Security Overview & Trust Center

Storefront Labs, LLC

A customer-facing overview of Storefront’s security, privacy, resilience, and shared-responsibility practices.

Effective DateAugust 5, 2026
Primary HostingAmazon Web Services
Security Contacthello@storefrontworks.com

1. Purpose and Scope

This Security Overview & Trust Center describes the general administrative, technical, and operational safeguards used by Storefront Labs, LLC (“Storefront”) to protect its hosted software, connected services, customer information, and supporting infrastructure.

This document is intended to support customer, security, privacy, legal, and procurement review. It is an informational overview rather than a certification, audit report, warranty, or independent assurance statement.

2. Relationship to Other Documents

Supporting overview. This document supplements the Storefront Terms of Use, Privacy Policy, Business Continuity & Disaster Recovery Policy, Data Retention & Deletion Policy, Vulnerability Disclosure Policy, and Subprocessors page.

If this overview conflicts with an executed Order or other binding agreement, the binding agreement controls. This overview does not expand Storefront’s contractual obligations beyond those expressly accepted in writing.

3. Security Governance

Storefront maintains a risk-based security program intended to protect the confidentiality, integrity, and availability of the Services and information processed through them.

Security responsibilities may include:

4. Cloud Infrastructure

Storefront’s primary cloud infrastructure is hosted on Amazon Web Services (“AWS”). Storefront may also use other providers identified on its Subprocessors page.

AreaGeneral Approach
EnvironmentCloud-hosted services and managed infrastructure selected according to product and operational needs.
SegmentationLogical controls are used to separate accounts, permissions, services, or customer data where appropriate to the architecture.
ConfigurationInfrastructure and service configurations are managed using commercially reasonable administrative and technical controls.
AvailabilityRedundancy, managed services, monitoring, and recovery capabilities may be used according to system criticality and design.

5. Encryption and Data Protection

Control AreaGeneral Approach
Data in transitTransport encryption, including TLS, is used where supported and appropriate.
Data at restCloud-provider and application-level encryption capabilities may be used for stored information according to system and data type.
CredentialsPasswords are not intended to be stored in readable plaintext. Tokens, secrets, and credentials are protected using controls appropriate to their use.
Data minimizationStorefront seeks to collect and retain information reasonably necessary for service, legal, security, and operational purposes.

Encryption does not eliminate all risk, and protection may depend on customer devices, networks, integrations, providers, and configuration.

6. Identity and Access Management

Storefront applies access controls intended to limit access to systems and data based on role, business need, and technical capability.

Customers remain responsible for their own administrators, Authorized Users, roles, passwords, devices, integration credentials, and local access controls.

7. Application and Development Security

Storefront uses commercially reasonable practices intended to reduce software and configuration risk throughout development and operation.

Practices may include:

8. Vulnerability Management

Storefront evaluates reported or identified vulnerabilities based on potential impact, exploitability, affected systems, available mitigations, and operational risk.

Storefront may use automated tools, provider alerts, dependency notices, internal review, customer reports, and responsible-disclosure submissions to identify issues.

Validated vulnerabilities are prioritized and addressed using commercially reasonable remediation, mitigation, monitoring, configuration, or provider-management measures.

9. Logging and Monitoring

Storefront may collect and review operational, authentication, application, infrastructure, device, integration, security, fraud, abuse, and diagnostic logs.

Monitoring is intended to support:

10. Incident Response

Storefront maintains procedures intended to identify, investigate, contain, remediate, document, and recover from suspected security incidents.

Depending on the event, Storefront may:

Personal-data breach obligations are governed by applicable law and any privacy terms expressly included in an applicable Order.

11. Backups and Business Continuity

Storefront uses commercially reasonable backup, restoration, continuity, and recovery practices appropriate to the affected systems and data.

Recovery priorities and timing depend on system criticality, incident scope, data type, provider availability, technical feasibility, and customer impact.

Additional information is available in the Business Continuity & Disaster Recovery Policy.

No absolute recovery guarantee. Backups and recovery processes reduce risk but do not guarantee that every record, message, recording, configuration, or integration state can be restored.

12. Privacy and Data Processing

Personal information is processed under the Privacy Policy and applicable agreements.

Retention and deletion practices are described in the Data Retention & Deletion Policy. Customer privacy requests are addressed through the Customer Data Request Policy.

13. Subprocessors and Service Providers

Storefront relies on third-party providers for cloud hosting, communications, payment processing, AI, analytics, support, and integrations.

Representative providers and their purposes are listed on the Subprocessors page. Storefront considers factors such as security, privacy, reliability, technical capability, contractual protections, and operational fit when selecting material providers.

Third-party services remain independently operated and may experience outages, security events, policy changes, or other failures outside Storefront’s control.

14. Connected Hardware and Devices

Storefront hardware and connected features may depend on local power, Wi-Fi, Bluetooth, cellular service, GPS, NFC, UWB, routers, mobile devices, cameras, sensors, and customer-installed equipment.

Customers are responsible for physical security, safe installation, supported configuration, local networks, environmental conditions, firmware and application updates, and compliance with recording, surveillance, accessibility, and workplace requirements.

Hardware warranty and device obligations are governed by the Hardware Warranty and Connected Device Terms.

15. Shared Responsibility and Customer Controls

Storefront security depends in part on customer practices. Customers should:

16. Assurance, Certifications, and Limitations

No certification implied. Storefront does not represent through this document that it holds SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, or another certification or attestation unless Storefront separately confirms that status in writing.

Security controls, architecture, providers, and practices may change as Storefront evolves. Some technical details may be withheld where disclosure could create security, confidentiality, legal, or operational risk.

No security program can prevent every attack, error, outage, data loss, or unauthorized access.

17. Reporting Security Concerns

Security vulnerabilities, suspected compromise, unauthorized access, credential exposure, or related concerns should be reported promptly to hello@storefrontworks.com.

Security researchers should also review the Vulnerability Disclosure Policy before testing or publicly disclosing a potential vulnerability.

18. Changes to This Overview

Storefront may update this overview prospectively as products, providers, controls, risks, and legal requirements evolve. The current version will be identified by its effective date.

19. Contact Information

Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States

Security and procurement inquiries: hello@storefrontworks.com
Website: www.storefrontworks.com

Last Updated: August 26, 2026