Inclusive ForgeCheck my storefront

Last updated 31 August 2026

Security and data handling

What we read from your storefront, what we keep, for how long, and how to tell us if you find a hole in any of it.

What we read

Public pages of your storefront, as an ordinary visitor sees them, plus a test item added to a cart to reach the checkout. We render the page, take a snapshot of its structure and a screenshot, and run the rules over the snapshot.

We do not sign in as one of your customers, we do not read orders, and we do not touch your database. The account page is scanned signed out.

What we store

WhatHow long
Findings and the journalWhile the account is open. The journal is never trimmed on our own: it is the evidence you may need years later
Screenshots of findingsWhile the account is open, then deleted with the account
Free-check resultsThirty days, then deleted automatically
Sign-in linksSingle use, and they expire whether used or not
Billing recordsAs long as tax law requires, held by the merchant of record

Your account has no password

Signing in is a one-time link that lives fifteen minutes and works once. There is no password to steal from you, reuse elsewhere or phish.

Our own operator console is a separate host and does have a password, plus a one-time code from an authenticator app. Saying otherwise here would be a claim we cannot keep.

Where it runs

On Cloudflare: the worker, the database and object storage. The storage bucket is created in the European jurisdiction, so screenshots of European storefronts stay in Europe.

Reporting a vulnerability

Write to support@inclusiveforge.com. Include what you did and what happened; a proof of concept helps but is not required.

WhatWhen
AcknowledgementWithin 3 working days
Initial assessment, with a severity and a planWithin 10 working days
Progress updates while the report is openAt least every 14 days
Credit in the fix noteUnless you would rather not be named

Safe harbour, and its edges

Research carried out in good faith under this policy will not be met with legal action from us. Stay on your own account and your own data, do not degrade the service for anyone else, and tell us before you tell anybody else.

Out of scope: denial of service, physical attacks, social engineering of our staff or our providers, and reports generated by a scanner with no evidence of impact.

We do not run a paid bounty. Promising money we have not budgeted would convert a helpful stranger into an aggrieved one, in public.