← Trustpack

A real sample security pack

Generated for Driftnet, This sample was generated by the same pipeline customers use, from a real intake for driftnet — an LLM-eval tool we run ourselves on Vercel, Stripe, OpenRouter, and GitHub. Operational details the public record doesn't establish use the most plausible value for a solo-founder SaaS on that stack.

This is the exact pipeline output a paying customer receives — the same prompts, the same validator gate, the same rendering — shown in full. Nothing here is staged or hand-edited. Every document carries its attestation line; items the intake marked “not yet” appear only in the Roadmap section, never as current practice.

Driftnet — Security & Trust

Based on answers provided by Driftnet on 2026-06-11. Self-attested by the vendor; not audited or certified by any third party.


Overview

Driftnet is an LLM-eval tool that catches output drift, built for solo developers. The company is a one-person operation; the founder is the sole engineer, administrator, and security contact. Security controls reflect that scale: direct, hands-on, and limited to what a single operator can maintain reliably.


Infrastructure & Hosting

Driftnet runs on Vercel serverless functions and Vercel Blob storage. All customer data resides in the United States, Vercel region iad1. Order and eval records in Vercel Blob are covered by automated daily snapshots retained for 30 days. A public status page is available at status.forage.bot.


Data Protection

Data stored: Customer email addresses, eval prompts and model outputs submitted for testing, and billing records processed through Stripe.

Encryption in transit: TLS 1.2 or higher on all endpoints.

Encryption at rest: Provider-managed encryption on Vercel Blob storage.

Retention and deletion: Data is deleted from live systems within 30 days of a written deletion request sent to driftnet@forage.bot.

Export: Customers can download their eval results as JSON directly from the dashboard at any time.

GDPR: Export and deletion requests for data subjects are handled on request via driftnet@forage.bot.


Access & Authentication

Production systems and customer data are accessible only to the founder. Access is protected by individual credentials with two-factor authentication (2FA) enforced on all critical systems. The founder's machines use full-disk encryption and OS automatic updates.

No third-party staff, contractors, or support agents have access to production data.


Incident Response & Breach Notification

The founder monitors systems via alerts and application logs. Upon detecting an incident, the process is: assess scope, apply a fix, and notify affected customers by email. Affected customers will be notified within 72 hours of confirming a security incident. Application and infrastructure logs are retained for 90 days to support investigation.


Monitoring & Vulnerability Management

Dependency alerts are handled through GitHub Dependabot. Critical patches are applied within days of notification. Application and infrastructure logs are retained for 90 days.

Development practices include: staging preview deployments before any production deploy, secrets stored in environment configuration rather than source code, and an automated test suite run on every change.


Subprocessors

The following third parties process or have access to customer data:

| Subprocessor | Purpose | |---|---| | Vercel | Hosting, serverless compute, and Blob storage | | Stripe | Payment processing and billing records | | OpenRouter | LLM inference for eval execution | | GitHub | Support issue tracking |


Current Posture & Roadmap

In place today

  • TLS 1.2+ encryption in transit on all endpoints
  • Provider-managed encryption at rest on Vercel Blob
  • Automated daily snapshots retained 30 days
  • 2FA enforced on all critical systems for the founder
  • Full-disk encryption and OS auto-updates on staff devices
  • GitHub Dependabot for automated dependency alerts; critical patches applied within days
  • Application and infrastructure logs retained 90 days
  • Staging previews before production deploys; secrets in environment config, not source
  • Automated test suite on every change
  • Data deletion within 30 days on written request
  • GDPR export and deletion handled on request
  • Customer breach notification within 72 hours of confirmed incident
  • Public status page at status.forage.bot

Planned

  • We plan to introduce a documented disaster-recovery runbook.
  • We plan to offer SSO to customers.
  • We plan to commission a third-party penetration test.
  • We plan to pursue a security certification (such as SOC 2 or ISO 27001).
  • We plan to obtain cyber-liability insurance.

Contact

Security questions, vulnerability disclosures, and data-subject requests (including GDPR export or deletion) should be directed to:

[driftnet@forage.bot](mailto:driftnet@forage.bot)

Responses are handled directly by the founder. There is no ticketing intermediary for security matters.

Build my security pack — $49Browse the answer guides