Third Party Index

Snapshot 16281

Document
Trust center
URL
https://trust.dronedeploy.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
134363 bytes
SHA-256 (raw)
fd81ed68d319fd40a766489e8d2cca44cb53600abe836808a465a48d155e0c0f
SHA-256 (normalized text)
c244def787449a435215940a00d3a2604b2639777fbd54207f8de3031b546f5d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
DroneDeploy
DroneDeploy is the unified reality capture platform that brings drone, ground, and robotic imagery together into measurable maps, 3D models, and digital twins for field operations across construction, energy, and more. Teams use it for flight planning, capture, inspection, and progress tracking—with Procore/Autodesk Build integrations and AI (Safety AI, Progress AI) to move faster.
[email protected]
Privacy PolicyOpens in new tab
Welcome to the DroneDeploy Trust Center! Protecting your data is fundamental to how we design, build, and operate our platform. This hub showcases our security, privacy, and compliance program, along with the certifications and frameworks that validate our approach. Explore how our layered controls safeguard the platform and your information, and request access to detailed security and privacy documentation when needed.
You can immediately access public materials. Gated materials—including SOC 2 reports and penetration test reports —are available upon request and require an NDA. You can also subscribe to receive notifications about new documents and security communications.
Compliance
ISO 27001:2022
SOC 1 Type 2
SOC 2 Type 2
SOC 3
GDPR
US Data Privacy
CCPA
EU AI ACT
Swiss-US DPF
PCI DSS - SAQ A
Resources
View all
DroneDeploy 2025 SOC 2 Type 2 Report.pdf
DroneDeploy Web Application Security Assessment 2025.pdf
DroneDeploy Data Handling Practices Limited Assurance Report 2025.pdf
Certificate of Good Standing - Delaware 250820.pdf
DroneDeploy Form W9.pdf
UK Employers' Liability Insurance (ELI) Certificate.pdf
Controls
View all
Product Security
Audit Logging
Application Penetration Testing
Integrations
View 3 more Product Security controls
Data Security
Data Asset Classification
Access Monitoring
Data Backups
View 6 more Data Security controls
Infrastructure Security
Cloud Workload Protection
Google Cloud Platform
Infrastructure Security
AI
AI Security
AI Risk Management
Third-Party AI Diligence
View 2 more AI controls
Legal
Master Service Agreement
Privacy Policy
Data Processing Agreement
View 4 more Legal controls
ESG
Anti-Bribery and Corruption
Anti-Modern Slavery
Code of Ethics
View 3 more ESG controls
Subprocessors
View all
Amazon Web Services
•
Cloud service provider
United States
BrainTrust
•
Safety AI - Fine Tuning prompts
United States
Cloudflare
•
Content delivery network
United States
Google
•
Cloud service provider
United States
Updates
View all
Security
External Perspective on DroneDeploy’s FedRAMP 20x Readiness
Published May 26, 2026
This external post from First Information Technology Services (FITS) shares their perspective on DroneDeploy’s recent FedRAMP 20x gap analysis and the roadmap developed from that work.
It highlights FITS’s view that FedRAMP 20x centers on continuous, evidence-driven assurance, including persistent validation and machine-readable telemetry, as organizations prepare for 20x readiness.
Read the full post here: First Information Technology Services LinkedIn postOpens in new tab.
Security
DroneDeploy’s Journey Toward FedRAMP-Aligned Security
Published May 26, 2026
We recently published a blog post about DroneDeploy’s work to align our security program with FedRAMP 20x.
The post explains why we are investing in FedRAMP-aligned security, our work with a specialized advisory firm and an accredited 3PAO, and how this effort supports public-sector and other regulated customers.
Read the full post here: DroneDeploy’s journey toward FedRAMP-aligned securityOpens in new tab.
Security
Important Update to DroneDeploy's Vulnerability Disclosure Program
Published January 23, 2026
DroneDeploy is updating our Vulnerability Disclosure Program. Effective immediately, we are no longer offering financial compensation for vulnerability reports.
What This Means
For Future Submissions:
We continue to accept vulnerability disclosures through our standard reporting process
Reports submitted after January 23, 2026 will not be eligible for financial compensation
We will not be responding to vulnerability reports going forward
All submissions are still covered under our Safe Harbor provisions
For Existing Submissions:
All vulnerability reports submitted prior to January 23, 2026 will continue to be processed according to the original policy terms
Valid vulnerabilities from past submissions will still receive appropriate compensation as determined under the previous policy
We remain committed to completing the review and remediation process for all existing reports
Why This Change
This update allows us to focus our security resources on remediation and system improvements while maintaining our commitment to responsible security research through our Safe Harbor provisions.
Updated Policy
Our updated Vulnerability Disclosure Policy is available in the Resources section of this Trust Center. The policy continues to provide:
Clear scope and guidelines for security research
Safe Harbor protections for authorized research activities
Instructions for reporting vulnerabilities
We appreciate the security research community's continued contributions to improving our security posture.
Questions? For questions about this update, please contact [email protected].
Compliance
Update on FCC Covered List Action and Foreign-Produced Drones
Published December 23, 2025
The FCC Covered List was recently updated to include foreign-produced drones and certain components, which has raised understandable questions for many of our customers. As explained in our latest blog post, this action primarily affects future approvals of new drone models and does not ban or ground existing, already authorized aircraft. Your current DroneDeploy-enabled fleet can continue operating under current rules.
The DroneDeploy platform remains hardware agnostic, giving you flexibility to plan for long-term fleet strategy and diversification while maintaining consistent data capture, analytics and security controls, including Firewall, local data modes and ISO-certified cloud security.
For a clear, fact-based overview of what this update means and how to plan ahead, please read our full blog post: [Foreign drones and the FCC Covered List: a fact-based guide for compliance teams](https://www.dronedeploy.com/blog/foreign-drones-and-the-fcc-covered-list-a-fact-based-guide-for-compliance-teams#quick-summaryOpens in new tab)