Skip to main content
Driftstack DRIFTSTACK

Security overview

This page is the entry point for a security review of Driftstack. It links out to the concrete controls + policy pages; this document is a map, not an exhaustive specification. For the contract-grade detail (SOC2 reports, pen-test summaries) reach out to [email protected].

Data handling

Authentication + authorization

Network + infrastructure

Browser sandbox

Sub-processors

A full sub-processor list with a description of what each receives is available at /legal/sub-processors. The shortlist as of 2026:

We publish 30-day notice before adding or rotating a sub- processor. Enterprise contracts can opt into the announcement mailing list at announcements@.

Audit + observability

Three log streams are customer-readable:

Incident response

See /docs/incident-policy for the disclosure timeline + the status page cadence. Security-relevant incidents are disclosed within 72h of confirmation; we do not bury exposure events.

Vulnerability reporting

Email [email protected] with the details. We respond within 1 business day. Our vulnerability disclosure policy covers safe-harbour for good-faith research; please review it before testing.

Related