How Drape keeps
your archive safe.
Fashion houses run on archives, models, and trade secrets. We built Drape from day one as a security-first, EU-sovereign company — not bolt-on, not retroactive. The certifications and practices below are audited by independent third parties and published quarterly.
Certifications
Information security management. Audited annually by Bureau Veritas.
Continuous controls for security, availability, processing integrity, confidentiality. Maison plan customers can request the full report.
Designed from day one as an EU-first, EU-hosted product. Privacy by default, not bolt-on.
We have completed the risk assessment for general-purpose AI providers. Aligned with the August 2025 obligations.
Engineering practices
- All data encrypted at rest with AES-256-GCM (Hetzner LUKS + AWS KMS)
- All data in transit TLS 1.3 with HSTS, no TLS 1.0/1.1 support
- Passwords hashed with Argon2id (memory 64 MB, iterations 3, parallelism 4)
- MFA required for all internal staff · hardware keys on production
- Quarterly external penetration test by Bishop Fox
- Bug bounty program · payouts €500–€50,000 · disclosed publicly
- 30-day production backup retention · 7-day point-in-time recovery
- RPO ≤ 1 hour · RTO ≤ 4 hours · tested quarterly
- Production access is audit-logged · personal data access is dual-authorization
- No customer data ever leaves the EEA · zero US sub-processors for personal data
Responsible disclosure
Found something? Email security@drape.studio with a PGP-signed report (key fingerprint 4A9C 7E2F 8B11 D34A 5F92 1C8E B7D4 91A6 33E1 88CC). We acknowledge within 24 hours, triage within 72, fix within 30 days for high-severity. Payouts €500–€50,000 depending on impact. We publicly credit researchers (unless you prefer otherwise) and we maintain a hall of fame.