Verified implementation scope

Security & Trust Center

A factual view of the technical controls currently implemented in ForensiMark application code and server configuration. This page is not an independent certification, legal opinion, or guarantee that copying can be prevented in every circumstance.

Last updated: August 3, 2026

Reviewed scope

Application boundaries

Application authentication, storage, privacy, evidence, and legal workflow boundaries.

Last reviewed

August 3, 2026

Public claim standard

Only controls supported by current code or infrastructure configuration are listed.

Implemented controls

These controls are described narrowly. Their presence does not replace secure merchant configuration, operational monitoring, or independent security assessment.

01 · Encrypted transport

ForensiMark public domains use HTTPS. The current server configuration enables HTTP Strict Transport Security with a one-year max-age, and certificate renewal is managed by an active Certbot timer.

02 · Shopify authentication boundaries

Merchant administration routes require Shopify admin authentication. App Proxy and webhook routes use Shopify-specific public and webhook authentication boundaries rather than trusting browser-submitted identity.

03 · Cryptographic signing and secret handling

HMAC-SHA256 signatures, timing-safe comparisons, hashed identifiers, and public key fingerprints are used where implemented. Watermark key material is stored encrypted, and secret key ciphertext is not included in public evidence certificates.

04 · Private evidence storage

Images, evidence, videos, and DMCA artifacts are stored in private service-owned paths with restricted permissions. Authenticated evidence downloads use private no-store responses and content-type protection headers.

05 · Privacy lifecycle controls

The application implements merchant data export, customer redaction, shop deletion, uninstall handling, and Shopify privacy webhooks. Trial-abuse prevention retains only a non-reversible HMAC marker and usage counters without retaining the shop domain in that record.

06 · Tenant isolation and URL safety

Tenant-sensitive data access is scoped by shop identifiers. External image and evidence URLs pass public-HTTPS validation that rejects unsafe schemes, localhost, loopback, and private-network destinations.

07 · Evidence integrity

Technical reports and certificates use deterministic SHA-256 evidence digests. DMCA audit records form a tamper-evident hash chain, and submission attempts use idempotency controls.

08 · Human review before legal action

Search findings are presented as Potential Matches or review signals. AI analysis remains assistive, merchant review is mandatory, and no result automatically proves infringement or authorizes a takedown.

Data and privacy boundaries

The service minimizes public exposure of evidence and identity signals while retaining the records needed for merchant workflows.

Hashed network and browser indicators

Session, browser, and network indicators are represented through hashes or fingerprints in the implemented delivery workflow. Geographic reports explicitly do not store raw IP addresses.

Secret watermark material is not public evidence

Certificates may expose a non-secret key fingerprint, but never the secret watermark key ciphertext.

Authenticated merchant exports

Privacy exports, evidence downloads, ownership certificates, and free-audit reports require authenticated merchant access and use private no-store delivery headers.

Limits and non-claims

Transparent limitations are part of the security model and prevent technical signals from being presented as legal certainty.

No absolute prevention guarantee

Browser controls cannot completely prevent screenshots, cameras, cropping, recompression, or deliberate removal attempts.

Screenshot signals are not proof

Supported browser indicators may be recorded as possible capture signals. They cannot prove that a screenshot occurred.

Technical certificates are not government registration

An ownership evidence certificate records merchant-supplied identity and technical protection data. It is not a government copyright registration or proof of authorship by itself.

No unsupported compliance claims

This page does not claim SOC 2 or ISO 27001 certification, independent penetration-test completion, cyber-insurance coverage, end-to-end encryption, or guaranteed incident response.

Security reporting and documents

Installed merchants can open an authenticated support ticket from the in-app Support page. Public policy documents are available below.