Drip Agency Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Overview

Apex by DRIP (Drip Trading GmbH) is an A/B testing and experimentation platform for e-commerce. Security and privacy are core to how we build: customer data is hosted in the EU on managed cloud infrastructure (Cloudflare, Vercel, Supabase, Tinybird, Upstash), encrypted in transit and at rest, with strict per-shop tenant isolation. We operate a GDPR-aligned privacy program including a public Data Processing Agreement, consent-aware tracking, data export and deletion APIs, and defined retention periods. Use this Trust Center to learn about our security posture and request access to our security documentation.

Product Security

Apex enforces per-shop tenant isolation at the data layer, role-based access within each organisation, and audit logging of privileged actions. Changes ship through a reviewed release pipeline with a staged rollout and a documented rollback path. Details on specific controls are available on request.

Reports

We have not completed a SOC 2 or ISO 27001 audit and do not publish a penetration test report. On request we can share our technical and organisational measures under Art. 32 GDPR, our Data Processing Agreement, and our current subprocessor list.

Self-Assessments

We have not published a CAIQ or HECVAT self-assessment. We answer security questionnaires directly — request access and we will respond.

Data Security

Customer data is encrypted in transit (TLS 1.2 or higher) and at rest with provider-managed keys. Merchant accounts and experiment configuration are stored in Supabase (PostgreSQL, EU region); analytics events are stored in Tinybird. Storefront visitors are identified by a pseudonymous ID — full IP addresses are never written to the analytics store, and country is derived at the edge.

App Security

Every change to Apex ships as a pull request that must pass automated checks before it can merge: type checking, unit and contract tests, static analysis with Semgrep, and secret scanning with Gitleaks. The main branch is protected against force-push and deletion, and releases run through a staged pipeline with a documented rollback path.

AI

Apex includes AI-assisted features (Apex Operator, landing-page generation and QA audit). All model inference is routed through a single gateway, OpenRouter, to Anthropic and OpenAI models. Only the merchant prompt and the content of the merchants own storefront pages are sent to a model — no analytics event data. AI output is always a draft: a person reviews it and launches every experiment.

ESG

We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.

Legal

We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.

Data Privacy

For storefront visitor data the merchant is the controller and Drip Trading GmbH is the processor, governed by our published Data Processing Agreement. We support consent mode and Do-Not-Track, provide data export and deletion APIs, handle Shopify GDPR webhooks, and run a scheduled retention cleanup job. Visitor identifiers are pseudonymous.

Access Control

Staff access runs through Google Workspace single sign-on with multi-factor authentication enforced. Access to production systems, the source repository and secrets is granted on a least-privilege basis with named accounts only, approved by the Security Officer and reviewed annually. Shared credentials are held in Bitwarden; machine secrets live in Bitwarden Secrets Manager, never in files on disk.

Infrastructure

Apex runs on managed cloud infrastructure: Cloudflare for edge delivery and event ingestion, Vercel for the dashboard application, Supabase (PostgreSQL) for accounts and experiment configuration, Tinybird for analytics, and Upstash for caching and rate limiting. We operate no servers or data centres of our own.

Endpoint Security

Company devices are Apple hardware with full-disk encryption (FileVault), automatic security updates, screen lock and the platform built-in protections (XProtect, Gatekeeper). Device compliance is monitored continuously through the Drata agent. We do not deploy a separate antivirus or EDR product.

Network Security

All traffic is served over TLS 1.2 or higher and terminates on Cloudflare, which provides DDoS protection, WAF rules and rate limiting at the edge. Apex has no corporate network perimeter or VPN: every system is a managed cloud service reached over authenticated, encrypted connections.

Corporate Security

We implement internal measures and practices to maintain a high standard of security.

Policies

We maintain a written information security policy set covering acceptable use, access control, encryption, change management, incident response, business continuity, data retention, vendor management and vulnerability management. Policies are approved by the Security Officer and reviewed at least annually. Copies are available under NDA on request.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

Incident Response

We maintain a documented incident response runbook with the Managing Director as incident commander. Production is monitored by Sentry, Better Stack, Cloudflare Worker observability and health endpoints, with alerts routed to an internal operations channel. As a processor we notify the affected controller without undue delay so that they can meet the 72-hour obligation under Art. 33 GDPR. We do not operate a 24/7 security operations centre.

Risk Management

Risk assessment is owned by the Security Officer and maintained in Drata. Accepted risks are recorded with the reason for acceptance and the trigger that would cause them to be revisited. The formal risk register is being established in 2026.

Asset Management

We maintain an inventory of systems, services and vendors in Drata, covering the Apex platform components, the cloud services they run on, and company devices. Vendors are reviewed before onboarding and recorded with their criticality.

BC/DR

Backups are provider-managed: daily backups with point-in-time recovery on our primary database. Our recovery time objective is 24 hours. Releases run through a staged pipeline with a documented rollback path, and the edge layer is globally distributed. We have not yet performed a documented restore exercise.

Training

Security awareness training is assigned through Drata at onboarding and annually thereafter, together with acknowledgement of the security policy set. This programme is newly established in 2026 and the first cycle is in progress.

Change Management

Every production change ships as a pull request that must pass required automated checks before merge. The main branch is protected against force-push and deletion and requires review threads to be resolved. Releases are versioned, produce a release manifest, and can be rolled back. Merge and production release are performed separately from change authoring.

Physical & Environment

Drip Trading GmbH operates no data centres. All production infrastructure runs on managed cloud providers whose physical and environmental controls are covered by their own certifications. Our offices hold no production data; company devices are encrypted and screen-locked.

Continuous Monitoring

Our controls are monitored continuously in Drata, which tests infrastructure, identity, device and personnel controls automatically and flags drift. Production health is monitored separately through Sentry, Better Stack, Cloudflare Worker observability and dedicated health endpoints.

Built onSafeBase by Drata Logo