Security · Privacy · Data Ownership

Your data. Your company. Protected and portable.

A clear account of how DropShield stores, protects, and returns your field operations data. Written for owners, IT leads, and safety directors running a vendor review.

How your data is protected.

Nine controls that protect every record, photo, and document in your account.

Encryption in transit & at rest

All traffic between the DropShield app and our servers runs over HTTPS/TLS. Data stored in the platform database and file storage is encrypted at rest by our cloud provider.

Certified cloud infrastructure

DropShield runs on enterprise cloud hosting infrastructure that is ISO 27001:2022 certified and SOC 2 Type II compliant, built on managed Postgres and modern edge infrastructure with certified operations processes behind it.

Managed authentication

Accounts are handled by the platform's managed authentication service. Passwords are salted and hashed by that service and are never stored in plain text or visible to us. Sessions use short-lived access tokens with refresh rotation.

Row-level database security

Access rules are enforced in the database itself with Postgres row-level security policies, so a user's session can only read and write the rows their company and role permit. Server-side checks run on every request — not only in the browser.

You own your data

Your company owns the records you create in DropShield — inspections, photos, work orders, receipts, incidents, employee records. We do not sell your data, share it for marketing, or use it to train AI models. A full database export is available on request.

Daily backups & point-in-time recovery

The platform database is backed up daily with point-in-time recovery across a rolling window of approximately 14 days. Application code is versioned continuously and can be rolled back to any earlier state. Code and data are restored separately.

Operational history

Every record in DropShield carries the user, the timestamp, and — where the device permits — the location captured at the moment of the event. That history stays queryable and exportable, so inspections, repairs, and incidents can be reconstructed exactly as they happened.

Secrets & credentials

Third-party API keys and credentials are stored in the platform's encrypted secret store and are only readable by server-side code. They are never bundled into the mobile or web client and never stored on user devices.

Small, defined access footprint

Administrative access to production data is limited to a small, named operations team plus the hosting provider's certified operations processes. Customer data is not read as part of normal operations.

Data Ownership

Your data is yours. Full stop.

You own it

Every inspection, photo, receipt, and record uploaded belongs to your company.

You can leave with it

A full export of your company's data is provided on request in standard formats. No lock-in, no export fee.

We never sell it

Your data is not used to train shared AI models and is never sold or shared for marketing.

Vendor Security Q&A

What your technical buyer will ask.

The exact answers we give when a prospect's IT lead or safety director sends the vendor security questionnaire.

QWho owns the data I upload to DropShield?+
You do. Your company retains ownership of every inspection, photo, work order, receipt, incident report, and employee record you create or upload. DropShield acts as the processor of that data on your behalf. If you leave the platform, we will provide your data back on request.
QWhere is my data stored, and by whom?+
DropShield is hosted on enterprise cloud infrastructure running managed Postgres. That hosting platform is ISO 27001:2022 certified and SOC 2 Type II compliant and is operated in line with EU and UK GDPR. Customer records are isolated per company by database row-level security policies enforced inside Postgres itself, so one company's session can only reach its own rows.
QHow is data protected in transit and at rest?+
HTTPS/TLS for every request between the app and our servers, and provider-managed encryption at rest for the database and file storage. Passwords are handled by the managed authentication service — salted, hashed, and never stored, logged, or transmitted in the clear.
QWho at DropShield can see my data?+
Access to production data is restricted to a small, named operations team, and only for the purpose of running and supporting the product. Customer data is not read as part of normal operations, and it is never mined, sold, or shared with third parties.
QCan I export my data if I leave?+
Yes. A full export of your company's data is produced on request in standard, portable formats — inspections, work orders, receipts, incidents, employee records, and attached photos and PDFs. There is no export fee and no contractual lock-in.
QHow long is data retained?+
Your records are retained for as long as your account is active, which keeps multi-year inspection and incident history available for audits and claims. Database backups are held on a rolling window of approximately 14 days for point-in-time recovery. Deletion timing after account closure is agreed with you and confirmed in writing.
QDo you use my data to train AI models?+
No. Your company data is not used to train shared or foundation AI models. AI features such as receipt reading and coaching drafts send only the specific record needed for that task to the AI provider through the platform's AI gateway, and the output is written back to your account.
QHow do users sign in, and how are sessions handled?+
Users sign in with email and password through a managed authentication service. Credentials are salted and hashed by that service and are never stored in plain text or visible to us. Sessions use short-lived access tokens with refresh rotation, and every request is re-authorized server-side against row-level security policies. If your organization has specific identity requirements, talk to us and we will scope them with you.
QHow do you handle security incidents?+
Infrastructure-level incidents are detected and handled by our hosting provider under its certified incident response program, with daily backups and point-in-time recovery available to restore data. At the application level, our commitment is direct communication: affected customers are notified without unreasonable delay with what happened, what data was involved, and what we are doing about it.
QWhat compliance certifications sit behind DropShield?+
DropShield is hosted on infrastructure that is ISO 27001:2022 certified and SOC 2 Type II compliant and operated in line with EU and UK GDPR. Those certifications cover the hosting, database, storage, and operations layer your data lives on. DropShield is a field operations platform and is not intended for protected health information.

Compliance posture

  • • Hosted on enterprise cloud infrastructure that is ISO 27001:2022 certified and SOC 2 Type II compliant
  • • Hosting platform operated in line with EU and UK GDPR
  • • Encryption in transit (TLS) and provider-managed encryption at rest
  • • Daily backups with roughly 14-day point-in-time recovery
  • • Postgres row-level security enforcing per-company data isolation
  • • Secrets and third-party credentials held in an encrypted, server-side store

Operating commitments

What you can hold us to as a customer:

  • • Your company owns every record, photo, and document you create
  • • A full data export on request, in standard formats, with no export fee
  • • No selling, sharing, or marketing use of your operational data
  • • Your data is never used to train shared or foundation AI models
  • • Access to production data limited to a small, named operations team
  • • Direct, prompt communication from a real person if anything affects your account

Have a security questionnaire?

Send us your vendor security questionnaire, DPA, or IT review document. We'll turn it around quickly with real answers — no boilerplate.

Contact our security team
Demo or 2-Week Free Trial

See DropShield on your jobsite.

Book a live walkthrough — or skip the call and start a 2-week free trial. Either way, we'll help you get your equipment, crew, jobsites, and work orders loaded fast.

  • 20-minute live walkthrough (Demo)
  • Full-access 2-week trial, no card required
  • Bulk-import onboarding — real training, not a "watch me click" call
  • Your top 3 priorities pre-load the agenda
I want to…
0/3 selected

Pick up to 3 — we'll pre-qualify your demo around them.

Opens your email app with the details prefilled.

Schedule Demo