Trust and Compliance
Last reviewed: September 28, 2026
Every statement on this page can be checked independently: each one links to its public source, and the test links run the check again live, so results can change over time. We only list facts we can show; we do not display seals or claim endorsements we do not have.
At a glance
| Check | Result | Verify |
|---|---|---|
| Florida company registration | Active (L26000422564) | Sunbiz · OpenCorporates |
| U.S. federal entity ID (SAM.gov) | UEI M5FPDS419RG5 | SAM.gov |
| HTTPS and encryption | A+ | Qualys SSL Labs |
| Web security headers | A+ · A+ | Mozilla Observatory · SecurityHeaders |
| Application security scan (OWASP ZAP, weekly) | 0 high · 0 medium | How we test |
| Vulnerability disclosure policy | CISA template, good-faith safe harbor | Policy · security.txt |
| Malware and blocklists | Clean | Google Safe Browsing · Sucuri · Norton |
| Tracking and third-party cookies | None found | Blacklight · Webbkoll |
| Sanctions and export compliance | Written program (OFAC framework, BIS guidelines) | Our policy |
| Fraud and money-laundering warning signs | Messages checked; recipients warned | Safety guide |
| Card payments | Stripe Checkout (PCI DSS Level 1) | Stripe |
| Accessibility (WCAG 2.2 A/AA) | 0 errors · Lighthouse 100 | Conformance report (VPAT® 2.5Rev, Section 508) |
| Self-assessments (CISA, NIST, OWASP, Canada) | 10 frameworks, October 2026 | Results |
| Valid HTML (W3C) | 0 errors on 29 pages | W3C validator |
| Speed (Google PageSpeed) | 96 mobile · 100 desktop | PageSpeed Insights |
1. Who we are
Fromerica LLC is a Florida limited liability company. Document number L26000422564, filed on August 10, 2026, status Active — verify it on the Florida Division of Corporations (Sunbiz), or in the independent open register OpenCorporates.
U.S. federal System for Award Management (SAM.gov): Unique Entity ID M5FPDS419RG5 — search it on SAM.gov (free sign-in required to view entity records).
Registered office: Registered Agents Inc., 7901 4th St N, Ste 300, St. Petersburg, FL 33702. Contact: info@fromerica.com.
Fromerica is an independent private company. It is not a government agency and is not affiliated with, or endorsed by, any of the agencies whose public data it uses.
2. Security: independent scans
Independent scans on September 27–28, 2026 (each link runs the test again, live):
- A+ on Qualys SSL Labs (HTTPS and encryption configuration) — see the result.
- A+ (110 points, 12 of 12 tests passed) on Mozilla HTTP Observatory (web security headers) — see the result.
- A+ on SecurityHeaders.com (browser security headers) — see the result.
- No unsafe content found on Google Safe Browsing, the system Chrome and other browsers use to warn about dangerous sites (checked for fromerica.com, www.fromerica.com and api.fromerica.com) — see the live status.
- No malware found and not blacklisted (9 blacklists checked) on Sucuri SiteCheck — see the live result.
- Rated Safe by Norton Safe Web — see the live rating.
- 0 high-risk and 0 medium-risk alerts in an OWASP ZAP baseline scan of the live site (the Open Worldwide Application Security Project's standard scanner, passive mode), run every week since September 28, 2026 — how we test ourselves.
- 0 errors on the official W3C HTML validator across 29 main pages (September 28, 2026) — validate the home page live.
- Our email domain is protected against spoofing with SPF, DKIM and DMARC, so messages that claim to come from fromerica.com but are not sent by us are rejected by the recipient's email provider (DMARC policy "reject").
- Our domain's DNS records are signed with DNSSEC, and CAA records limit which certificate authorities may issue certificates for fromerica.com.
3. Security: how we protect the site
- HTTPS everywhere with HTTP Strict Transport Security, a strict Content Security Policy (no inline scripts or styles allowed) and anti-framing and cross-origin isolation headers.
- Every code change is checked automatically before it goes live, including a scan for known vulnerabilities in the software libraries we use.
- Passwords are stored only as salted bcrypt hashes; administrator accounts require two-factor authentication.
- A web application firewall, rate limiting and tamper-evident security logs.
- Card payments are entered only on Stripe's hosted checkout page: we never receive or store card numbers. Stripe is certified as a PCI DSS Level 1 Service Provider, the highest level of the payment card industry standard — Stripe's security page. (This certification belongs to Stripe, not to Fromerica.)
- Daily encrypted database backups (AES-256-GCM), kept for 90 days.
4. Accessibility
We aim to conform to WCAG 2.2 Level AA. On September 27, 2026, our ten main pages (home, exporter and importer registration, search, tariffs, Schedule B, export statistics, market finder, tenders and this page) showed 0 errors and 0 contrast errors in WebAIM's WAVE — run it again on the home page — and 100 out of 100 for accessibility in Google Lighthouse.
- A "Skip to main content" link, visible keyboard focus and full keyboard operation.
- Pages that adapt to narrow screens (tested at 320 pixels) and to increased text spacing.
- Form fields with visible labels that declare their purpose, and a button to pause the home page background video.
The result for each of the 55 WCAG 2.2 A and AA criteria, including what is still only partially supported, is published in our Accessibility Conformance Report (based on VPAT® 2.5Rev, Revised Section 508 Edition). Automated tools do not catch every barrier; see our Accessibility Statement to report one.
5. Sanctions and export compliance
We maintain a written Sanctions and Export Compliance Program that follows the U.S. Treasury's framework for OFAC compliance commitments and the U.S. Department of Commerce's export compliance guidelines — read our policy. Screening records are kept for ten years. We also check messages between users for common signs of payment scams and trade-based money laundering and warn the recipient — see how to spot trade scams.
- Every registration and request for quote is checked against comprehensively sanctioned countries and regions and against the U.S. government's Consolidated Screening List; possible matches are held for review.
- Requests for quote to high-risk destinations (Russia, Belarus, Venezuela) carry an export-control warning for U.S. suppliers.
- Changes to a company or professional name or address are screened again, and a registration made from a connection located in a sanctioned country or region is reviewed by our Compliance Officer.
- A free restricted-party screening tool is available to everyone.
6. Your data
- We do not sell personal information and run no third-party advertising or tracking pixels; optional analytics run only with consent, and we honor Global Privacy Control (declared in gpc.json).
- Independent privacy scans on September 27, 2026: 0 ad trackers, 0 third-party cookies, no fingerprinting, no session recording, no keystroke capturing and no Facebook, TikTok, X or Google remarketing pixels on The Markup's Blacklight — see the result; and 0 cookies and 0 third-party requests on our home page in Webbkoll, a data-protection checker run by the 5th of July Foundation — see the result. Pages that show a map or a spam check load Google Maps or reCAPTCHA, as described in our Cookie Policy.
- Every marketing or alert email includes our postal address and a one-click unsubscribe from all optional emails (CAN-SPAM in the United States, CASL in Canada).
- Acceptance of our Terms and Privacy Policy is recorded with its date and version.
- Retention periods are published: see Privacy Policy, section 9.
Policies: Terms of Use · Privacy Policy · Cookie Policy · Copyright Policy · Accessibility Statement.
7. Official data sources
- U.S. import tariffs: U.S. International Trade Commission, Harmonized Tariff Schedule, checked daily.
- U.S. export statistics: U.S. Census Bureau. This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.
- Export codes: U.S. Census Bureau, Schedule B, updated monthly.
- Restricted parties: Consolidated Screening List (Departments of Commerce, State and the Treasury), updated daily.
- Freight forwarder licenses: Federal Maritime Commission list of Ocean Transportation Intermediaries, updated weekly.
- Tenders: World Bank Procurement Notices (CC BY 4.0), updated every 6 hours.
8. Public listings
- Our connector for AI assistants is published in the official MCP Registry as
com.fromerica.api/trade-data.
9. Self-assessments against public frameworks
We review Fromerica against public security and compliance frameworks by reading our own code and testing the live site, fix what we find, and record the gaps that remain with a date to close them. These are self-assessments made by Fromerica, not certifications or audits: none of these organizations has reviewed or endorsed Fromerica. We describe the detailed results on request to business users and partners at info@fromerica.com.
| Framework | Date | Result |
|---|---|---|
| CISA Cross-Sector Cybersecurity Performance Goals 2.0 | September 30, 2026, updated October 3, 2026 | 24 met, 5 partial, 1 in progress, 4 not applicable (34 goals) |
| NIST Cybersecurity Framework 2.0 (organizational profile) | September 30, 2026, updated October 3, 2026 | 19 achieved, 2 partial, 1 not yet (22 categories); current Tier 2, target Tier 3 by September 2027 |
| NIST Secure Software Development Framework (SP 800-218) | September 30, 2026, updated October 3, 2026 | 14 implemented, 5 partial (19 practices) |
| OWASP Application Security Verification Standard 5.0, Level 1 | October 2, 2026 | 60 met, 2 partial, 8 not applicable (70 requirements) |
| Canadian Centre for Cyber Security, Baseline Cyber Security Controls | October 2, 2026, updated October 3, 2026 | 33 met, 10 partial, 1 in progress, 2 not yet, 4 not applicable (50 controls) |
| OFAC Framework for Compliance Commitments | October 2, 2026 | 3 of 5 components met, 1 partial (no independent audit yet), 1 in progress (annual training) |
| Commercial email: CAN-SPAM (U.S.) and CASL (Canada) | October 2, 2026 | 13 met, 2 partial, 1 not applicable (16 requirements) |
| Price representations (no added mandatory fees) | October 2, 2026 | Every advertised price is the total charged; currency shown |
| Canadian Code of Practice for Consumer Protection in Electronic Commerce (used as a benchmark; we serve businesses) | October 2, 2026 | 22 met, 10 partial, 5 not applicable (37 clauses) |
| Ontario AODA and Accessible Canada Act (not legally applicable to us; followed voluntarily) | October 2, 2026 | 33 of the 38 WCAG 2.0 A/AA criteria supported, 3 partial (advertiser videos), 2 exempted |
Also published: our software bills of materials, signed and following CISA's 2026 minimum elements (backend · website), and our accessibility conformance report. Card payments are taken only on Stripe's hosted pages, which keeps Fromerica eligible for the shortest PCI DSS questionnaire (SAQ A); Stripe currently requires no PCI submission from our account.
10. Report a problem
Security issues, data errors, suspicious listings or accessibility barriers: info@fromerica.com. We aim to reply within 5 business days.
Security researchers: see our Vulnerability Disclosure Policy (based on the CISA template, with a good-faith safe harbor). Our contact is also published in security.txt, following the RFC 9116 standard.
