Skip to main content

Trust hub

Trust & Security

Digital Empire Holdings LLC · Last updated: August 20, 2026

Honest disclosure: Digital Empire Holdings LLC is a small, solo-founder-operated company. We do not hold an independent SOC 2, ISO 27001, or PCI DSS attestation as of August 20, 2026. We rely on the SOC 2 / PCI compliance of our infrastructure providers (Vercel, Supabase, Stripe) listed below. Independent audit is planned for Q2 2027 pending customer scale. If your procurement process requires an executed DPA or vendor security questionnaire before that, email support@digitalempireholdings.com and we'll respond within one business day.

Legal & policy documents

Every document is public and versioned. Because each product has product-specific data categories (pixel scan findings vs. HTS codes vs. importer submissions), privacy / terms / sub-processors / cookies each have a per-product version. The Data Processing Agreement (DPA) is portfolio-wide.

Product
Privacy
Terms
Sub-processors
Cookies
PixelProof
Meta pixel + GA4 + GTM monitoring for Shopify
Privacy
Terms
Sub-processors
Cookies
EntryProof
CPSC eFiling readiness for consumer-product importers
Privacy
Terms
Sub-processors
Cookies
TariffWatch
Section 232 metals exposure + comment-letter drafting
Privacy
Terms
Sub-processors
Cookies

Certifications & standards

Digital Empire Holdings LLC itself does not hold an independent SOC 2 Type II, ISO 27001, or PCI DSS attestation as of August 20, 2026. Instead, we run entirely on infrastructure providers who do — and who are contractually bound to those attestations under their own DPAs (linked in each per-product sub-processors page):

Roadmap: independent SOC 2 Type I engagement is scoped for Q2 2027, gated on customer scale — the audit cost only becomes justified past a revenue threshold. If your procurement blocks on an executed SOC 2 report today, we will provide our infrastructure providers' SOC 2 letters (via their trust portals) as an interim — email support@digitalempireholdings.com.

Sub-processors

Complete per-product lists (with each vendor's DPA + privacy-policy URL and the exact data categories they process): PixelProof · EntryProof · TariffWatch.

Vendor
Country / residency
DPA
Supabase, Inc.
US region (AWS us-east-1)
DPA · Privacy
Stripe, Inc.
US region (Stripe global infrastructure, PCI DSS Level 1)
DPA · Privacy
Resend, Inc.
US region
DPA · Privacy
Vercel Inc.
US region (primary), global edge network for static/cached assets
DPA · Privacy
PostHog Inc.
US region (us.i.posthog.com)
DPA · Privacy
Functional Software, Inc. (Sentry)
US region
DPA · Privacy
Apollo.io (Apollo Technologies, Inc.)
US region
DPA · Privacy

We will notify Enterprise customers 30 days in advance of adding a new sub-processor, giving you an opportunity to object per your DPA.

Data locations

EU / UK data-transfer basis: Standard Contractual Clauses (2021/914) executed with each US sub-processor. Full clause list in each per-product sub-processors page and in the DPA.

Encryption & access control

Data retention & deletion

Incident response

Company & contact

This trust hub is versioned; material changes are logged in /changelog. Nothing on this page constitutes legal advice or a warranty of any specific security outcome; the binding legal instruments are each product's Terms of Service and the DPA linked above.