← Trustpack

A real sample security pack

Generated for Driftnet, This sample was generated by the same pipeline customers use, from a real intake for driftnet — an LLM-eval tool we run ourselves on Vercel, Stripe, OpenRouter, and GitHub. Operational details the public record doesn't establish use the most plausible value for a solo-founder SaaS on that stack.

This is the exact pipeline output a paying customer receives — the same prompts, the same validator gate, the same rendering — shown in full. Nothing here is staged or hand-edited. Every document carries its attestation line; items the intake marked “not yet” appear only in the Roadmap section, never as current practice.

Driftnet — Security & Trust

Based on answers provided by Driftnet on 2026-06-12. Self-attested by the vendor; not audited or certified by any third party.


Overview

Driftnet is an LLM-eval tool that catches output drift, built for solo developers. The product is operated by a single founder. Security controls are proportionate to that scale: specific in the areas that matter for customer data, and honest about what is not yet in place.


Infrastructure & Hosting

Driftnet runs on Vercel using serverless functions and Vercel Blob storage. All customer data is held in the United States in Vercel's iad1 region. No other geographic regions are used.

A public health endpoint is available at driftnet.forage.bot/api/health for uptime verification.

Backups and a formal disaster-recovery runbook are not currently in place; see Roadmap below.


Data Protection

Data stored: Customer email addresses, eval prompts and model outputs submitted for testing, and billing records processed through Stripe.

Encryption in transit: TLS 1.2 or higher on all endpoints.

Encryption at rest: Provider-managed encryption on Vercel Blob storage.

Retention and deletion: Data is removed from live systems within 30 days of a verified deletion request submitted to driftnet@forage.bot.

Export: Customers can download their eval packs and results at any time from their tokenized dashboard.

GDPR: Export and deletion requests are handled on request via driftnet@forage.bot.


Access & Authentication

Production access: The founder is the only person with access to production systems and customer data. Access requires individual credentials with two-factor authentication (2FA) enforced.

Customer authentication: Customers access the product through tokenized private dashboard links. No passwords are created or stored by Driftnet.

Staff device security: The founder's machines use full-disk encryption and OS-level automatic updates.

SSO for customers is not currently available; see Roadmap below.


Monitoring & Vulnerability Management

Logging: Request and function logs are retained at Vercel's default hosting-provider retention. No extended log retention is configured at this time.

Dependency management: GitHub Dependabot provides automated alerts for dependency vulnerabilities. Critical patches are applied within days of notification.

Incident response: The founder monitors alerts, assesses and remediates incidents, and notifies affected customers by email within 72 hours of confirming an incident.

Development practices: Changes go through staging preview deploys before reaching production. Secrets are stored in environment configuration, not in source code. An automated test suite runs on every change.

A third-party penetration test has not been conducted; see Roadmap below.


Subprocessors

SubprocessorPurpose
VercelHosting (serverless functions and blob storage)
StripePayment processing and billing records
OpenRouterLLM inference
GitHubSupport issue tracking

Current Posture & Roadmap

In place today

  • TLS 1.2+ encryption in transit on all endpoints
  • Provider-managed encryption at rest on Vercel Blob storage
  • Production access restricted to the founder, with 2FA enforced
  • Tokenized dashboard links for customer authentication (no stored passwords)
  • Full-disk encryption and auto-updates on founder devices
  • GitHub Dependabot automated dependency alerting; critical patches within days
  • Staging preview deploys before all production changes
  • Secrets stored in environment configuration, not source code
  • Automated test suite on every change
  • Data deletion within 30 days of request
  • Customer data export available on demand
  • GDPR export and deletion handled on request
  • Breach notification to affected customers within 72 hours of confirmed incident
  • Public health endpoint at driftnet.forage.bot/api/health

Planned

  • We plan to implement a formal backup strategy for customer data
  • We plan to document a disaster-recovery runbook
  • We plan to offer SSO as a customer authentication option
  • We plan to conduct a third-party penetration test
  • We plan to configure extended audit log retention beyond provider defaults
  • We plan to pursue formal security certification (such as SOC 2)
  • We plan to obtain cyber-liability insurance

Contact

Security questions, vulnerability disclosures, and data-subject requests (including GDPR export and deletion) should be sent to driftnet@forage.bot.

Build my security pack — $49Browse the answer guides