Drip Agency Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Apex is an experimentation and analytics platform for ecommerce teams, built and operated by Drip Trading GmbH in Germany. We measure what happens on your storefront so you can decide what to change. That job only works if two things are true at once: the numbers have to be right, and the people they describe have to stay anonymous. Most of the engineering decisions on this page come from holding both.

The practical version is this. A shopper's visitor ID is a random value generated in their own browser. It is not built from an IP address, a fingerprint or a customer record, and it means nothing outside your shop. Our edge sees the request IP, uses it for country lookup and abuse rate limiting, and never writes it to the analytics store. Storefront events land in Tinybird in London (covered by the EU's UK adequacy decision). Your accounts, your configuration and your audit log land in a separate PostgreSQL database in Ireland, with point-in-time recovery. Those two planes meet once, at query time, as a read scoped to your shop. We have no offices and no servers of our own, so there is no server room to describe: physical security belongs to Cloudflare, Vercel, Supabase and Tinybird, and we verify their certifications as part of our vendor reviews.

The control we would show a competitor is the deploy pipeline, because it is mechanical rather than procedural. Nobody at Drip can push to production. Direct pushes to the main branch are rejected by the repository, so is a manual merge, and so is auto-merge from an approved green pull request. The only route into production is a deployment queue processed by a single release role, and a change reaches that queue only after clearing twelve required checks, including static analysis and secret scanning. We built it that way for an unglamorous reason: on a small team, the person who writes the change is often the person who would ship it, and we would rather remove the ability to ship by hand than write a policy asking people not to.

Fabian Gmeindl, Geschäftsführer, owns the security program personally, which means the risk decisions, access reviews and incident calls have one name on them rather than a committee. PROLIANCE GmbH serves as our external Data Protection Officer from 1 September 2026, reachable at datenschutzbeauftragter@proliance.ai, and being external is the point: they can tell us no. On certification we will be blunt, because you will find out anyway. Our ISO 27001 Statement of Applicability is approved and the controls are running and monitored daily, but the SOC 2 Type II and ISO 27001 certification audits are being engaged for an October to December 2026 window. We do not have the certificate yet. If your procurement process needs one today, better you hear that in the first meeting than in week six.

One more thing, on the same principle. In August 2026 a change that passed every required check damaged a production analytics rollup on its first scheduled run, while our freshness monitor stayed green because the data was fresh and merely wrong. We detected and resolved it in under six hours, then changed the rule that let it through: every change now ships with its own written live verification plan and specific production probes, and the engineer who wrote it owns it until those probes pass. We put that in a trust center on purpose. A vendor who has never had an incident is a vendor who is not looking.

Security questionnaires, vendor reviews and architecture calls: security@drip-apex.com. Fabian answers them, usually the same week. Vulnerability reports: same address, or /.well-known/security.txt. Privacy and data subject requests: privacy@drip-apex.com or directly to the DPO.

Documents

REPORTSData Flow Diagram (DFD)

Product Security

Apex enforces per-shop tenant isolation at the data layer, role-based access within each organisation, and audit logging of privileged actions. Changes ship through a reviewed release pipeline with a staged rollout and a documented rollback path. Details on specific controls are available on request.

Self-Assessments

We have not published a CAIQ or HECVAT self-assessment. We answer security questionnaires directly — request access and we will respond.

Data Security

Customer data is encrypted in transit (TLS 1.2 or higher) and at rest with provider-managed keys. Merchant accounts and experiment configuration are stored in Supabase (PostgreSQL, EU region); analytics events are stored in Tinybird. Storefront visitors are identified by a pseudonymous ID — full IP addresses are never written to the analytics store, and country is derived at the edge.

App Security

Every change to Apex ships as a pull request that must pass automated checks before it can merge: type checking, unit and contract tests, static analysis with Semgrep, and secret scanning with Gitleaks. The main branch is protected against force-push and deletion, and releases run through a staged pipeline with a documented rollback path.

AI

Apex includes AI-assisted features (Apex Operator, landing-page generation and QA audit). All model inference is routed through a single gateway, OpenRouter, to Anthropic and OpenAI models. Only the merchant prompt and the content of the merchants own storefront pages are sent to a model — no analytics event data. AI output is always a draft: a person reviews it and launches every experiment.

ESG

We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.

Legal

We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.

Data Privacy

For storefront visitor data the merchant is the controller and Drip Trading GmbH is the processor, governed by our published Data Processing Agreement. We support consent mode and Do-Not-Track, provide data export and deletion APIs, handle Shopify GDPR webhooks, and run a scheduled retention cleanup job. Visitor identifiers are pseudonymous.

Access Control

Staff access runs through Google Workspace single sign-on with multi-factor authentication enforced. Access to production systems, the source repository and secrets is granted on a least-privilege basis with named accounts only, approved by the Security Officer and reviewed annually. Shared credentials are held in Bitwarden; machine secrets live in Bitwarden Secrets Manager, never in files on disk.

Infrastructure

Apex runs on managed cloud infrastructure: Cloudflare for edge delivery and event ingestion, Vercel for the dashboard application, Supabase (PostgreSQL) for accounts and experiment configuration, Tinybird for analytics, and Upstash for caching and rate limiting. We operate no servers or data centres of our own.

Endpoint Security

Company devices are Apple hardware with full-disk encryption (FileVault), automatic security updates, screen lock and the platform built-in protections (XProtect, Gatekeeper). Device compliance is monitored continuously through the Drata agent. We do not deploy a separate antivirus or EDR product.

Network Security

All traffic is served over TLS 1.2 or higher and terminates on Cloudflare, which provides DDoS protection, WAF rules and rate limiting at the edge. Apex has no corporate network perimeter or VPN: every system is a managed cloud service reached over authenticated, encrypted connections.

Corporate Security

We implement internal measures and practices to maintain a high standard of security.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

Incident Response

We maintain a documented incident response runbook with the Managing Director as incident commander. Production is monitored by Sentry, Better Stack, Cloudflare Worker observability and health endpoints, with alerts routed to an internal operations channel. As a processor we notify the affected controller without undue delay so that they can meet the 72-hour obligation under Art. 33 GDPR. We do not operate a 24/7 security operations centre.

Asset Management

We maintain an inventory of systems, services and vendors in Drata, covering the Apex platform components, the cloud services they run on, and company devices. Vendors are reviewed before onboarding and recorded with their criticality.

Training

Security awareness training is assigned through Drata at onboarding and annually thereafter, together with acknowledgement of the security policy set. This programme is newly established in 2026 and the first cycle is in progress.

Change Management

Every production change ships as a pull request that must pass required automated checks before merge. The main branch is protected against force-push and deletion and requires review threads to be resolved. Releases are versioned, produce a release manifest, and can be rolled back. Merge and production release are performed separately from change authoring.

Physical & Environment

Drip Trading GmbH operates no data centres. All production infrastructure runs on managed cloud providers whose physical and environmental controls are covered by their own certifications. Our offices hold no production data; company devices are encrypted and screen-locked.

Continuous Monitoring

Our controls are monitored continuously in Drata, which tests infrastructure, identity, device and personnel controls automatically and flags drift. Production health is monitored separately through Sentry, Better Stack, Cloudflare Worker observability and dedicated health endpoints.

Built onSafeBase by Drata Logo