Terms & Policies
Transparency, privacy, and security are at the core of Flux Drop. Here you can find our legal frameworks and commitments.
Security Policy
Last updated: July 15, 2026
On this page
1. Encryption Standards
Security is built into every layer of Flux Drop. All data in transit is encrypted using TLS 1.3 (with fallbacks to TLS 1.2 for older clients) to secure connections between user applications and our servers. Data at rest is encrypted using AES-256 storage solutions, ensuring that your raw files cannot be read directly from physical storage media.
2. Access Control & Authorization
We implement strict security measures to protect account credentials and API keys. API keys are hashed at rest, meaning that even in the case of a database dump, your actual keys remain private. We advise users to rotate API keys regularly and restrict access. Access to files is verified on every request through signature verification rules.
3. Isolated Project Storage
We employ logical data isolation to ensure that every user's files and project data are separate. Storage paths are hashed using random, cryptographically secure IDs, preventing directory traversal attacks or unauthorized file access by third parties, even if they guess file names.
4. Responsible Vulnerability Disclosure
We welcome security researchers and developers to report any vulnerabilities found on our platform. If you discover a security issue, please contact us privately at security@fluxdrop.pl. We request that you do not publish details of the vulnerability until we have had reasonable time to patch it. We will cooperate to resolve the issue as quickly as possible.
Have questions about our terms?
Our compliance and support team is ready to assist you. Get in touch with us if you need further clarification.