Skip to main content

Security and marketplace access

How Fulfillio connects to your sales channels, what it holds, and how you stay in control of it.

Security in one paragraph

Fulfillio connects to marketplaces through their own authorisation flows rather than by storing your marketplace passwords. Credentials and access tokens are encrypted in transit and at rest, access inside a workspace is governed by role-based permissions, and because the connection is authorised on the marketplace you can revoke it from the marketplace at any time without going through us.

Authorisation, not passwords

eBay, Amazon, Shopify and Etsy are connected by signing in or authorising on the marketplace itself — eBay seller sign-in (OAuth), Amazon SP-API authorisation in Seller Central, a Shopify app install on your store domain, Etsy OAuth sign-in. Your marketplace password is never entered into Fulfillio.

Encrypted credentials

The tokens and credentials that keep a connection alive are encrypted in transit and at rest. Channels that authenticate with API client keys instead of a sign-in flow, such as Walmart Marketplace, are handled the same way.

Role-based access

Workspaces have user management with role-based permissions, so packing staff, operations leads and finance users each get the access their job needs rather than a shared login with the keys to everything.

You stay in control

Revoking access

Because every connection is authorised on the marketplace, it is also cancelled there. You do not need to raise a ticket with us to cut a connection.

  • Amazon — withdraw the SP-API authorisation in Seller Central
  • eBay and Etsy — revoke application access from your account settings
  • Shopify — uninstall the app from your Shopify admin
  • Walmart — rotate or revoke your Marketplace API client keys
FAQ

Security questions

No. Fulfillio connects through each marketplace's own authorisation flow — signing in with your eBay, Etsy or Amazon Seller Central account, or installing the app on your Shopify store. Your marketplace password is entered on the marketplace, not in Fulfillio, and is never stored by us.

The access tokens and credentials that authorise a connection are encrypted in transit and at rest. Where a channel uses API keys rather than a sign-in flow — Walmart, for example — those keys are handled the same way.

Yes, and you do not need us to do it. Because access is granted through the marketplace, it can be withdrawn from the marketplace: revoke the authorisation in Seller Central, eBay, Etsy or your Shopify admin, or rotate your Walmart API client keys. Access stops immediately.

Access inside a workspace is governed by role-based permissions, so warehouse staff, operations leads and finance users can be given the access their role needs rather than everything.

You do. Fulfillio processes your data to run the service on your behalf, as set out in the privacy policy and terms.

Fulfillio does not currently claim any formal security certification or audit attestation. The practices described on this page — authorisation-based connections, encrypted credentials, role-based access — are what is in place today. If you need specific assurances for a procurement process, contact the RASCODEX team directly.

Questions your security team needs answered?

Talk to the RASCODEX engineers who build Fulfillio — not a support script.

Contact the team WhatsApp Us