Security & privacy

Security & privacy.

What we do, and don't, with your data.

In transit

Every request - upload, download, login - uses HTTPS / TLS. The tus upload protocol is HTTP-native, so the same TLS terminator that protects the rest of your site protects uploads.

At rest

Files are stored as opaque objects on disk under randomized storage keys. Filenames in the database are sanitized. Deleted files are purged from disk, not just marked.

Credentials

Passwords are hashed with Argon2id (the OWASP-recommended algorithm). We never see your plaintext password. Sessions are JWTs in HTTP-only, SameSite=Lax cookies.

Access logs

Download requests are logged with a SHA-256 hash of the requester IP - not the IP itself. Logs are retained for 90 days for abuse prevention, then deleted.

Billing

We don't see your wallet address. Our payment provider processes the crypto transaction; we receive the order ID, amount, and status only.

Responsible disclosure

Found a security issue? Email us at legal@drop.xxx. We respond within 48 hours. Please don't disclose publicly until we've had a chance to patch.

Drop