← Back to home

Trust and Compliance

Last reviewed: September 28, 2026

Every statement on this page can be checked independently: each one links to its public source, and the test links run the check again live, so results can change over time. We only list facts we can show; we do not display seals or claim endorsements we do not have.

At a glance

CheckResultVerify
Florida company registrationActive (L26000422564)Sunbiz · OpenCorporates
U.S. federal entity ID (SAM.gov)UEI M5FPDS419RG5SAM.gov
HTTPS and encryptionA+Qualys SSL Labs
Web security headersA+ · A+Mozilla Observatory · SecurityHeaders
Application security scan (OWASP ZAP, weekly)0 high · 0 mediumHow we test
Vulnerability disclosure policyCISA template, good-faith safe harborPolicy · security.txt
Malware and blocklistsCleanGoogle Safe Browsing · Sucuri · Norton
Tracking and third-party cookiesNone foundBlacklight · Webbkoll
Sanctions and export complianceWritten program (OFAC framework, BIS guidelines)Our policy
Fraud and money-laundering warning signsMessages checked; recipients warnedSafety guide
Card paymentsStripe Checkout (PCI DSS Level 1)Stripe
Accessibility (WCAG 2.2 A/AA)0 errors · Lighthouse 100Conformance report (VPAT® 2.5Rev, Section 508)
Self-assessments (CISA, NIST, OWASP, Canada)10 frameworks, October 2026Results
Valid HTML (W3C)0 errors on 29 pagesW3C validator
Speed (Google PageSpeed)96 mobile · 100 desktopPageSpeed Insights

1. Who we are

Fromerica LLC is a Florida limited liability company. Document number L26000422564, filed on August 10, 2026, status Active — verify it on the Florida Division of Corporations (Sunbiz), or in the independent open register OpenCorporates.

U.S. federal System for Award Management (SAM.gov): Unique Entity ID M5FPDS419RG5 — search it on SAM.gov (free sign-in required to view entity records).

Registered office: Registered Agents Inc., 7901 4th St N, Ste 300, St. Petersburg, FL 33702. Contact: info@fromerica.com.

Fromerica is an independent private company. It is not a government agency and is not affiliated with, or endorsed by, any of the agencies whose public data it uses.

2. Security: independent scans

Independent scans on September 27–28, 2026 (each link runs the test again, live):

  • A+ on Qualys SSL Labs (HTTPS and encryption configuration) — see the result.
  • A+ (110 points, 12 of 12 tests passed) on Mozilla HTTP Observatory (web security headers) — see the result.
  • A+ on SecurityHeaders.com (browser security headers) — see the result.
  • No unsafe content found on Google Safe Browsing, the system Chrome and other browsers use to warn about dangerous sites (checked for fromerica.com, www.fromerica.com and api.fromerica.com) — see the live status.
  • No malware found and not blacklisted (9 blacklists checked) on Sucuri SiteCheck — see the live result.
  • Rated Safe by Norton Safe Web — see the live rating.
  • 0 high-risk and 0 medium-risk alerts in an OWASP ZAP baseline scan of the live site (the Open Worldwide Application Security Project's standard scanner, passive mode), run every week since September 28, 2026 — how we test ourselves.
  • 0 errors on the official W3C HTML validator across 29 main pages (September 28, 2026) — validate the home page live.
  • Our email domain is protected against spoofing with SPF, DKIM and DMARC, so messages that claim to come from fromerica.com but are not sent by us are rejected by the recipient's email provider (DMARC policy "reject").
  • Our domain's DNS records are signed with DNSSEC, and CAA records limit which certificate authorities may issue certificates for fromerica.com.

3. Security: how we protect the site

  • HTTPS everywhere with HTTP Strict Transport Security, a strict Content Security Policy (no inline scripts or styles allowed) and anti-framing and cross-origin isolation headers.
  • Every code change is checked automatically before it goes live, including a scan for known vulnerabilities in the software libraries we use.
  • Passwords are stored only as salted bcrypt hashes; administrator accounts require two-factor authentication.
  • A web application firewall, rate limiting and tamper-evident security logs.
  • Card payments are entered only on Stripe's hosted checkout page: we never receive or store card numbers. Stripe is certified as a PCI DSS Level 1 Service Provider, the highest level of the payment card industry standard — Stripe's security page. (This certification belongs to Stripe, not to Fromerica.)
  • Daily encrypted database backups (AES-256-GCM), kept for 90 days.

4. Accessibility

We aim to conform to WCAG 2.2 Level AA. On September 27, 2026, our ten main pages (home, exporter and importer registration, search, tariffs, Schedule B, export statistics, market finder, tenders and this page) showed 0 errors and 0 contrast errors in WebAIM's WAVE — run it again on the home page — and 100 out of 100 for accessibility in Google Lighthouse.

  • A "Skip to main content" link, visible keyboard focus and full keyboard operation.
  • Pages that adapt to narrow screens (tested at 320 pixels) and to increased text spacing.
  • Form fields with visible labels that declare their purpose, and a button to pause the home page background video.

The result for each of the 55 WCAG 2.2 A and AA criteria, including what is still only partially supported, is published in our Accessibility Conformance Report (based on VPAT® 2.5Rev, Revised Section 508 Edition). Automated tools do not catch every barrier; see our Accessibility Statement to report one.

5. Sanctions and export compliance

We maintain a written Sanctions and Export Compliance Program that follows the U.S. Treasury's framework for OFAC compliance commitments and the U.S. Department of Commerce's export compliance guidelines — read our policy. Screening records are kept for ten years. We also check messages between users for common signs of payment scams and trade-based money laundering and warn the recipient — see how to spot trade scams.

  • Every registration and request for quote is checked against comprehensively sanctioned countries and regions and against the U.S. government's Consolidated Screening List; possible matches are held for review.
  • Requests for quote to high-risk destinations (Russia, Belarus, Venezuela) carry an export-control warning for U.S. suppliers.
  • Changes to a company or professional name or address are screened again, and a registration made from a connection located in a sanctioned country or region is reviewed by our Compliance Officer.
  • A free restricted-party screening tool is available to everyone.

6. Your data

  • We do not sell personal information and run no third-party advertising or tracking pixels; optional analytics run only with consent, and we honor Global Privacy Control (declared in gpc.json).
  • Independent privacy scans on September 27, 2026: 0 ad trackers, 0 third-party cookies, no fingerprinting, no session recording, no keystroke capturing and no Facebook, TikTok, X or Google remarketing pixels on The Markup's Blacklight — see the result; and 0 cookies and 0 third-party requests on our home page in Webbkoll, a data-protection checker run by the 5th of July Foundation — see the result. Pages that show a map or a spam check load Google Maps or reCAPTCHA, as described in our Cookie Policy.
  • Every marketing or alert email includes our postal address and a one-click unsubscribe from all optional emails (CAN-SPAM in the United States, CASL in Canada).
  • Acceptance of our Terms and Privacy Policy is recorded with its date and version.
  • Retention periods are published: see Privacy Policy, section 9.

Policies: Terms of Use · Privacy Policy · Cookie Policy · Copyright Policy · Accessibility Statement.

7. Official data sources

  • U.S. import tariffs: U.S. International Trade Commission, Harmonized Tariff Schedule, checked daily.
  • U.S. export statistics: U.S. Census Bureau. This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.
  • Export codes: U.S. Census Bureau, Schedule B, updated monthly.
  • Restricted parties: Consolidated Screening List (Departments of Commerce, State and the Treasury), updated daily.
  • Freight forwarder licenses: Federal Maritime Commission list of Ocean Transportation Intermediaries, updated weekly.
  • Tenders: World Bank Procurement Notices (CC BY 4.0), updated every 6 hours.

8. Public listings

  • Our connector for AI assistants is published in the official MCP Registry as com.fromerica.api/trade-data.

9. Self-assessments against public frameworks

We review Fromerica against public security and compliance frameworks by reading our own code and testing the live site, fix what we find, and record the gaps that remain with a date to close them. These are self-assessments made by Fromerica, not certifications or audits: none of these organizations has reviewed or endorsed Fromerica. We describe the detailed results on request to business users and partners at info@fromerica.com.

FrameworkDateResult
CISA Cross-Sector Cybersecurity Performance Goals 2.0September 30, 2026, updated October 3, 202624 met, 5 partial, 1 in progress, 4 not applicable (34 goals)
NIST Cybersecurity Framework 2.0 (organizational profile)September 30, 2026, updated October 3, 202619 achieved, 2 partial, 1 not yet (22 categories); current Tier 2, target Tier 3 by September 2027
NIST Secure Software Development Framework (SP 800-218)September 30, 2026, updated October 3, 202614 implemented, 5 partial (19 practices)
OWASP Application Security Verification Standard 5.0, Level 1October 2, 202660 met, 2 partial, 8 not applicable (70 requirements)
Canadian Centre for Cyber Security, Baseline Cyber Security ControlsOctober 2, 2026, updated October 3, 202633 met, 10 partial, 1 in progress, 2 not yet, 4 not applicable (50 controls)
OFAC Framework for Compliance CommitmentsOctober 2, 20263 of 5 components met, 1 partial (no independent audit yet), 1 in progress (annual training)
Commercial email: CAN-SPAM (U.S.) and CASL (Canada)October 2, 202613 met, 2 partial, 1 not applicable (16 requirements)
Price representations (no added mandatory fees)October 2, 2026Every advertised price is the total charged; currency shown
Canadian Code of Practice for Consumer Protection in Electronic Commerce (used as a benchmark; we serve businesses)October 2, 202622 met, 10 partial, 5 not applicable (37 clauses)
Ontario AODA and Accessible Canada Act (not legally applicable to us; followed voluntarily)October 2, 202633 of the 38 WCAG 2.0 A/AA criteria supported, 3 partial (advertiser videos), 2 exempted

Also published: our software bills of materials, signed and following CISA's 2026 minimum elements (backend · website), and our accessibility conformance report. Card payments are taken only on Stripe's hosted pages, which keeps Fromerica eligible for the shortest PCI DSS questionnaire (SAQ A); Stripe currently requires no PCI submission from our account.

10. Report a problem

Security issues, data errors, suspicious listings or accessibility barriers: info@fromerica.com. We aim to reply within 5 business days.

Security researchers: see our Vulnerability Disclosure Policy (based on the CISA template, with a good-faith safe harbor). Our contact is also published in security.txt, following the RFC 9116 standard.