Vulnerability Disclosure Policy

Storefront Labs, LLC

Guidelines for responsible security research and coordinated vulnerability reporting.

Effective DateJuly 27, 2026
Applies ToSecurity Researchers and Reporters
Contacthello@storefrontworks.com

1. Purpose

Storefront Labs, LLC (“Storefront”) values the work of independent security researchers and others who help identify and responsibly report potential vulnerabilities affecting Storefront products, services, applications, websites, infrastructure, integrations, connected signs, devices, and related systems.

This consolidated Vulnerability and Security Disclosure Policy explains how to conduct good-faith security research, report suspected vulnerabilities, security incidents, abuse, or unauthorized access, and what reporters may expect from Storefront after submitting a report.

2. Scope

This policy applies to publicly accessible systems and services owned or operated by Storefront, including:

This policy does not authorize testing of systems, infrastructure, applications, accounts, or devices owned or controlled by Storefront customers, vendors, service providers, platform partners, or other third parties.

3. Good-Faith Research

Good-faith research. Storefront supports security research that is designed to identify vulnerabilities, avoids harm, respects privacy, and follows this policy.

Research is considered good faith when the researcher:

4. Authorized Testing

Researchers may test publicly accessible Storefront systems only to the extent reasonably necessary to confirm a suspected vulnerability and only when the testing:

Researchers should use accounts, data, devices, and environments they own or are expressly authorized to test.

5. Prohibited Activities

The following activities are not authorized:

6. Handling Customer Data

If you encounter personal data, customer content, confidential information, credentials, payment information, recordings, messages, location data, or other sensitive information, you must:

Minimize evidence. Reports should include only the information necessary to demonstrate the vulnerability. Do not include customer records, passwords, full payment-card numbers, private messages, recordings, or other sensitive data.

7. How to Report

Please send vulnerability reports, suspected security incidents, abuse reports, and reports of unauthorized access to:

Email: hello@storefrontworks.com

Use a clear subject line such as “Security Vulnerability Report.” For an active compromise, ongoing unauthorized access, imminent customer harm, or material risk of data loss, use the subject line “URGENT SECURITY INCIDENT.” If the report contains sensitive technical details, request a secure communication method before sending exploit code, credentials, or highly sensitive information.

8. What to Include

A useful report should include:

InformationExamples
Affected systemURL, endpoint, application, device model, firmware version, or feature.
Vulnerability descriptionType of issue, expected behavior, and observed behavior.
Reproduction stepsClear, minimal, sequential instructions that Storefront can repeat.
ImpactWhat an attacker could reasonably access, alter, disclose, or disrupt.
EvidenceSanitized screenshots, logs, request and response samples, or proof-of-concept details.
EnvironmentBrowser, operating system, device, account type, region, and relevant configuration.
Contact informationName or alias and a reliable method for follow-up.
Disclosure plansAny proposed publication date or coordination request.

Reports should describe one vulnerability per submission unless multiple issues are necessary to demonstrate a single attack chain.

9. Storefront Response Process

After receiving a report, Storefront will make commercially reasonable efforts to:

Response and remediation timing will vary based on severity, complexity, affected vendors, architectural dependencies, operational risk, and the availability of compensating controls.

10. Coordinated Disclosure

Researchers must not publicly disclose a vulnerability, proof of concept, technical details, screenshots, data, or communications until Storefront has confirmed remediation or has agreed in writing to a disclosure timeline.

Storefront may request additional time where remediation requires substantial architectural work, coordinated vendor action, customer updates, hardware replacement, firmware deployment, or other complex measures.

Public disclosure must not include confidential information, personal data, customer information, credentials, exploit code that creates unreasonable risk, or details that would materially increase the likelihood of abuse.

11. Safe-Harbor Statement

When a researcher acts in good faith, complies with this policy, avoids harm, and promptly reports the issue, Storefront does not intend to initiate legal action solely for the authorized research activity.

This statement does not:

If you are uncertain whether planned research is authorized, contact Storefront before proceeding.

12. Rewards and Recognition

Storefront does not currently operate a guaranteed bug-bounty program. Submission of a report does not create any right to payment, reimbursement, reward, or other compensation.

At Storefront’s discretion, Storefront may provide acknowledgment, public credit, merchandise, or another form of recognition for useful reports. Any recognition is voluntary and may depend on report quality, severity, originality, compliance with this policy, and whether the issue was previously known.

13. Limitations

This policy is informational and does not create warranties, service levels, audit rights, contractual obligations, or guarantees regarding response times, remediation, disclosure, recognition, or compensation.

Storefront may determine that a reported issue is low risk, accepted risk, intended behavior, duplicate, out of scope, dependent on a third party, or not reasonably exploitable.

14. Policy Changes

Storefront may update this policy as its products, systems, vendors, legal obligations, and security practices evolve. The current version will be identified by its effective date.

15. Contact Information

Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States

Email: hello@storefrontworks.com
Website: www.storefrontworks.com

Please do not send passwords, full payment-card numbers, private customer records, or other sensitive data in an initial report.

Last Updated: August 26, 2026