Trust Center
Trust & transparency
What runs behind httpdrop, who processes your data, and where we stand on the compliance journey.
For technical security practices (authentication, isolation, LGPD masking, on-premise), see our Security page →
Subprocessors
- Stripe — payment and subscription processing
- Render — application and database hosting
- Resend — transactional email delivery (welcome emails, limit alerts)
- GitHub OAuth and Google OAuth — authentication, no password stored
Status & Availability
- Public health-check endpoint at
/health, with process version and uptime - No public historical status page yet — it's on the radar, not a dated promise
- Relevant incidents are communicated by email to affected users
Documentation on request
- Data Processing Agreement (DPA) available on request for Enterprise customers
- Security summary (whitepaper) available on request — we do not yet have a standardized public PDF
- Reach out via /contact for any specific compliance document
Certification Roadmap
- No formal certification (SOC 2 type I/II, ISO 27001) at this time
- Technical security practices already implemented — see Security
- Compliance on demand for Enterprise: contract review, DPA, and customer-specific requirements
Transparency: httpdrop does not yet hold formal certifications (SOC 2, ISO 27001) or a dedicated public status page. The above reflects the product's actual current posture — no marketing fluff. Specific compliance questions? Reach out.