πŸ›‘οΈ Trust & Security

Built for enterprise trust.

Dragonfly moves high-value cargo for regulated industries β€” pharmacies, healthcare, corporate catering, government contracts. Here's how we protect every stakeholder on the platform.

πŸ’°

$5M commercial insurance per delivery

Every order is covered from pickup to delivery against loss, theft, and damage. Coverage includes auto, cargo, and general liability. Certificate of insurance available to enterprise clients on request.

Carrier: National specialty insurance
πŸ₯

HIPAA-aware pharmacy & medical delivery

Chain-of-custody tracking, tamper-evident packaging protocols, delivery-to-patient-only options, and signed-receipt confirmation. We don't store PHI β€” the tracking metadata stays with the pharmacy's own system.

Privacy-first by design
πŸ”

Stripe-grade payment infrastructure

PCI-DSS Level 1 processing via Stripe and Coinflow. We never touch raw card data β€” tokenized at the browser. Driver payouts run through Coinflow's KYB-verified rails with bank-grade encryption.

PCI DSS Level 1 Β· Tokenized
πŸ§‘β€βœˆοΈ

Vetted, trained, professional drivers

Every driver passes a Checkr background check (MVR + criminal). Onboarding includes white-glove delivery training, photo-verified uniform, and signed independent contractor agreement. Drivers rated every delivery β€” underperformers removed.

Background check Β· 98.5% on-time
πŸ“Š

Audit-ready delivery logs

Every order has a complete trail: pickup timestamp, GPS route, delivery timestamp, recipient photo/signature. Exportable via dashboard for audit, reconciliation, or compliance review. Retained 7 years.

7-year retention Β· CSV + API export
πŸ‡ΊπŸ‡Έ

US data residency

All production data lives in US-based Supabase/Postgres clusters. Our stack (Vercel, Stripe, Supabase, Coinflow) is US-hosted. No cross-border data transfers by default. EU/CA residency available for enterprise tenants.

US-only by default
πŸ“ˆ

SOC 2 Type II on the roadmap

Dragonfly is actively preparing for SOC 2 Type II certification in 2026. Vanta-style continuous monitoring covering security, availability, and confidentiality. Target audit window: Q4 2026. Contact us for current controls mapping.

Audit window Q4 2026
πŸ›οΈ

Government-ready

Dragonfly is SAM.gov registered and actively tracks 656 federal contracts. We're bidding on USPS Surface Transport ($5M) and DOD catering packages. Cage code and DUNS on request.

SAM.gov Β· 656 contracts tracked

Compliance & certifications

At-a-glance status for regulated buyers and procurement teams.

Control / StandardStatusNotes
PCI DSS Level 1 (payments)CompliantVia Stripe + Coinflow; Dragonfly never handles raw card data
HIPAA-aware deliveryCompliantOperational controls; BAA available for enterprise pharmacy clients
SOC 2 Type IIIn progress Β· 2026Audit window Q4 2026. Trust report available under NDA
GDPR / CCPACompliantPrivacy policy + data-subject request flow live
COI / Cargo insuranceActive Β· $5M/deliveryCertificate on request via Enterprise Sales
SAM.gov / FederalActive registrationCAGE code + DUNS on request
Driver background checksEvery driver, pre-activationCheckr-powered MVR + criminal history
Bug bounty / responsible disclosureEmail-based Β· 2026 roadmap[email protected]

Security questionnaire or COI?

Enterprise buyers: we respond to vendor-risk questionnaires, DPA requests, and COI requests within 2 business days.

Report a security issue: [email protected]