Effective August 14, 2026 · Version 1.0

Security

BroFam’s architecture separates application authorizations and workloads, limits access by purpose, encrypts protected information, uses finite retention and keeps Development and Production separate. Restricted shipping information is isolated from pricing workloads. These statements do not claim certification, completed audit or penetration testing.

Reporting a vulnerability

Email security@brofam.app with the affected service, steps to reproduce and potential impact. Do not access another seller’s data, degrade service, use social engineering, persist access or retain personal information. We will acknowledge and coordinate safe validation and remediation.

Safe handling

Never send credentials, access tokens, buyer messages or buyer PII by ordinary email. Use synthetic examples and wait for secure-transfer instructions if sensitive evidence is unavoidable.

Change history

Version 1.0 — initial disclosure/contact policy prepared August 14, 2026.