Compliance and Trust Matrix

Storefront Labs, LLC

A consolidated reference mapping Storefront policies, controls, and customer responsibilities to common enterprise review areas.

Effective DateAugust 5, 2026
AudienceSecurity, Legal, Privacy, and Procurement Teams
Contacthello@storefrontworks.com

1. Purpose and Scope

This Compliance and Trust Matrix provides a high-level map of the policies, agreements, technical safeguards, and operational practices maintained by Storefront Labs, LLC (“Storefront”).

It is intended to support enterprise procurement, security review, privacy review, vendor due diligence, and contract administration. It does not create certifications, warranties, audit rights, or contractual obligations beyond those expressly stated in an executed agreement.

Reference document. The governing source for any commitment is the applicable signed Order, Terms of Use, or other executed agreement.

2. Governance and Contracting

Review AreaStorefront PositionPrimary Documents
Core service termsUse, fees, disclaimers, liability, arbitration, indemnification, and account rules are governed by Storefront’s master service terms and Orders.Terms of Use; Subscription Billing, Payment, and Refund Policy
Customer data processingPersonal information is processed as described in the Privacy Policy and any privacy terms expressly included in an applicable Order.Privacy Policy; applicable Order

3. Privacy and Data Protection

Control AreaStorefront ApproachPrimary Documents
Privacy noticesStorefront describes controller and business-purpose processing through its Privacy Policy.Privacy Policy
Processing obligationsProcessing obligations may be addressed through applicable Orders, the Privacy Policy, security practices, and subprocessor disclosures.Privacy Policy; Security Overview; Subprocessors
Retention and deletionData is retained for commercially reasonable periods based on service, legal, operational, security, and backup requirements.Data Retention and Deletion Policy
Cookies and trackingCookie, analytics, advertising, consent, browser, and mobile controls are described separately.Cookie Policy
SubprocessorsRepresentative providers are disclosed and may change subject to applicable contractual requirements.Subprocessors
Children and sensitive settingsCustomers are responsible for lawful authority, notices, consent, and configuration where the Services are used around children or regulated populations.Privacy Policy; Acceptable Use Policy; Accessibility Statement

4. Security Controls

Control FamilyRepresentative PracticesPrimary Documents
Cloud infrastructurePrimary hosting on AWS with managed cloud services and logical access controls.Security Overview and Trust Center; Security Overview
EncryptionIndustry-standard encryption in transit and appropriate encryption at rest where supported.Security Overview
Identity and accessLeast privilege, unique accounts, role-based controls where practicable, credential protection, and access revocation.Security Overview; Acceptable Use Policy
Monitoring and loggingOperational, authentication, integration, security, diagnostic, and abuse-related telemetry may be retained and reviewed.Security Overview; Data Retention and Deletion Policy
Vulnerability managementMaterial vulnerabilities are assessed and addressed based on risk and available mitigations.Vulnerability Disclosure Policy; Security Overview
Incident responseStorefront maintains procedures to investigate, contain, remediate, document, and communicate material incidents.Security Overview; Vulnerability Disclosure Policy
Responsible disclosureGood-faith security research may be reported through a coordinated disclosure process.Vulnerability Disclosure Policy

5. Resilience and Availability

AreaStorefront ApproachPrimary Documents
AvailabilityStorefront does not currently publish a contractual uptime target or service-credit program.Terms of Use
MaintenanceScheduled and emergency maintenance may occur.Terms of Use
BackupsBackup, replication, archive, or recovery mechanisms are used according to system criticality and operational need.Business Continuity and Disaster Recovery Policy; Security Overview
Continuity planningRecovery methods may include alternate infrastructure, provider substitution, restoration, manual procedures, and prioritized recovery.Business Continuity and Disaster Recovery Policy
Third-party dependenciesExternal cloud, telecommunications, AI, payment, mapping, and platform outages may affect service delivery.Terms of Use

6. AI and Automation

AreaStorefront ApproachPrimary Documents
AI transparencyAI features, provider dependencies, limitations, and customer review responsibilities are disclosed.AI Transparency and Responsible AI Policy; AI and Automated Decision-Making Policy
Human oversightCustomers must review outputs and maintain meaningful human oversight for consequential uses.AI Transparency and Responsible AI Policy; Acceptable Use Policy
Restricted usesStorefront AI may not be used as the sole basis for specified high-risk, safety-critical, or regulated decisions.AI and Automated Decision-Making Policy; Acceptable Use Policy
Third-party providersStorefront uses Anthropic for AI functionality, subject to product configuration and provider terms.AI Transparency and Responsible AI Policy; Subprocessors

7. Communications and Messaging

AreaStorefront ApproachPrimary Documents
Electronic consentAccount, billing, service, legal, security, and operational notices may be delivered electronically.Electronic Communications and Messaging Consent Policy
Commercial messagingCustomers must obtain required consent, honor opt-outs, maintain records, and comply with messaging laws.Electronic Communications and Messaging Consent Policy; Acceptable Use Policy
Delivery limitationsEmail, SMS, push, and in-app messages may be delayed, filtered, blocked, duplicated, or undelivered.Electronic Communications and Messaging Consent Policy
Message storageMessages may be stored for a reasonable period, but indefinite availability is not guaranteed.Data Retention and Deletion Policy; Electronic Communications and Messaging Consent Policy

8. Hardware and Connected Devices

AreaStorefront ApproachPrimary Documents
Limited warrantyStorefront-branded hardware is generally covered for defects in materials and workmanship for the stated warranty period.Hardware Warranty and Connected Device Terms
InstallationCustomers are responsible for safe, secure, code-compliant installation unless an Order states otherwise.Hardware Warranty and Connected Device Terms
ConnectivityHardware may depend on power, Wi-Fi, Bluetooth, cellular, GPS, NFC, UWB, local networks, and cloud services.Hardware Warranty and Connected Device Terms
Firmware and updatesStorefront may deploy remote updates to maintain security, compatibility, reliability, or functionality.Hardware Warranty and Connected Device Terms; Mobile Application EULA
Camera and audio privacyCustomers are responsible for lawful placement, signage, notices, consent, retention, and monitoring practices.Hardware Warranty and Connected Device Terms; Acceptable Use Policy

9. Intellectual Property

AreaStorefront ApproachPrimary Documents
Copyright complaintsStorefront maintains a notice and counter-notice process for copyright claims.Copyright and DMCA Policy
Trademark useStorefront marks may be used only as permitted by written authorization and brand guidelines.Trademark and Brand Usage Guidelines
FeedbackFeedback concerning Storefront products may be used, assigned, or licensed to Storefront as stated in applicable agreements.Terms of Use

10. Regulatory and Trade Compliance

AreaStorefront ApproachPrimary Documents
Government requestsRequests are reviewed for validity, scope, jurisdiction, notice restrictions, and legal sufficiency.Law Enforcement and Government Requests Policy
Export and sanctionsStorefront may screen, restrict, suspend, or terminate service to comply with export controls and sanctions.Export Control and Sanctions Compliance Policy
AccessibilityStorefront works toward accessible digital experiences and provides a channel for reporting barriers.Accessibility Statement
Records and retentionLegal holds, investigations, disputes, audit, tax, security, and regulatory obligations may extend retention.Data Retention and Deletion Policy

11. Customer Responsibilities

Storefront operates under a shared-responsibility model. Depending on the feature and deployment, customers are responsible for:

12. Limitations and Verification

No certification implied. This matrix does not represent that Storefront holds SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or other certification unless Storefront separately confirms that status in writing.

Controls, products, providers, architecture, and policies may change as Storefront evolves. Certain technical details may be withheld where disclosure would create security, confidentiality, legal, or operational risk.

Enterprise customers may submit reasonable follow-up questions to Storefront, subject to confidentiality, relevance, available resources, and applicable agreements.

13. Contact Information

Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States

Email: hello@storefrontworks.com
Website: www.storefrontworks.com

Last Updated: August 26, 2026