1. Purpose and Scope
This Security Overview & Trust Center describes the general administrative, technical, and operational safeguards used by Storefront Labs, LLC (“Storefront”) to protect its hosted software, connected services, customer information, and supporting infrastructure.
This document is intended to support customer, security, privacy, legal, and procurement review. It is an informational overview rather than a certification, audit report, warranty, or independent assurance statement.
2. Relationship to Other Documents
If this overview conflicts with an executed Order or other binding agreement, the binding agreement controls. This overview does not expand Storefront’s contractual obligations beyond those expressly accepted in writing.
3. Security Governance
Storefront maintains a risk-based security program intended to protect the confidentiality, integrity, and availability of the Services and information processed through them.
Security responsibilities may include:
- reviewing material risks and security events;
- maintaining security, privacy, incident-response, continuity, and access procedures;
- assigning access based on business need and least privilege;
- reviewing significant providers and subprocessors;
- maintaining reasonable workforce confidentiality obligations; and
- updating practices as products, threats, providers, and laws evolve.
4. Cloud Infrastructure
Storefront’s primary cloud infrastructure is hosted on Amazon Web Services (“AWS”). Storefront may also use other providers identified on its Subprocessors page.
| Area | General Approach |
|---|---|
| Environment | Cloud-hosted services and managed infrastructure selected according to product and operational needs. |
| Segmentation | Logical controls are used to separate accounts, permissions, services, or customer data where appropriate to the architecture. |
| Configuration | Infrastructure and service configurations are managed using commercially reasonable administrative and technical controls. |
| Availability | Redundancy, managed services, monitoring, and recovery capabilities may be used according to system criticality and design. |
5. Encryption and Data Protection
| Control Area | General Approach |
|---|---|
| Data in transit | Transport encryption, including TLS, is used where supported and appropriate. |
| Data at rest | Cloud-provider and application-level encryption capabilities may be used for stored information according to system and data type. |
| Credentials | Passwords are not intended to be stored in readable plaintext. Tokens, secrets, and credentials are protected using controls appropriate to their use. |
| Data minimization | Storefront seeks to collect and retain information reasonably necessary for service, legal, security, and operational purposes. |
Encryption does not eliminate all risk, and protection may depend on customer devices, networks, integrations, providers, and configuration.
6. Identity and Access Management
Storefront applies access controls intended to limit access to systems and data based on role, business need, and technical capability.
- unique accounts and authentication controls where appropriate;
- least-privilege access for administrative and operational functions;
- access removal or adjustment when responsibilities change;
- credential and secret-management practices appropriate to the system;
- administrative logging where supported; and
- periodic or event-driven review of material access.
Customers remain responsible for their own administrators, Authorized Users, roles, passwords, devices, integration credentials, and local access controls.
7. Application and Development Security
Storefront uses commercially reasonable practices intended to reduce software and configuration risk throughout development and operation.
Practices may include:
- source-code management and change control;
- peer or technical review for material changes where appropriate;
- dependency and package management;
- testing before production release;
- separation of development and production access where practicable;
- security updates and remediation based on risk; and
- controls intended to prevent unauthorized code or configuration changes.
8. Vulnerability Management
Storefront evaluates reported or identified vulnerabilities based on potential impact, exploitability, affected systems, available mitigations, and operational risk.
Storefront may use automated tools, provider alerts, dependency notices, internal review, customer reports, and responsible-disclosure submissions to identify issues.
Validated vulnerabilities are prioritized and addressed using commercially reasonable remediation, mitigation, monitoring, configuration, or provider-management measures.
9. Logging and Monitoring
Storefront may collect and review operational, authentication, application, infrastructure, device, integration, security, fraud, abuse, and diagnostic logs.
Monitoring is intended to support:
- availability and performance;
- error detection and troubleshooting;
- security-event identification and investigation;
- fraud and abuse prevention;
- capacity and reliability planning; and
- compliance and audit support where applicable.
10. Incident Response
Storefront maintains procedures intended to identify, investigate, contain, remediate, document, and recover from suspected security incidents.
Depending on the event, Storefront may:
- restrict credentials, accounts, devices, integrations, or traffic;
- preserve relevant evidence and logs;
- engage cloud, security, legal, insurance, or other providers;
- restore affected systems or data from available recovery sources;
- notify affected customers or authorities where required by law or contract; and
- perform post-incident review and corrective action.
Personal-data breach obligations are governed by applicable law and any privacy terms expressly included in an applicable Order.
11. Backups and Business Continuity
Storefront uses commercially reasonable backup, restoration, continuity, and recovery practices appropriate to the affected systems and data.
Recovery priorities and timing depend on system criticality, incident scope, data type, provider availability, technical feasibility, and customer impact.
Additional information is available in the Business Continuity & Disaster Recovery Policy.
12. Privacy and Data Processing
Personal information is processed under the Privacy Policy and applicable agreements.
Retention and deletion practices are described in the Data Retention & Deletion Policy. Customer privacy requests are addressed through the Customer Data Request Policy.
13. Subprocessors and Service Providers
Storefront relies on third-party providers for cloud hosting, communications, payment processing, AI, analytics, support, and integrations.
Representative providers and their purposes are listed on the Subprocessors page. Storefront considers factors such as security, privacy, reliability, technical capability, contractual protections, and operational fit when selecting material providers.
Third-party services remain independently operated and may experience outages, security events, policy changes, or other failures outside Storefront’s control.
14. Connected Hardware and Devices
Storefront hardware and connected features may depend on local power, Wi-Fi, Bluetooth, cellular service, GPS, NFC, UWB, routers, mobile devices, cameras, sensors, and customer-installed equipment.
Customers are responsible for physical security, safe installation, supported configuration, local networks, environmental conditions, firmware and application updates, and compliance with recording, surveillance, accessibility, and workplace requirements.
Hardware warranty and device obligations are governed by the Hardware Warranty and Connected Device Terms.
15. Shared Responsibility and Customer Controls
Storefront security depends in part on customer practices. Customers should:
- use strong, unique authentication credentials;
- limit administrator and Authorized User access;
- remove access promptly when no longer required;
- protect credentials, tokens, devices, networks, and integrations;
- maintain supported software, firmware, browsers, and operating systems;
- configure cameras, sensors, retention, messaging, and publishing appropriately;
- maintain independent copies of legally or operationally critical records; and
- report suspected compromise promptly.
16. Assurance, Certifications, and Limitations
Security controls, architecture, providers, and practices may change as Storefront evolves. Some technical details may be withheld where disclosure could create security, confidentiality, legal, or operational risk.
No security program can prevent every attack, error, outage, data loss, or unauthorized access.
17. Reporting Security Concerns
Security vulnerabilities, suspected compromise, unauthorized access, credential exposure, or related concerns should be reported promptly to hello@storefrontworks.com.
Security researchers should also review the Vulnerability Disclosure Policy before testing or publicly disclosing a potential vulnerability.
18. Changes to This Overview
Storefront may update this overview prospectively as products, providers, controls, risks, and legal requirements evolve. The current version will be identified by its effective date.
19. Contact Information
Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States
Security and procurement inquiries: hello@storefrontworks.com
Website: www.storefrontworks.com
Last Updated: August 26, 2026