Driftro / security
Security is part of the service.
Last updated: 30 August 2026
Driftro is an invite-only beta. We keep the operational surface deliberately small while we build the evidence and controls needed for a broader launch.
Current practices
- Primary application data is hosted in Finland / the EU.
- Access is invite-only, with workspace roles and scoped unattended wallboard links.
- Production traffic is TLS-terminated at a Caddy edge; application and database services stay on private networks.
- Credentials and one-time monitor or wallboard tokens are handled separately from ordinary application records.
- Production releases use immutable container image digests and build provenance attestations.
Responsible disclosure
Please report suspected security issues privately to security@driftro.se. Include enough detail for us to reproduce the issue, but do not access, alter, or retain another person’s data.
What this page does not claim
Driftro does not currently claim a security certification, GDPR certification, full EU-only processing, or a service-level agreement. We will publish substantiated updates as the beta matures.