Security and data handling
What we read from your storefront, what we keep, for how long, and how to tell us if you find a hole in any of it.
What we read
Public pages of your storefront, as an ordinary visitor sees them, plus a test item added to a cart to reach the checkout. We render the page, take a snapshot of its structure and a screenshot, and run the rules over the snapshot.
We do not sign in as one of your customers, we do not read orders, and we do not touch your database. The account page is scanned signed out.
What we store
| What | How long |
|---|---|
| Findings and the journal | While the account is open. The journal is never trimmed on our own: it is the evidence you may need years later |
| Screenshots of findings | While the account is open, then deleted with the account |
| Free-check results | Thirty days, then deleted automatically |
| Sign-in links | Single use, and they expire whether used or not |
| Billing records | As long as tax law requires, held by the merchant of record |
Your account has no password
Signing in is a one-time link that lives fifteen minutes and works once. There is no password to steal from you, reuse elsewhere or phish.
Our own operator console is a separate host and does have a password, plus a one-time code from an authenticator app. Saying otherwise here would be a claim we cannot keep.
Where it runs
On Cloudflare: the worker, the database and object storage. The storage bucket is created in the European jurisdiction, so screenshots of European storefronts stay in Europe.
Reporting a vulnerability
Write to support@inclusiveforge.com. Include what you did and what happened; a proof of concept helps but is not required.
| What | When |
|---|---|
| Acknowledgement | Within 3 working days |
| Initial assessment, with a severity and a plan | Within 10 working days |
| Progress updates while the report is open | At least every 14 days |
| Credit in the fix note | Unless you would rather not be named |
Safe harbour, and its edges
Research carried out in good faith under this policy will not be met with legal action from us. Stay on your own account and your own data, do not degrade the service for anyone else, and tell us before you tell anybody else.
Out of scope: denial of service, physical attacks, social engineering of our staff or our providers, and reports generated by a scanner with no evidence of impact.
We do not run a paid bounty. Promising money we have not budgeted would convert a helpful stranger into an aggrieved one, in public.