PT EN
← Back
Trust Center

Trust & transparency

What runs behind httpdrop, who processes your data, and where we stand on the compliance journey.

For technical security practices (authentication, isolation, LGPD masking, on-premise), see our Security page →

Subprocessors
  • Stripe — payment and subscription processing
  • Render — application and database hosting
  • Resend — transactional email delivery (welcome emails, limit alerts)
  • GitHub OAuth and Google OAuth — authentication, no password stored
Status & Availability
  • Public health-check endpoint at /health, with process version and uptime
  • No public historical status page yet — it's on the radar, not a dated promise
  • Relevant incidents are communicated by email to affected users
Documentation on request
  • Data Processing Agreement (DPA) available on request for Enterprise customers
  • Security summary (whitepaper) available on request — we do not yet have a standardized public PDF
  • Reach out via /contact for any specific compliance document
Certification Roadmap
  • No formal certification (SOC 2 type I/II, ISO 27001) at this time
  • Technical security practices already implemented — see Security
  • Compliance on demand for Enterprise: contract review, DPA, and customer-specific requirements
Transparency: httpdrop does not yet hold formal certifications (SOC 2, ISO 27001) or a dedicated public status page. The above reflects the product's actual current posture — no marketing fluff. Specific compliance questions? Reach out.