◆ Security

Built like the projects
it documents.

Encryption in transit and at rest, role-based access, per-object signed URLs, and a roadmap toward audit logging, SOC 2, and ISO 27001 — because your site data deserves the same rigor as the sites themselves.

Site data is sensitive. Progress photos leak schedule risk, elevation models leak strategy, and portals leak everything. DroneFlow.Ai is designed so your project data is never shared with other customers — we rely only on the service providers required to host, secure, process, and operate the platform (listed in our Privacy Policy), and your data leaves the platform only through the client share links you choose to create.

◆ LIVE  Encrypted in transit (HTTPS/TLS)
◆ LIVE  Encrypted at rest
◆ LIVE  Role-based access control
◆ LIVE  Per-account data isolation
◆ LIVE  Time-limited signed download URLs
◆ LIVE  Google sign-in
◆ LIVE  Two-factor authentication (TOTP)
◇ ROADMAP  SOC 2 Type II · planned
◇ ROADMAP  ISO 27001 · planned

Each item above is generated from the capability registry in our application code, where every “live” entry names the implementation behind it — so this page cannot claim something the product does not do.

IMPLEMENTED

Encrypted transport & storage

Traffic is served over TLS and files are encrypted at rest — both provided by our infrastructure and storage providers. Every file is fetched through a time-limited, per-object signed URL that expires automatically.

IMPLEMENTED

Role-based access control

Owner and admin roles have full control; member is read-only. Roles are enforced server-side, and deliverables can be shared via one-off expiring links.

ROADMAP

Audit logging

An account-level audit trail of key actions is on our roadmap. CSV / SIEM export is planned for Airspace — talk to us if it's a requirement for your rollout.

ENTERPRISE / ROADMAP

Sign-in — and what isn't available yet

Sign in with email or Google (OAuth) today. Audit trail, Enterprise SSO (SAML / OIDC), SCIM provisioning, and Regional data residency are not available yet — they are on our roadmap, and we would rather tell you that than let you discover it during a security review. If one of them gates your rollout, tell us and it will inform what we build next.

CONFIGURABLE

Retention & expiry

Share links can be set to expire on a chosen date. Project data is retained per your plan and can be deleted on request.

TRANSPARENT

Subprocessors & data handling

Your files are hosted with a vetted set of infrastructure and payment subprocessors, listed in our Privacy Policy. The application and database that run the service are hosted in the United States; uploaded files sit in region-less object storage, so we do not offer regional data residency — see Section 10 for the detail.

Need a security questionnaire answered or a DPA signed?
We're happy to walk through our architecture with your security team.
Contact us →