Security
How DriftLess protects your account and site data
Keys, sessions, data handling, and platform safety in plain language.
- Your site and account data are private to your account.
- We protect files and version history with access checks.
- Maker-confirmed public HTTPS payment links send customers to the maker’s provider. DriftLess does not receive buyer contact, delivery, payment, order, refund, dispute, chargeback, or payout data through those links.
- Card and bank details stay with the maker’s chosen provider and are never stored by DriftLess.
- Session-based login with time-limited cookies.
- Optional Google and GitHub sign-in.
- Passwords are hashed, never stored as plain text.
- We do not sell your data.
- We do not expose API keys.
- We do not bill model usage through hidden markups.
- The website never calculates prices or marks an external payment as paid.
- DriftLess may reject an obviously fictional identity entry, but it does not check a company register or perform business or merchant identity checks.
- Most makers never need to add provider keys.
- Advanced teams can add their own provider keys.
- Keys are encrypted at rest and never logged or exposed.
- You pay model providers directly when you choose this option.