Security by boundary
Every storefront is treated as somebody else’s business.
Tenant isolation, least privilege, recent MFA for sensitive work, explicit provider evidence, immutable audit, and fail-closed launch gates are product requirements—not later hardening.
Identity
Confirmed email, strong password policy, non-enumerating recovery, staff MFA, and recent step-up for sensitive writes.
Tenancy
Platform, operator, storefront, and buyer roles are separate. Hostname selection is repeated in database authorization and never trusted as a tenant header.
Operations
Public, tenant-private, buyer-private, and platform-private surfaces are classified. Storage keys, jobs, webhooks, caches, exports, and audit carry tenant context.
Verification
The target is OWASP ASVS 5.0.0 Level 2 with automated evidence, independent review, and no compliance claim before proof.