Trust center

Security at StorefrontShield

Security is the product, so our own controls should be understandable too. This page explains our current approach without exposing sensitive operational details.

Last reviewed June 23, 2026

Our security principles

Infrastructure and application controls

Data protection

Scan reports can reveal a merchant's technology and vendor footprint, so report files and raw inventories are not published. Rate-limit identifiers are stored as keyed cryptographic hashes rather than raw IP addresses, email addresses, or storefront domains in the application database. See our Privacy Policy for collection and retention details.

Scan boundaries

A free scan starts with the public URL submitted by an authorized user and may follow representative public product, collection, category, or cart links on the same storefront. It does not enter checkout or test passwords, payment forms, administrative interfaces, APIs, or vulnerabilities. External reputation sources can produce false positives or false negatives. The scan does not prove that a site is secure, and it may not observe scripts that require another location, consent choice, account state, or user interaction.

Responsible disclosure

If you believe you found a security vulnerability in StorefrontShield, email [email protected]. If that address is unavailable, use [email protected].

Please include a clear description, affected URL or component, reproduction steps, and potential impact. Do not access customer data, disrupt the service, use social engineering, perform denial-of-service testing, or publicly disclose an unresolved issue.

What to expect

We will acknowledge a credible report as soon as practical, investigate it, and communicate material progress when possible. We ask researchers to give us reasonable time to remediate before disclosure.

Current assurance status

StorefrontShield is an early-stage service. We do not currently claim SOC 2, ISO 27001, PCI assessor, penetration-test, or bug-bounty certification. We will update this page as independent assurance and formal policies are added.