Security claims should be specific and verifiable.
AmazonDrift separates safeguards implemented on the public website from production-application requirements and independently verified certifications.
Current safeguards on amazondrift.com.
The marketing website uses practical controls for browsing and lead-form submissions.
HTTPS enforcement
Requests are redirected to HTTPS on supported production hosting.
Browser security headers
Content Security Policy, clickjacking protection, referrer controls and MIME-sniffing protection are configured at the server layer.
Protected forms
Lead forms use CSRF tokens, server-side validation, a honeypot and basic submission throttling.
Restricted lead storage
Lead files are kept in a protected directory with directory listing disabled and restrictive file permissions.
Controls required before customer operational data is broadly connected.
These items describe production requirements, not completed certifications.
Tenant separation
Customer organisations and their business records must remain isolated from one another.
Least-privilege access
Owners, managers and team members should only see the brands, records and actions their role permits.
Attributable activity history
Important operational and approval actions should be attributable to the responsible user.
Protected transport and sessions
Production access should use HTTPS, secure authentication and appropriately protected sessions.
Backup and recovery
Production data should have documented, tested backup and restore procedures.
Use three labels: implemented, required, independently verified.
Buyers should be able to tell whether a security statement describes a control that exists now, a release requirement or an external assurance that has been independently achieved.
- Implemented: controls currently in place.
- Required: production safeguards that must be satisfied for the relevant release scope.
- Independently verified: certifications or external assurance that can be validated.
- Planned integrations are kept separate from available connections.
Implemented
HTTPS redirect, security headers, CSRF protection, validation and protected form storage.
Required
Tenant isolation, least-privilege permissions, attributable activity, secure access and recovery.
Not currently claimed
No SOC 2 or ISO 27001 certification is presented as achieved.
Contact
Send security or data-handling questions through the contact page before connecting business data.