End-to-End Security Measures
DroneDeploy offers a comprehensive security solution to safeguard customer data with multiple layers of protection. Whether utilizing DroneDeploy Aerial or DroneDeploy Ground applications, all information is encrypted in transit (TLS 1.2+) and at rest (AES 256), with continuous monitoring for performance, reliability, and security. Additionally, the platform adheres to industry-leading compliance certifications and regulations such as SOC 2 Type 1, SOC 2 Type 2, ISO 27001, PCI/DSS, Privacy Shield, and GDPR.
Robust User Access Controls
DroneDeploy provides robust identity and user management tools to ensure data access is restricted to authorized personnel. Features like Single sign-on (SSO) with Google SSO and two-factor authentication (2FA), as well as Enterprise SSO for authentication against various providers, enhance security while simplifying the user experience. The platform also offers different user roles (admin, editor, viewer, coordinator) with specific permissions, along with activity audit trails for monitoring and tracking interactions.
Data Infrastructure Security
From data capture to storage, DroneDeploy ensures robust data infrastructure security. Hosting data in AWS and Google Cloud with physical security measures and access restrictions, the platform employs data encryption in-transit and at-rest to prevent unauthorized access. Annual penetration testing, stringent physical access controls, and collaboration only with trusted service providers further contribute to the stringent security measures.
Product and Application Security
DroneDeploy emphasizes product and application security by integrating security and privacy by design principles into feature development. Every new feature undergoes rigorous risk assessments and security reviews to meet industry standards. The platform implements a Secure Development Lifecycle (SDL) and OWASP Top 10 practices, conducting security reviews, code audits, and bug bounty programs to identify and address security vulnerabilities.
Extend Security to Hardware
Apart from cloud security protocols, DroneDeploy offers additional security measures for fixed assets like DJI’s Dock 1 and Dock 2, and the DJI Mavic 3 Enterprise. The Firewall offering adds another layer of security by ensuring data transmission to trusted DroneDeploy servers in the U.S. with dedicated IP addresses. For those concerned about privacy, Privacy Mode conceals faces and bodies in Walks in DroneDeploy Ground for enhanced privacy protection.