SECURITY · UPDATED 2026-08-14
How we hold your key.
Your DROP key is the most sensitive thing you give us. This page says exactly what happens to it, in plain English. When any line stops being true, we change it here that day.
- AT REST
- Encrypted with AES-256 before it is written. The decryption key lives in a separate managed keystore, not in our database and not in our code.
- IN TRANSIT
- TLS 1.2 or better on every call: yours to us, ours to DROP.
- WHO SEES IT
- Nobody at DropDue. It is decrypted only inside the job that calls DROP, and it is never shown back to you or to us after you paste it. Every use is written to your audit log.
- WHAT WE STORE
- Hashed identifiers, match results, and the status files you confirmed. Your records stay in your systems. We never ask for the raw data.
- WHEN YOU LEAVE
- Delete the key in Data sources, or cancel, and it is purged immediately. Automated pulls stop the same minute. Your audit log and past exports stay readable.
- ON PAPER
- A Data Processing Addendum carrying the service-provider terms California requires is presented at signup. Not on request, not after a sales call.
Who else touches it.
- Vercel
- Application hosting
- Railway
- Background job processing
- Neon
- Database hosting
- Amazon Web Services
- Key management
- Cloudflare
- Object storage and outbound email
- Postmark
- Inbound email parsing
- Stripe
- Payments
We announce a material change to this list here before it takes effect. Every one of them is bound to the same restrictions we accept in the DPA.
No SOC 2 report yet.
It is on the roadmap. Until an auditor has signed one we will not imply otherwise, and we will not list a control on this page that we have not actually built. The day that changes, this page says so first.
Security questions, or something you think we got wrong: security@dropdue.com. We answer these ourselves.
Read the DPA →Terms →Privacy →
DropDue is not affiliated with the CPPA. Not legal advice.