Security by architecture
Built so you never hand us your data.
Standardization, hashing, and matching all run in your browser — only matches ever cross the wire. There's no raw PII on our side to review. Here's exactly where your data goes, and where it doesn't.
Where your data goes — and doesn't.
- 1
Your browser
Raw PII + real record IDs · standardized & hashed locally · never leaves the device
- 2
DROPAttest server
Append-only audit chain · hashes + record tokens · no raw PII · no record counts
- 3
External witness
RFC-3161 TSA timestamp · in an extensible proof list · standard-tool verifiable
RFC-3161 TSA
Reachable without sign-in. Everything on this page is static — no customer data is loaded or shown.
The four properties.
Never holds raw PII
Only matched hashes and tokens are transmitted.
Never deletes
Deletions are broker-attested, run in your own systems.
Matching validated against DROP's test vectors
The shipped engine passes DROP's published vectors.
spec v1.1.0Tenancy keyed to the registrant
The chain keys to your CPPA registrant — not to any single login.