Security at Dripdrop

Last updated: 21 July 2026.

Dripdrop builds connected umbrella rental stands deployed in hotels and venues across Europe. Security is engineered into our products — signed and encrypted firmware updates, per-unit device identities, and encrypted communication between our stands and our cloud platform — and maintained throughout each product’s supported lifetime.

Reporting a vulnerability

If you believe you have found a security vulnerability in a Dripdrop product, service, or website, we want to hear from you.

Email: security@dripdrop.io

You will receive an automatic confirmation immediately. A member of our security team will respond within 72 hours (business days, CET/CEST).

Please include, where possible:

  • The affected product, service, or URL, and version if known
  • Steps to reproduce or proof-of-concept
  • Any indication that the vulnerability is being actively exploited — please state this clearly, as it affects triage priority

Prefer not to send details in plain email? Request an encrypted channel via security@dripdrop.io and we will arrange one with you. Machine-readable contact details: [/.well-known/security.txt].

What is in scope

  • Dripdrop stands and kiosks (hardware and firmware)
  • Dripdrop cloud services and dashboards (*.dripdrop.io)
  • Dripdrop web and mobile applications

Out of scope: third-party services we integrate with but do not operate; denial-of-service testing against production systems; social engineering of Dripdrop staff, customers, or venue personnel; physical attacks against deployed stands beyond what is needed to demonstrate a vulnerability (please do not damage, remove, or disable units).

Our commitments

Step Timeframe
Confirmation of receipt Immediate (automatic)
Human response ≤ 72 hours (business days)
Initial assessment ≤ 7 calendar days
Status updates during remediation At least every 30 days
Coordinated public disclosure Target: within 90 days of report

Safe harbour

We will not pursue legal action against anyone who researches and reports vulnerabilities in good faith under this policy — meaning you avoid privacy violations, data destruction, and service degradation; access no more data than needed to demonstrate the issue; and report promptly without exploiting the vulnerability beyond demonstration.

Recognition

We do not currently run a paid bug bounty programme. With your consent, we are happy to credit you in the related security advisory.

Security updates and product support

Dripdrop stands receive security updates automatically over the air, free of charge, for the product’s declared support period. Security advisories for fixed vulnerabilities are published at [/security/advisories].

Regulatory

Dripdrop ApS is preparing for and tracks the EU Cyber Resilience Act (Regulation (EU) 2024/2847). This page and our vulnerability disclosure process implement its coordinated vulnerability disclosure requirements (Annex I, Part II) and support our incident and vulnerability reporting obligations as a manufacturer (Article 14, applicable from 11 September 2026). Registered office: Søren Frichs Vej 25, 1. sal, 8000 Aarhus C, Denmark.