Draimo legal
Security Overview
Version 1.0Effective 22 July 2026Updated 22 July 2026
1. Controls observed in engineering
- Firebase authentication and server session cookies.
- Supabase/Postgres access patterns, Storage, RLS migrations and signed URL helpers.
- Server-side environment variables and Cloud Run private-worker architecture with authenticated dispatch paths.
- SSRF/public-URL validation, upload validation, webhook signature checks and rate limiting in selected paths.
- Execution events, usage settlement and audit-oriented records for research and agents.
2. Security commitments
- Draimo reviews access, authentication, storage, worker, backup and incident controls as part of its security programme.
- Draimo does not present unverified certifications or test results as guarantees.
- Security and privacy reports can be sent to team@draimo.com.
3. Incident contact
Security reports should be sent to team@draimo.com. The incident response plan, breach assessment and regulator/user notification process are being documented.
This document explains Draimo's current service terms and safeguards in clear language. It is not legal advice, a certification, or a waiver of rights that cannot lawfully be waived.