// trust

Trust and product assurance

Specific controls and evidence, without a decorative wall of compliance logos.

Product validation

Each kit has an automated validation workflow in its product repository. Product pages prefer the latest owner-approved CI evidence. If current machine-readable totals are unavailable, the page labels older screenshots as archival rather than presenting unknown counts as zero.

Storefront regression coverage

The public storefront is checked across desktop and mobile browser projects for route availability, navigation, product discovery, live checkout links, sitemap coverage, and key interaction behavior. Checkout tests do not submit production transactions.

Purchase and account controls

  • Lemon Squeezy provides hosted payment processing; card data is not collected by this application.
  • Webhook signatures are verified before order records are processed.
  • Customer authentication uses short-lived, one-time email links and hashed session tokens.
  • Administrative APIs require an authenticated account on an explicit allow-list.
  • Refund events are retained separately from original purchase records for reconciliation.

Data and email controls

Subscription status is stored separately from lead data. An unsubscribed address is not silently reactivated by a later form submission. Delivery records prevent the same nurture step from being sent repeatedly. Automated nurture delivery is disabled until campaign content and scheduling are approved.

Third-party dependencies

The site and kits depend on third-party runtimes, test frameworks, browsers, APIs, and hosted services. Validation reduces compatibility risk but cannot eliminate upstream outages or breaking changes. Product pages identify the supported stack; buyers should test upgrades in their own environment.

Security reporting

Do not include secrets or exploit details in a public channel. Use the contact page, select the closest relevant topic, and clearly mark the message as a security report. Reports are reviewed before public disclosure.

Compliance status

No SOC 2, ISO 27001, PCI certification, or independent penetration-test claim is made by automationframework.dev. Payment-card processing is delegated to the merchant of record. This page describes implemented controls, not a certification.