software or malware from altering your database or Tradebox service loops.

  • How to comply: Set up standard Windows user accounts for your team members. Reserve the Local Administrator account strictly for your IT management or software updates.

3. Enable Automated Screen Locks (Max 15 Minutes)

Devices must automatically lock when left unattended to prevent unauthorized physical access to customer order details.

  • How to comply: Go to Windows Settings > Accounts > Sign-in options > Dynamic Lock / Screen Timeout and set the device to turn off the display and lock automatically after a maximum of 15 minutes of inactivity.

4. Enforce USB / Removable Media Restrictions

To stop data leaks, your system must block users from copying database files or customer information onto loose USB flash drives or external hard drives.

  • How to comply: If you use Windows Pro or Enterprise, your IT team can enforce this via the Local Group Policy Editor (gpedit.msc) by navigating to Computer Configuration > Administrative Templates > System > Removable Storage Access and enabling “All Removable Storage classes: Deny all access”.

5. Implement Active Malware Protection & Automatic Updates

To protect downloaded Amazon order data from malicious actors or ransomware, all systems hosting Tradebox or the SQL Express database must run active endpoint protection.

  • How to comply: Ensure that Windows Security (Windows Defender) or a corporate-managed anti-malware alternative is fully active.
  • Enforce Updates: In Windows Settings, verify that Windows Update is set to automatically download and install definition updates. If your environment blocks automatic updates, updates must be run manually at least once per month.
  • Enable Tamper Protection: Ensure Tamper Protection is turned ON within your anti-virus software settings to prevent standard users or unauthorized scripts from disabling your malware defenses.