Trust hub
Trust & Security
Digital Empire Holdings LLC · Last updated: August 20, 2026
Legal & policy documents
Every document is public and versioned. Because each product has product-specific data categories (pixel scan findings vs. HTS codes vs. importer submissions), privacy / terms / sub-processors / cookies each have a per-product version. The Data Processing Agreement (DPA) is portfolio-wide.
- Data Processing Agreement (DPA): /dpa — GDPR Art. 28, UK GDPR, CCPA/CPRA service-provider terms, EU SCCs (2021/914). Portfolio-wide, v0 pending attorney review; countersigned copy available on request.
- Security posture: /security — controls summary, scope, PGP key.
- Coordinated vulnerability disclosure: /security-disclosure — RFC 9116 security.txt, safe-harbor terms, researcher acknowledgments at /hall-of-fame.
- Portfolio cookie policy: /cookie-policy — categories, consent mechanics, per-product supplements.
- Refund policy summary: money-back available per each product's Terms of Service (§3.4 in each). See PixelProof Terms, EntryProof Terms, and TariffWatch Terms.
- Corrections policy: /corrections. Editorial policy: /editorial-policy.
- Public status page: /status.
Certifications & standards
Digital Empire Holdings LLC itself does not hold an independent SOC 2 Type II, ISO 27001, or PCI DSS attestation as of August 20, 2026. Instead, we run entirely on infrastructure providers who do — and who are contractually bound to those attestations under their own DPAs (linked in each per-product sub-processors page):
- Vercel (hosting, edge network, TLS termination): SOC 2 Type II. See vercel.com/security.
- Supabase (primary database, auth, storage): SOC 2 Type II. See supabase.com/security.
- Stripe (billing, checkout, card tokenization): PCI DSS Level 1 (highest merchant tier). We never see, store, or transmit raw card numbers — all payment fields are hosted in Stripe-served iframes. See stripe.com/docs/security.
- Resend (transactional email): SOC 2 Type II. See resend.com/legal/security.
Roadmap: independent SOC 2 Type I engagement is scoped for Q2 2027, gated on customer scale — the audit cost only becomes justified past a revenue threshold. If your procurement blocks on an executed SOC 2 report today, we will provide our infrastructure providers' SOC 2 letters (via their trust portals) as an interim — email support@digitalempireholdings.com.
Sub-processors
Complete per-product lists (with each vendor's DPA + privacy-policy URL and the exact data categories they process): PixelProof · EntryProof · TariffWatch.
We will notify Enterprise customers 30 days in advance of adding a new sub-processor, giving you an opportunity to object per your DPA.
Data locations
- Primary application database (Supabase): AWS
us-east-1(N. Virginia). Encrypted at rest. - Hosting & serverless compute (Vercel): US region primary; static assets served via Vercel's global edge network (edge cache holds compiled HTML + public assets only, never customer PII).
- Payments (Stripe): Stripe global PCI-DSS-scoped infrastructure. Card data is tokenized at collection and never traverses our servers.
- Transactional email (Resend): US region.
EU / UK data-transfer basis: Standard Contractual Clauses (2021/914) executed with each US sub-processor. Full clause list in each per-product sub-processors page and in the DPA.
Encryption & access control
- Encryption in transit: TLS 1.3 (or TLS 1.2 fallback), terminated at Vercel's edge for the application and at Stripe's edge for payment fields. HSTS enforced site-wide.
- Encryption at rest: AES-256 via Supabase (Postgres storage + managed backups) and Vercel (build artifacts, deployment logs).
- Admin access: two-factor authentication required on all admin accounts (Vercel, Supabase, Stripe, GitHub, Resend). Role-based access control on Supabase Row-Level Security policies is enforced per user for every table containing customer data.
- Secrets management: production secrets stored in Vercel encrypted environment variables; no secrets in source control.
- Development access: single-founder engineering. Any AI-assisted code changes run in isolated developer contexts; no customer runtime data is fed to any third-party LLM (see the no-runtime-LLM disclosure on each per-product sub-processors page).
Data retention & deletion
- Email addresses (marketing / newsletter): retained until you unsubscribe. Every marketing email carries a one-click unsubscribe (RFC 8058) plus a footer link. Unsubscribed addresses move to a suppression list — the record persists (so we don't re-mail you) but is not used for outreach.
- Account & product data: retained for the life of the subscription plus a 30-day grace period after cancellation for reactivation. Scan results, submissions, and account records are then deleted or hard-anonymized.
- Billing & order data (Stripe + our records): retained for seven (7) years post-transaction to meet U.S. federal / state accounting and tax-audit requirements (26 U.S.C. §6001, state analogues).
- Application logs: Vercel edge / function logs (which may contain IP addresses and request metadata) roll off per Vercel's standard retention (typically 24 hours to 30 days depending on plan).
- Deletion requests: email support@digitalempireholdings.com from your account email (or with account verification). We honor full-deletion requests within 30 days per CCPA / CPRA / GDPR SLA, subject only to billing records we're legally required to retain (above).
Incident response
- Detection: Sentry (application errors) + Vercel platform alerts + Supabase auth-log review. Anomaly triage is on-call by the founder.
- Notification SLA: in the event of a personal-data breach affecting EU / UK data subjects, we will notify the relevant supervisory authority within 72 hours of becoming aware per GDPR Art. 33, and notify affected data subjects without undue delay per Art. 34 where the breach is likely to result in a high risk to their rights and freedoms.
- State-law notifications (US): we will comply with the specific timing and content requirements of each affected state's breach-notification statute (e.g. CCPA / CPRA, N.Y. GBL §899-aa, Cal. Civ. Code §1798.82).
- Report a suspected incident: security@argushq.ai (PGP key at /pgp-key.txt) — researcher safe-harbor terms and response-time commitments live at /security-disclosure.
Company & contact
- Legal name: Digital Empire Holdings LLC
- Jurisdiction: Wyoming, USA
- Registered address: 30 N Gould St Ste N, Sheridan WY 82801
- General & privacy contact: support@digitalempireholdings.com
- Security contact: security@argushq.ai (see /.well-known/security.txt)
- Enterprise procurement: support@digitalempireholdings.com — typical turnaround one business day on vendor security questionnaires and DPA countersign requests.
This trust hub is versioned; material changes are logged in /changelog. Nothing on this page constitutes legal advice or a warranty of any specific security outcome; the binding legal instruments are each product's Terms of Service and the DPA linked above.