1. Purpose
Storefront Labs, LLC (“Storefront”) values the work of independent security researchers and others who help identify and responsibly report potential vulnerabilities affecting Storefront products, services, applications, websites, infrastructure, integrations, connected signs, devices, and related systems.
This consolidated Vulnerability and Security Disclosure Policy explains how to conduct good-faith security research, report suspected vulnerabilities, security incidents, abuse, or unauthorized access, and what reporters may expect from Storefront after submitting a report.
2. Scope
This policy applies to publicly accessible systems and services owned or operated by Storefront, including:
- the Storefront Business Manager and Places applications;
- Storefront websites and customer-facing web services;
- Storefront-controlled integration endpoints;
- Storefront-connected signs, hardware, firmware, and device services;
- authentication, account, administrative, and customer portals; and
- other systems expressly identified by Storefront as in scope.
This policy does not authorize testing of systems, infrastructure, applications, accounts, or devices owned or controlled by Storefront customers, vendors, service providers, platform partners, or other third parties.
3. Good-Faith Research
Research is considered good faith when the researcher:
- acts to improve security rather than exploit or profit from unauthorized access;
- uses the least intrusive method reasonably available;
- avoids disruption, degradation, destruction, or interference;
- stops testing when customer data, confidential information, or sensitive systems may be exposed;
- reports findings promptly and privately;
- does not retain, use, disclose, or distribute data obtained during testing; and
- provides Storefront a reasonable opportunity to investigate and remediate before public disclosure.
5. Prohibited Activities
The following activities are not authorized:
- denial-of-service, distributed denial-of-service, load, stress, or resource-exhaustion testing;
- social engineering, phishing, vishing, smishing, pretexting, or impersonation;
- physical intrusion, theft, surveillance, or unauthorized access to offices, facilities, devices, or personnel;
- malware deployment, ransomware, destructive payloads, cryptomining, or persistent access;
- accessing, modifying, downloading, deleting, encrypting, or retaining customer or employee data;
- testing customer accounts, customer networks, customer devices, or customer-configured integrations without explicit authorization;
- testing third-party services, cloud providers, payment systems, social platforms, mapping services, email providers, or other vendor systems;
- credential stuffing, password spraying, brute-force attacks, or testing stolen credentials;
- spam, unsolicited messaging, or mass account creation;
- publishing vulnerability details before coordinated disclosure is complete;
- extortion, coercion, threats, or demands for payment; and
- any activity likely to cause harm, privacy invasion, financial loss, regulatory exposure, or service disruption.
6. Handling Customer Data
If you encounter personal data, customer content, confidential information, credentials, payment information, recordings, messages, location data, or other sensitive information, you must:
- stop testing immediately;
- avoid viewing, copying, downloading, modifying, transmitting, or retaining the data;
- notify Storefront promptly;
- delete any inadvertently retained copies after Storefront confirms they are no longer needed for investigation; and
- not disclose the existence or contents of the data to any third party.
7. How to Report
Please send vulnerability reports, suspected security incidents, abuse reports, and reports of unauthorized access to:
Email: hello@storefrontworks.com
Use a clear subject line such as “Security Vulnerability Report.” For an active compromise, ongoing unauthorized access, imminent customer harm, or material risk of data loss, use the subject line “URGENT SECURITY INCIDENT.” If the report contains sensitive technical details, request a secure communication method before sending exploit code, credentials, or highly sensitive information.
8. What to Include
A useful report should include:
| Information | Examples |
|---|---|
| Affected system | URL, endpoint, application, device model, firmware version, or feature. |
| Vulnerability description | Type of issue, expected behavior, and observed behavior. |
| Reproduction steps | Clear, minimal, sequential instructions that Storefront can repeat. |
| Impact | What an attacker could reasonably access, alter, disclose, or disrupt. |
| Evidence | Sanitized screenshots, logs, request and response samples, or proof-of-concept details. |
| Environment | Browser, operating system, device, account type, region, and relevant configuration. |
| Contact information | Name or alias and a reliable method for follow-up. |
| Disclosure plans | Any proposed publication date or coordination request. |
Reports should describe one vulnerability per submission unless multiple issues are necessary to demonstrate a single attack chain.
9. Storefront Response Process
After receiving a report, Storefront will make commercially reasonable efforts to:
- acknowledge receipt;
- evaluate whether the report is in scope and reproducible;
- request additional information when necessary;
- assess severity, exploitability, affected systems, and potential impact;
- develop and implement appropriate remediation or mitigation;
- keep the reporter informed when reasonably practicable; and
- confirm when the matter has been resolved or otherwise closed.
Response and remediation timing will vary based on severity, complexity, affected vendors, architectural dependencies, operational risk, and the availability of compensating controls.
10. Coordinated Disclosure
Researchers must not publicly disclose a vulnerability, proof of concept, technical details, screenshots, data, or communications until Storefront has confirmed remediation or has agreed in writing to a disclosure timeline.
Storefront may request additional time where remediation requires substantial architectural work, coordinated vendor action, customer updates, hardware replacement, firmware deployment, or other complex measures.
Public disclosure must not include confidential information, personal data, customer information, credentials, exploit code that creates unreasonable risk, or details that would materially increase the likelihood of abuse.
11. Safe-Harbor Statement
When a researcher acts in good faith, complies with this policy, avoids harm, and promptly reports the issue, Storefront does not intend to initiate legal action solely for the authorized research activity.
This statement does not:
- authorize conduct that violates applicable law;
- bind third parties, customers, vendors, regulators, or law enforcement;
- waive Storefront’s rights regarding activity outside the scope of this policy;
- protect extortion, theft, privacy invasion, service disruption, or misuse of data; or
- create a contract, employment relationship, agency relationship, or entitlement to payment.
If you are uncertain whether planned research is authorized, contact Storefront before proceeding.
12. Rewards and Recognition
Storefront does not currently operate a guaranteed bug-bounty program. Submission of a report does not create any right to payment, reimbursement, reward, or other compensation.
At Storefront’s discretion, Storefront may provide acknowledgment, public credit, merchandise, or another form of recognition for useful reports. Any recognition is voluntary and may depend on report quality, severity, originality, compliance with this policy, and whether the issue was previously known.
13. Limitations
This policy is informational and does not create warranties, service levels, audit rights, contractual obligations, or guarantees regarding response times, remediation, disclosure, recognition, or compensation.
Storefront may determine that a reported issue is low risk, accepted risk, intended behavior, duplicate, out of scope, dependent on a third party, or not reasonably exploitable.
14. Policy Changes
Storefront may update this policy as its products, systems, vendors, legal obligations, and security practices evolve. The current version will be identified by its effective date.
15. Contact Information
Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States
Email: hello@storefrontworks.com
Website: www.storefrontworks.com
Please do not send passwords, full payment-card numbers, private customer records, or other sensitive data in an initial report.
Last Updated: August 26, 2026