Draimo legal

Security Overview

Version 1.0Effective 22 July 2026Updated 22 July 2026

1. Controls observed in engineering

  • Firebase authentication and server session cookies.
  • Supabase/Postgres access patterns, Storage, RLS migrations and signed URL helpers.
  • Server-side environment variables and Cloud Run private-worker architecture with authenticated dispatch paths.
  • SSRF/public-URL validation, upload validation, webhook signature checks and rate limiting in selected paths.
  • Execution events, usage settlement and audit-oriented records for research and agents.

2. Security commitments

  • Draimo reviews access, authentication, storage, worker, backup and incident controls as part of its security programme.
  • Draimo does not present unverified certifications or test results as guarantees.
  • Security and privacy reports can be sent to team@draimo.com.

3. Incident contact

Security reports should be sent to team@draimo.com. The incident response plan, breach assessment and regulator/user notification process are being documented.

This document explains Draimo's current service terms and safeguards in clear language. It is not legal advice, a certification, or a waiver of rights that cannot lawfully be waived.