Caleffi Price Manager
Our commitment to protecting your data
Caleffi Price Manager, operated by Caleffi SPA, implements industry-leading security standards to protect your sensitive business data and Amazon Seller credentials. Our multi-layered security approach ensures your information remains confidential, available, and protected against unauthorized access.
All stored data is encrypted using AES-256 (Advanced Encryption Standard), the same encryption standard used by governments and financial institutions worldwide.
All data transmitted between your browser, our servers, and Amazon SP-API is protected with TLS 1.3:
Your Amazon credentials are never stored on our servers. We use Amazon's official OAuth 2.0 flow to obtain secure refresh tokens that are encrypted and stored separately from other data.
Admin accounts are protected with Time-based One-Time Passwords (TOTP) using industry-standard authenticator apps like Google Authenticator or Authy.
Principle of least privilege: Users and processes only have access to the minimum data and operations required for their function.
HTTP-only, secure cookies with short expiration times. Sessions are invalidated after 24 hours of inactivity.
Hosted on Microsoft Azure with industry-leading security certifications:
All user inputs are validated and sanitized to prevent injection attacks (SQL, XSS, CSRF)
Automated security scanning with GitHub Advanced Security and SonarQube
Automated vulnerability scanning with Dependabot; dependencies updated weekly
API rate limiting (100 req/min per IP) and Cloudflare DDoS mitigation
All API calls, authentication attempts, and price changes logged for audit trails
Full compliance with EU General Data Protection Regulation (GDPR):
Real-time monitoring with Azure Security Center, automated alerts for suspicious activity, and immediate response protocols.
AI-powered threat detection with Azure Sentinel, behavioral analysis, and automated blocking of malicious IPs.
Documented incident response procedures with defined escalation paths, containment strategies, and user notification protocols.
All third-party services undergo security review and are bound by Data Processing Agreements (DPAs):
All providers are SOC 2 Type II certified and GDPR compliant.
To maintain security, you should:
If you discover a security vulnerability, please report it responsibly:
Security Team: security@caleffionline.it
PGP Key: Available on request
Response Time: 24 hours for critical issues
We appreciate responsible disclosure and will acknowledge security researchers in our hall of fame.
Audited annually
Information Security
EU Compliant
Our security practices are continuously reviewed and improved to meet evolving threats and regulatory requirements.
Last security audit: January 2026 | Next audit: July 2026