Security at Drift
Introduction to Security & Privacy at Drift
Managing our customer data is more than just a responsibility to be met, it’s something our company is truly passionate about. We believe our customer’s trust is something that must be earned every day. To achieve that, we do more than just follow policies and check boxes, we instill awareness and best practices in our culture so that security and data privacy are top of mind when designing our application, managing our networks, and conducting daily business operations.
Certifications
Drift performs a variety of audits and assessments to provide ourselves and our customers with independent, third-party assurance that we are adhering to our commitment to protect our systems and our customer’s data.
Drift undergoes this industry recognized audit of our security program on an annual basis and makes our report available to all prospective customers.
Drift adheres to the Privacy Shield principles of notice, choice, accountability, security, data integrity and purpose limitation, access and recourse, and are certified by the U.S. Department of Commerce.
Learn More ›Drift knows that our customers want to know about how we secure their data. As a Cloud Security Alliance STAR registrant, Drift’s security practices are conveniently and immediately available for review, no need to send us a survey.
Learn More ›Top Security & Privacy Features
Drift is exclusively hosted on AWS who provides robust, physical data center security and environmental controls. Drift’s corporate offices all require badge access for entry, maintain video surveillance, and require all visitors to sign in and be accompanied when present.
Drift controls access to our production networks through the use of strictly defined rules and requires multi-factor authentication and encrypted connections. We also utilize intrusion detection systems in our production network and advanced email filtering in our corporate network to identify potential security threats.
Drift employs both internal and external testing of our product. We regularly scan source code and systems for vulnerabilities and perform necessary patching and updates based on those results. On an annual basis we utilize a nationally recognized firm to test our application and network to provide ourselves and our customers assurance that data is being robustly protected.
Drift requires all employees and contractors to sign a confidentiality agreement prior to commencement. During the onboarding process, security awareness training is delivered to all new hires and we continually publicize security alerts through our internal communication channels.
Drift utilizes geographically separate environments to ensure data availability and uptime. In the unlikely event of simultaneous failure of both environments, Drift maintains daily backups, meaning that the RPO is no greater than 24 hours.
Drift encrypts data in transit and at rest on our servers utilizing recognized encryption protocols. At end-of-life, AWS destroys disks per NIST 800-88 standards.
Drift and the EU General Data Protection Regulation (GDPR)
Drift is committed to helping our users understand the rights and obligations under the General Data Protection Regulation (GDPR), which took effect on May 25, 2018.
To learn more about our GDPR compliance, please read our GDPR Policy.
Learn MoreFrequently Asked Questions
Legal Resources at Drift
Drift is committed to helping our users understand their terms of Service in using Drift.
To learn more about our GDPR compliance, please read our GDPR Policy.
To learn more about all other Legal Resources, please read our Drift Terms of Service, API Terms of Service>, Privacy Policy, Acceptable Use Policy, GDPR, and Drift Information Security Addendum.