Security
Your accounts stay yours. Here is exactly how.
Every protection below is named for what it does for you, and every one is enforced by the code, not just promised.
What protects you, and what it does for you
No password ever reaches us
You connect each network through its own official sign-in. We can post for you, and nothing more. There is no password of yours to steal from us.
Encrypted connection keys
The keys to your connected accounts are encrypted before they are stored, tied to your account, and the encryption key is held apart from the database. Even a copy of the database would not open your accounts.
Fail-safe start
If the encryption key is ever missing or malformed, the app refuses to start rather than quietly storing anything unprotected.
Keys never travel back to your browser
No page or API returns a stored key. A test fails the build if one ever does.
Built-in emergency control system
If something goes wrong out of the blue, we flip one switch and all publishing stops, or the whole product goes read-only, in seconds. Nothing scheduled is lost, and nothing goes out until we say it is safe.
Runs on Cloudflare
Dripost is hosted on Cloudflare, one of the world's most widely trusted infrastructure platforms, with its network-level protection and secure sign-in tooling behind everything we run.
Nothing goes out unless you say so
Only posts you scheduled or approved are ever published. With approvals on, an unapproved post cannot go out. It is checked on the server, not just hidden on screen.
Each post goes out once
A post is sent to each network at most once. When we cannot tell whether a request landed, we ask you instead of sending it again.
Cancel or pause any time
Stop one scheduled post, or pause everything in your workspace, and nothing goes out until you say so. Your posts are kept, never deleted, and when you switch publishing back on we ask you about anything that came due rather than sending a backlog all at once.
Roles that actually restrict
Owner, admin, editor, approver and viewer are enforced on the server for every change. A viewer cannot change anything, even by trying.
Your workspace is walled off
Every request for a post, file or delivery is checked against your account. Asking for someone else's returns 'not found'.
Private files, short-lived links
Uploaded media sits in private storage. Networks fetch it through a link that expires in 15 minutes and works for that one file.
New sign-in alerts
If your account is used from a new browser, device or country, we email you straight away, so a takeover is visible in minutes.
Confirm-it's-you for sensitive changes
Changing a password, a recovery address, exporting your data or deleting your account asks for a fresh emailed code first. A borrowed or left-open session cannot do it.
Guess-proof codes
Sign-in codes expire quickly, work once, and repeated wrong tries are slowed down and locked out.
Leave any time, with your data
Disconnect any network, download a copy of your data, or delete your account in Settings. Deleting removes your connections, posts and files.
What it does not do yet
- Two-factor sign-in with an authenticator app, and passkeys. Both are built and are being tested; they are not switched on for accounts yet.
- A list of active sessions you can end remotely.
- A visible audit log of sensitive actions, and the full history of who approved or commented on a post. Both are built and tested; they are not switched on for accounts yet.
- An independent security audit. Dripost has not had one.
Questions
Where does Dripost run?
On Cloudflare's global network, with the database on Cloudflare D1, behind our own emergency control switch.
How do I report a security problem?
Use the contact page and put 'security' in the subject. Our Grievance Officer, Rajesh Kumar, reads it directly.
Is Dripost certified, for example SOC 2 or ISO 27001?
Not yet. Certification is on our roadmap. Until then, the protections above are what the code enforces today, and you can see most of them working for yourself.
Checked against the product on 2026-09-21.