Security & trust center

How Drape keeps
your archive safe.

Fashion houses run on archives, models, and trade secrets. We built Drape from day one as a security-first, EU-sovereign company — not bolt-on, not retroactive. The certifications and practices below are audited by independent third parties and published quarterly.

Certifications

ISO 27001
Certified 2025

Information security management. Audited annually by Bureau Veritas.

SOC 2 Type II
Type II since 2026

Continuous controls for security, availability, processing integrity, confidentiality. Maison plan customers can request the full report.

GDPR-native
Since launch

Designed from day one as an EU-first, EU-hosted product. Privacy by default, not bolt-on.

EU AI Act ready
Compliant 2026

We have completed the risk assessment for general-purpose AI providers. Aligned with the August 2025 obligations.

Engineering practices

  • All data encrypted at rest with AES-256-GCM (Hetzner LUKS + AWS KMS)
  • All data in transit TLS 1.3 with HSTS, no TLS 1.0/1.1 support
  • Passwords hashed with Argon2id (memory 64 MB, iterations 3, parallelism 4)
  • MFA required for all internal staff · hardware keys on production
  • Quarterly external penetration test by Bishop Fox
  • Bug bounty program · payouts €500–€50,000 · disclosed publicly
  • 30-day production backup retention · 7-day point-in-time recovery
  • RPO ≤ 1 hour · RTO ≤ 4 hours · tested quarterly
  • Production access is audit-logged · personal data access is dual-authorization
  • No customer data ever leaves the EEA · zero US sub-processors for personal data

Responsible disclosure

Bug bounty · always on

Found something? Email security@drape.studio with a PGP-signed report (key fingerprint 4A9C 7E2F 8B11 D34A 5F92 1C8E B7D4 91A6 33E1 88CC). We acknowledge within 24 hours, triage within 72, fix within 30 days for high-severity. Payouts €500–€50,000 depending on impact. We publicly credit researchers (unless you prefer otherwise) and we maintain a hall of fame.

security@drape.studio →
For SOC 2 reports, penetration test summaries, or any compliance documentation, contact security@drape.studio. Real reply, signed NDA, full pack within 48 hours.
Free · no card
10 editorial frames waiting in your inbox.
Open atelier →