built for control.
secured carefully.
dreach is a managed service for staffing firms, delivered through the hosted web workspace at app.dreach.ai and work performed by Drippay's team. The workspace holds the account, employer, hiring, ATS, network, placement, job order, and fee data your firm chooses to provide or reports. Your team decides who to contact and does the reaching out. Hosted services process the data needed to provide the features you use.
What dreach holds
the hosted workspace can hold:
- account and workspace data
- the employer accounts your firm asks dreach to watch
- public hiring information about those employers
- contact details of hiring managers
- ATS or placement data and network data your firm chooses to upload or authorize
- job order, placement, and fee outcomes your firm reports
What your team controls
- which employers dreach watches
- what ATS, past-placement, and network data your firm uploads or authorizes
- who is contacted. Your firm's team decides who to contact and does the reaching out.
- deletion on request. ask us to delete your workspace data.
The hosted workspace
the hosted workspace at app.dreach.ai is a web application. The employers your firm asks dreach to watch, openings it flags with their source and date, hiring managers to contact, people ranked from data your firm authorizes, and the outcomes your firm reports are stored in our managed database.
- workspace scoping. every record belongs to one workspace, and reads are scoped to the workspace of the signed-in session at the data layer rather than filtered in the interface, so a bug in a screen cannot widen it.
- closed by default. every route requires a session except the public marketing pages and the protocol endpoints that authenticate each request themselves.
- connected senders. OAuth token hashing and scoped keys protect mailbox and sender authorisations. Tokens are scoped to the access you granted, and revoking the connection ends that access.
- team outreach. your firm's team decides who to contact and does the reaching out.
Encryption
In transit
requests between the hosted workspace, the dashboard, and our backend use TLS 1.2 or higher.
At rest
managed databases and cloud storage use encryption at rest. Sensitive tokens and secrets are additionally protected with application-level encryption where configured.
Access controls and monitoring
- production access is limited to authorized personnel
- access is granted by role and reviewed as part of our security program
- administrative and production actions are logged where the platform supports it
- security controls are monitored through Vanta as part of our compliance program
No shared model training
dreach does not train a shared AI model on your messages. When an AI feature is used, selected context is sent only as needed to the configured hosted dreach AI or customer-managed provider key, depending on your plan and settings.
Compliance and trust center
- SOC 2 Type I. dreach has completed a SOC 2 Type I audit performed by an independent CPA firm. The report is available to customers and prospects under NDA.
- Continuous monitoring. security controls are continuously monitored through Vanta as part of our compliance program.
- Vanta Trust Center. the SOC 2 report and live control status are available at trust.usedrip.ai. For anything not covered there, email security@drippay.dev.
- GDPR and CCPA. privacy access, export, correction, and deletion requests can be sent to privacy@drippay.dev.
- dreach is not intended to process protected health information and is not HIPAA covered.
Incident response
we monitor service health and security signals. Confirmed incidents are triaged through our incident process, and impacted customers are notified as required by law and contract.
Responsible disclosure
if you find a vulnerability, send a detailed report to security@drippay.dev. include reproduction steps, affected endpoints, and your contact info. we commit to:
- acknowledging your report within 2 business days
- providing a timeline for triage within 5 business days
- not pursuing legal action against good-faith research that respects user privacy
- publicly crediting you, with your permission, once a fix ships
do not access customer data, run automated scans against production, or test denial-of-service scenarios. we will work with you on safer reproduction paths.
Contact
security and disclosure: security@drippay.dev. privacy requests: privacy@drippay.dev.