First mandatory DROP cycle begins August 1
Don't just clear the DROP cycle — prove you did.
Matching runs in your browser, so PII never leaves your device. You run the deletions; DROPAttest turns every 45-day cycle into a tamper-evident, externally witnessed evidence package — the thing you hand the auditor in 2028.
How it works
One 45-day cycle — file in, evidence out.
Step 1 · Load
No integration — just drop the file.
Step 2 · Map
Map once, reuse every cycle.
Step 3 · Match
Nothing leaves your device.
Step 4 · Confirm
You make the call; the chain records it.
Step 5 · Submit
Every cycle ends in evidence.
Cycle complete
What left your device: nothing. What you keep: proof.
Every record was standardized and SHA-256 hashed in your browser — only matches were transmitted — and the whole cycle landed in a tamper-evident, externally witnessed evidence package.
0 bytes of PII off-device · 1 evidence package
How it works
One 45-day cycle — file in, evidence out.
- 1LoadNo integration — just drop the file.
- 2MapMap once, reuse every cycle.
- 3MatchNothing leaves your device.
- 4ConfirmYou make the call; the chain records it.
- 5SubmitEvery cycle ends in evidence.
Security by architecture
Built so you never hand us your data.
The heaviest part of a privacy purchase is the security review. There's simply no raw PII on our side to review.
PII never leaves your browser
Standardization, hashing, and matching all run client-side. Only matches — a work-item ID and a salted record token — are ever transmitted.
You hold the data; you run the deletions
DROPAttest never takes custody of raw records and never executes a deletion. You export the worklist and run it in your own systems.
Tamper-evident, externally witnessed
Every write extends an append-only hash chain whose head is externally timestamped — so the archive's integrity is provable, not just asserted.
Honestly scoped proof
Internally tamper-evident, externally witnessed; deletions are broker-attested. We prove what happened — we don't claim to have done it for you.
Pricing
One flat price. No quotes, no procurement.
Enterprise privacy suites hide behind a sales call. DROPAttest is built for a 2–20-person broker and priced like an expense report.
DROPAttest
$499/mo, flat
One price for every broker. No tiers, no quotes, no procurement.
Book a setup call- All six DROP list types — NDZ, Email, Phone, MAID, NameVIN, CTVID, composites included
- Unlimited 45-day cycles, with a live deadline countdown
- Client-side matching — raw PII never leaves your browser
- Delete worklist export (CSV / SQL) + upload-ready response file
- Tamper-evident, externally-anchored evidence package
- Multi-cycle history dashboard — your audit archive from cycle one
Your first cycle, free — and I run it with you.
The first brokers to come on get their first full 45-day cycle at no cost, hands-on white-glove onboarding for that cycle, and a direct line into the roadmap. Then it's $499/mo, locked for life — the price rises for everyone who waits, never for you. Cancel anytime.
Claim a founding spotFAQ
The questions brokers actually ask.
Do you see our data?
No. Standardization, hashing, and matching all run in your browser. Raw PII and your real record IDs never leave the device — the server stores only salted tokens.
Do you delete records for us?
No. You export the delete worklist and run it in your own systems. DROPAttest produces the proof; deletions are broker-attested. That's deliberate — it keeps you in control and keeps us out of your security review.
We're looking at OneTrust / Transcend / Ketch — why you?
They orchestrate deletions inside their cloud: you connect your consumer data to their systems, sign an annual contract, and run an integration project. DROPAttest never sees your data and exists to produce proof. And honestly: if you need deletion orchestration across dozens of connected systems, they're the right buy — we'll tell you so on the call.
Which DROP list types do you cover?
All six — Email, Phone, MAID, NDZ, NameVIN, CTVID — including the composite hash-of-hashes, validated byte-for-byte against CPPA's published golden vectors.
What do I hand the auditor in 2028?
A tamper-evident evidence package: an append-only, hash-chained log of every cycle, externally timestamped, with each request's determination mapped to DROP's codes (Delete, Exempt, Opted-out, Not found).
How is this different from a spreadsheet?
A spreadsheet can't standardize to DROP's exact hashing, can't prove it wasn't edited after the fact, and won't produce an upload-ready response file. Miss a real match and it's a missed deletion — $200 per request, per day.
Can we still be ready before August 1?
Yes. There's no integration project — you upload your DROP export in the browser and run your first cycle the same day. A suite bought today starts with an implementation kickoff; you'd start with the cycle.