Hijacked buy box
An unauthorised seller takes the buy box on your own listing. Your traffic converts into someone else's revenue, and nothing notifies you.
Buy box holder changed
For Amazon brands and their agencies
Hijacked buy boxes, suppressed listings, stockouts and price erosion cost you money quietly. Restitor watches your listings, prices each incident against your own unit economics, and produces a signed report you can send.
No card required to connect a source and declare your baselines. A subscription is what runs the analysis.
Buy box lost to an unauthorised seller
22 days open · 88 observations
sha256 4f9c…a17b · Ed25519
What this costs you
Your marketplace has no obligation to tell you that a listing stopped converting, or that the buy box on your own product now belongs to someone else. By the time it shows up in a weekly number, the window you could have evidenced has usually closed.
An unauthorised seller takes the buy box on your own listing. Your traffic converts into someone else's revenue, and nothing notifies you.
Buy box holder changed
The listing stops being buyable. Sessions continue, sales stop, and the gap only looks like ordinary softness in a weekly report.
Offer count fell to zero
Availability lapses on a product that was selling. The loss is the velocity you had, not the inventory you were holding.
Availability lost at observed velocity
Competing offers walk your price down. Each step is small, the cumulative margin is not, and no single day looks like an incident.
Sustained price decline
The method
Restitor is not a dashboard that asserts a number. Each stage produces something you can inspect, and the last one produces a document you can send.
Your seller IDs and marketplace.
The connection is tested against the real data provider before the source is marked ready. A saved string is never treated as a working connection.
Connection tested, then ready
Listings are watched on a schedule.
Every pass writes an immutable snapshot: buy box, price, availability, capture time. The raw response is stored content-addressed, so the record cannot drift from what was seen.
Snapshot, hashed and stored
Something changes, and an incident opens.
Four detectors watch for the losses that actually cost money. An incident carries its window — when it opened, how long it ran, and every observation inside it.
Incident opened with its window
The incident is priced against your own numbers.
Loss models use baselines you declare — your margin, your velocity — each recorded with a source. A baseline with no source is rejected, and the result is a range with a confidence band.
Range, with a confidence band
A document you can send.
Every figure on the report traces to a specific observation: source, SHA-256 digest, capture time. The report itself is signed with Ed25519, so a recipient can verify it was not altered.
Signed, and independently verifiable
The output
A quantified finding, backed by the observations that establish it — rendered here with the same components the workspace uses, so this is the real output shape. Figures are an example, not live data.
Example output — illustrative figures, not live data
PublishedDetected on a listing in your protected catalogue, open for 22 days before it was closed.
Every number on a real report traces back to a specific observation: source URL, SHA-256 digest and capture time. Nothing is asserted that cannot be shown.
The honest part
Financial clarity
A product that blends a modelled estimate into a recovered total is easier to sell and impossible to defend. Restitor keeps them in separate columns, in the database and on the page.
Observed fact
88 observations
What was seen, when it was seen, and the digest of the response it came from. Not inferred, not modelled — recorded.
Modelled estimate
€11,200 – €25,900
What the incident plausibly cost, computed from baselines you declared. A range with a confidence band, because that is what the underlying data supports.
Recorded outcome
€0 until it happens
What a marketplace actually paid, entered when it is paid and with its source. The only money in the product that describes something that already occurred.
There is no combined figure anywhere in the product, because there is no honest way to add a thing that happened to a thing that was modelled.
Why it is different
The constraints below are not positioning. They are enforced in code, and each one costs Restitor something to keep.
Pricing
Running an analysis is the paid operation — it spends marketplace data quota and produces a report. Everything you have already established stays readable whatever happens to the subscription.
This deployment
No payment provider is configured for this deployment, so there is nothing to purchase and nothing is charged. The product itself is fully functional — how this workspace is licensed is a question for whoever operates it.
Set up a workspaceWithout a subscription
The line is drawn at new work, not at access. Nothing you have already established is withheld — including after a subscription ends.
Enforced in one place: a single paid boundary in the entitlement model, checked before an analysis starts and before scheduled work spends provider quota.
Full detail on what a subscription includes is on the pricing page.
Before you decide
No. You can create a workspace, invite your team, connect your seller account, have the connection genuinely tested against the data provider, and declare your baselines — all without paying. Starting an analysis is the point at which a subscription is required.
From baselines you declare yourself — your margin, your conversion, your unit economics — each recorded with a source. Restitor does not guess them, and a baseline submitted without a source is rejected. Your figures are scoped to your organization and are never visible to another customer.
It says so. An incident with too little underlying data is reported as insufficient rather than given a number, and an estimate always carries the confidence band its observations support. There is no setting that turns a weak finding into a confident one.
No. Observations come from an API-licensed data provider, which is what makes the evidence chain usable in a conversation with a marketplace or a finance team. Every snapshot records its source and capture time.
New analyses pause. Every report, opportunity, recorded outcome and evidence chain you already have stays available and readable. Your recovered-revenue record is yours — withholding it to apply commercial pressure is not something the product does.
The EU. Observations come from an API-licensed marketplace data provider rather than scraping, evidence is stored content-addressed and immutable, and reports are signed with Ed25519 so a recipient can verify the document was not altered.
Connect a seller account, declare the baselines your loss models should use, and Restitor will tell you what it can substantiate — and say so plainly when it cannot.
No card required to connect a source and declare your baselines.