
Last updated: September 19, 2026
Droptop takes the security, confidentiality, and availability of customer information seriously. We maintain administrative, technical, and organizational safeguards designed to protect customer data and the systems used to provide our services.
Security Program
Droptop maintains documented security policies covering access control, data management, incident response, business continuity, vulnerability management, vendor management, and employee security responsibilities.
Our security controls are periodically reviewed and updated as our services, risks, and regulatory requirements evolve.
Infrastructure Security
Droptop uses established cloud infrastructure providers to host and operate its services. Our infrastructure is protected through controls that include:
Network firewalls and traffic restrictions
Centralized security logging and monitoring
Threat-detection and alerting services
Encryption of data in transit
Encryption of supported data stores at rest
Restricted administrative access
Secure configuration and change-management practices.
Production access is limited to authorized personnel with a legitimate business need.
Identity and Access Management
Droptop applies role-based and least-privilege access principles. Access to critical systems is protected using controls that include:
Unique user accounts
Multi-factor authentication
Strong password requirements
Company-approved password management
Periodic user access reviews
Prompt access removal following termination or role changes
Additional restrictions for privileged administrative access
Application and Vulnerability Security
Droptop maintains processes for identifying, evaluating, prioritizing, and remediating security vulnerabilities.
Security activities may include vulnerability scanning, software dependency review, system patching, configuration review, access review, and investigation of security alerts. Findings are prioritized according to their severity, exploitability, and potential impact.
Changes to production systems are reviewed and deployed using controlled development and deployment processes.
Monitoring and Incident Response
Droptop monitors relevant infrastructure and security events for abnormal or potentially malicious activity. We maintain an incident-response process covering:
Detection and reporting
Investigation and classification
Containment and remediation
Recovery and validation
Internal and external communication
Root cause analysis
Corrective actions intended to prevent recurrence.
Where required by applicable law or contractual obligations, affected customers will be notified of confirmed security incidents involving their information.
Data Protection
Droptop limits the collection and use of customer information to legitimate business purposes. Access to customer data is restricted based on job responsibilities and business need. Data is retained only as required for operational, contractual, and legal purposes and is deleted or securely disposed of in accordance with applicable retention requirements. Additional information about how Droptop handles personal information is available in our Privacy Policy.
Business Continuity
Droptop maintains business continuity and recovery procedures designed to support the continued availability and restoration of critical services following a disruption.These procedures address system recovery, backups where applicable, communication responsibilities, and periodic review of continuity arrangements.
Personnel and Vendor Security
Personnel with access to Droptop systems are required to follow company security policies and complete applicable security awareness training. Third-party providers that may access or process sensitive information are evaluated based on the nature of the service and associated risk. Contractual and security safeguards are applied where appropriate.
Responsible Disclosure
If you believe you have identified a security vulnerability affecting Droptop, please contact us at support@droptop.io. Please include sufficient information for us to reproduce and investigate the issue. Do not access, modify, retain, or disclose customer information while conducting security research. We will acknowledge legitimate reports and investigate them in accordance with our vulnerability-management and incident-response procedures.
Security Inquiries
Customers requiring additional security information or documentation may contact support@droptop.io