Skip to main content
Driftstack DRIFTSTACK

Account

Privacy & security

Password, two-factor authentication, active sign-ins, connected accounts, and control over your data. Changes here affect all sessions, profiles, and webhooks under this account.

Your data is protected

Saved profile state and recoverable credentials are encrypted at rest with context-bound wrapping under platform-held keys.

Profile encryption

AES-256-GCM at rest

Profile state is stored as ciphertext; when it is used, the platform unwraps its bound key for that authorized session.

Envelope binding

Context-bound encryption

Authenticated encryption binds wrapped values to the owning account and, for record-scoped stores, the exact record and value slot.

Credential audit

Recorded management events

Review credential-management events that were recorded in your audit log. Routine runtime use is not logged as a credential-read event.

Full model at driftstack.dev/trust · export and deletion are request-based today; start in the danger zone.

Security

Password + recovery options.

We email you a magic link to confirm. The link expires after 60 minutes; old sessions stay signed in until they naturally expire.

Two-factor authentication

Add a TOTP code from your authenticator app on top of your password. Recovery codes are issued at enrollment — store them somewhere safe; without your authenticator AND your recovery codes, account access requires support intervention.

loading…

Active sign-ins

Browser sessions where you're signed in to the dashboard. Distinct from the automation sessions you run in the Driftstack desktop app.

  • Sign in to load your active sessions.

IP omitted for privacy. The "current" session is the one you're using right now and can't be revoked from this list — sign out from the menu instead.

Connected accounts

IDPs (Google / GitHub) linked to your account. Each link lets you sign in via that provider. Revoking the link on the provider side (e.g. Google → Security → Third-party access) automatically marks it inactive here on next sign-in attempt; password sign-in continues to work either way.

  • Sign in to load your linked accounts.

Recent activity

API key mints + revokes, session lifecycle events, and other account changes. Newest first; filtered to your own account.

  • Sign in to load recent activity.

Danger zone

Account deletion is irreversible. All sessions, profiles, API keys, and webhook endpoints are immediately revoked, and stored account data is purged on the schedule in the privacy policy. Invoice history retained per Dutch tax law (7 years) — not deletable on request.

Deletion is currently processed by emailing support@driftstack.dev so we can confirm + walk the data-portability export with you before the irreversible step.