Security by boundary

Every storefront is treated as somebody else’s business.

Tenant isolation, least privilege, recent MFA for sensitive work, explicit provider evidence, immutable audit, and fail-closed launch gates are product requirements—not later hardening.

Identity

Confirmed email, strong password policy, non-enumerating recovery, staff MFA, and recent step-up for sensitive writes.

Tenancy

Platform, operator, storefront, and buyer roles are separate. Hostname selection is repeated in database authorization and never trusted as a tenant header.

Operations

Public, tenant-private, buyer-private, and platform-private surfaces are classified. Storage keys, jobs, webhooks, caches, exports, and audit carry tenant context.

Verification

The target is OWASP ASVS 5.0.0 Level 2 with automated evidence, independent review, and no compliance claim before proof.