← Trust and Compliance

Security and Vulnerability Disclosure Policy

Effective: September 28, 2026

Fromerica LLC is committed to keeping the information of exporters, buyers and professionals safe. This policy, based on the U.S. Cybersecurity and Infrastructure Security Agency (CISA) template, explains how to tell us about a security vulnerability, what research we authorize, and what you can expect from us.

1. Authorization

If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Fromerica LLC will not recommend or pursue legal action related to your research. If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will make this authorization known.

2. Guidelines

Under this policy, "research" means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent access, or pivot to other systems.
  • Stop testing and notify us immediately if you access personal data or another user's account, and do not keep, share or use that data.
  • Give us a reasonable time to fix the issue before you disclose it publicly.
  • Do not submit a high volume of low-quality reports.

3. Test methods that are not authorized

  • Network denial of service (DoS or DDoS) tests or any other test that impairs access to or damages a system or data.
  • Physical testing (for example, of office access).
  • Social engineering (for example, phishing or vishing) of Fromerica, its users or its service providers.
  • Automated scanning at a volume that affects other users. Our firewall temporarily blocks addresses that send attack patterns; please test at a low rate.

4. Scope

In scope:

  • www.fromerica.com (the website)
  • api.fromerica.com (the API, including the public API and the MCP connector at /mcp)

Out of scope: the services of our providers, such as Stripe, Google, Railway, GoDaddy (including the redirect of fromerica.com without "www") and Resend. Report issues in those services directly to the provider under its own program. Vulnerabilities found in systems from our vendors fall outside this policy's scope. If you are not sure whether a system is in scope, ask us first.

5. Reporting a vulnerability

Email info@fromerica.com with the subject "Security report". Our contact is also published in security.txt (RFC 9116). Reports may be written in English or Spanish and may be submitted anonymously.

Please include: where the vulnerability was found, its potential impact, and the technical details needed to reproduce it (steps, proof-of-concept code, screenshots). Do not send personal data you may have accessed.

Fromerica does not offer payment for reports at this time.

6. What you can expect from us

  • We will acknowledge your report within 3 business days, if you gave us a way to contact you.
  • We will confirm whether the vulnerability exists and keep you informed as we work on it.
  • Our remediation targets are: vulnerabilities being actively exploited or critical, within 7 days; high, within 30 days; medium, within 90 days; low, at our next planned change.
  • With your permission, we will credit you when we announce the fix.

7. Security checks we run on ourselves

  • On every code change: static analysis, automated tests, and known-vulnerability scans of our Go and JavaScript dependencies (govulncheck and npm audit). A change is not deployed unless the checks pass.
  • Every week: the official W3C HTML validator on our main pages, and an OWASP ZAP baseline scan (a passive scan by the Open Worldwide Application Security Project's standard tool) of the live site.
  • External ratings: the public results from SSL Labs, Mozilla Observatory, SecurityHeaders and SecurityScorecard are listed with live links on our Trust and Compliance page.

8. Questions and changes

Questions about this policy can be sent to info@fromerica.com. We may update this policy; the effective date above shows the latest version.