Last updated: 21 July 2026.
Dripdrop builds connected umbrella rental stands deployed in hotels and venues across Europe. Security is engineered into our products — signed and encrypted firmware updates, per-unit device identities, and encrypted communication between our stands and our cloud platform — and maintained throughout each product’s supported lifetime.
If you believe you have found a security vulnerability in a Dripdrop product, service, or website, we want to hear from you.
Email: security@dripdrop.io
You will receive an automatic confirmation immediately. A member of our security team will respond within 72 hours (business days, CET/CEST).
Please include, where possible:
Prefer not to send details in plain email? Request an encrypted channel via security@dripdrop.io and we will arrange one with you. Machine-readable contact details: [/.well-known/security.txt].
Out of scope: third-party services we integrate with but do not operate; denial-of-service testing against production systems; social engineering of Dripdrop staff, customers, or venue personnel; physical attacks against deployed stands beyond what is needed to demonstrate a vulnerability (please do not damage, remove, or disable units).
We will not pursue legal action against anyone who researches and reports vulnerabilities in good faith under this policy — meaning you avoid privacy violations, data destruction, and service degradation; access no more data than needed to demonstrate the issue; and report promptly without exploiting the vulnerability beyond demonstration.
We do not currently run a paid bug bounty programme. With your consent, we are happy to credit you in the related security advisory.
Dripdrop stands receive security updates automatically over the air, free of charge, for the product’s declared support period. Security advisories for fixed vulnerabilities are published at [/security/advisories].
Dripdrop ApS is preparing for and tracks the EU Cyber Resilience Act (Regulation (EU) 2024/2847). This page and our vulnerability disclosure process implement its coordinated vulnerability disclosure requirements (Annex I, Part II) and support our incident and vulnerability reporting obligations as a manufacturer (Article 14, applicable from 11 September 2026). Registered office: Søren Frichs Vej 25, 1. sal, 8000 Aarhus C, Denmark.