Trust center · Compliance
Compliance posture & disclosure
The controls and attestations available today, plus the private disclosure channel for security findings.
Certifications & attestations
This table lists only attestations currently in place. Driftstack is not currently SOC 2 or ISO 27001 certified.
| Standard | Status | Evidence |
|---|---|---|
| GDPR Article 28 DPA with SCCs available | In place | Data Processing Agreement |
Vulnerability disclosure policy
Report security issues privately to [email protected]. If a report contains customer data or exploit material, use the initial email to arrange an encrypted transfer channel.
- Response commitments
-
- Acknowledge receipt within 2 business days.
- Provide an initial severity assessment within 5 business days.
- Send status updates at least every 14 days until resolution.
- Credit the reporter publicly after remediation, with consent.
- Safe harbour
- We will not pursue legal action against good-faith research on the public Driftstack surface when the researcher avoids customer data, service disruption, and public disclosure before remediation.
Sub-processor change notice
Under GDPR Article 28(2) and Annex 3 of our DPA, we provide 30 calendar days' notice for a material addition or replacement on the sub-processor list. Customers can object during that window by emailing [email protected].
Audit-log retention
-
Customer audit logs follow the account tier's published retention and
are available through the dashboard and
GET /v1/account/audit-log. - Privileged admin-action records are retained internally for 365 days.
- Access logs stay in quick-access storage for 90 days, then in archive for one year.