Skip to main content
DRIFTSTACK

Compliance posture & disclosure

The controls and attestations available today, plus the private disclosure channel for security findings.

Certifications & attestations

This table lists only attestations currently in place. Driftstack is not currently SOC 2 or ISO 27001 certified.

Standard Status Evidence
GDPR Article 28
DPA with SCCs available
In place Data Processing Agreement

Vulnerability disclosure policy

Report security issues privately to [email protected]. If a report contains customer data or exploit material, use the initial email to arrange an encrypted transfer channel.

Response commitments
  • Acknowledge receipt within 2 business days.
  • Provide an initial severity assessment within 5 business days.
  • Send status updates at least every 14 days until resolution.
  • Credit the reporter publicly after remediation, with consent.
Safe harbour
We will not pursue legal action against good-faith research on the public Driftstack surface when the researcher avoids customer data, service disruption, and public disclosure before remediation.

Sub-processor change notice

Under GDPR Article 28(2) and Annex 3 of our DPA, we provide 30 calendar days' notice for a material addition or replacement on the sub-processor list. Customers can object during that window by emailing [email protected].

Audit-log retention

  • Customer audit logs follow the account tier's published retention and are available through the dashboard and GET /v1/account/audit-log.
  • Privileged admin-action records are retained internally for 365 days.
  • Access logs stay in quick-access storage for 90 days, then in archive for one year.