A clear account of how DropShield stores, protects, and returns your field operations data. Written for owners, IT leads, and safety directors running a vendor review.
Nine controls that protect every record, photo, and document in your account.
All traffic between the DropShield app and our servers runs over HTTPS/TLS. Data stored in the platform database and file storage is encrypted at rest by our cloud provider.
DropShield runs on enterprise cloud hosting infrastructure that is ISO 27001:2022 certified and SOC 2 Type II compliant, built on managed Postgres and modern edge infrastructure with certified operations processes behind it.
Accounts are handled by the platform's managed authentication service. Passwords are salted and hashed by that service and are never stored in plain text or visible to us. Sessions use short-lived access tokens with refresh rotation.
Access rules are enforced in the database itself with Postgres row-level security policies, so a user's session can only read and write the rows their company and role permit. Server-side checks run on every request — not only in the browser.
Your company owns the records you create in DropShield — inspections, photos, work orders, receipts, incidents, employee records. We do not sell your data, share it for marketing, or use it to train AI models. A full database export is available on request.
The platform database is backed up daily with point-in-time recovery across a rolling window of approximately 14 days. Application code is versioned continuously and can be rolled back to any earlier state. Code and data are restored separately.
Every record in DropShield carries the user, the timestamp, and — where the device permits — the location captured at the moment of the event. That history stays queryable and exportable, so inspections, repairs, and incidents can be reconstructed exactly as they happened.
Third-party API keys and credentials are stored in the platform's encrypted secret store and are only readable by server-side code. They are never bundled into the mobile or web client and never stored on user devices.
Administrative access to production data is limited to a small, named operations team plus the hosting provider's certified operations processes. Customer data is not read as part of normal operations.
Every inspection, photo, receipt, and record uploaded belongs to your company.
A full export of your company's data is provided on request in standard formats. No lock-in, no export fee.
Your data is not used to train shared AI models and is never sold or shared for marketing.
The exact answers we give when a prospect's IT lead or safety director sends the vendor security questionnaire.
What you can hold us to as a customer:
Send us your vendor security questionnaire, DPA, or IT review document. We'll turn it around quickly with real answers — no boilerplate.
Contact our security teamBook a live walkthrough — or skip the call and start a 2-week free trial. Either way, we'll help you get your equipment, crew, jobsites, and work orders loaded fast.