Skip to content

Security & Privacy

Drovio has been designed with security and privacy as a top priority. Based on WebRTC, we leverage a P2P architecture to handle customer communications, whether for screen sharing, audio chat, file transfer or messaging. Communication between user endpoints is end-to-end encrypted, and in ~85% of screen sharing sessions the media never transits our servers (see Connection flow). Drovio Server handles authentication and signaling, but it never holds the keys to the media stream: we can't see or hear what you're doing. We also store only the minimum information needed to provide the service.

Enterprise (on-premises): nothing reaches our servers

For our most demanding customers, we've built a complete on-premises edition that requires no Internet connection, and thus no communication whatsoever with our servers. Contact us to learn more.

Applies to both editions

Whether you're interested in our Cloud (SaaS) or Enterprise (on-premises) edition, everything here applies unless stated otherwise. Sections labelled (Cloud edition) are specific to the hosted service. Who operates what is set out in Shared responsibility.

In this section

  • How Drovio works


    The WebRTC/P2P architecture, signaling, STUN & TURN, with the protocols and ports involved.

    Architecture & data flow

  • Session access & control


    Who can join a session, what guests see, and how remote control is granted and revoked.

    Session access & control

  • Data protection


    Hosting, encryption in transit and at rest, what we store, and data retention.

    Data protection

  • Compliance


    GDPR roles, sub-processors, international transfers and data subject rights.

    Compliance & data processing

  • Operations


    Network & endpoint security, penetration testing and certifications.

    Operational security

  • Shared responsibility


    Who operates what, depending on whether we host Drovio or you do.

    Shared responsibility

Key principles

  • End-to-end encryption of all user media and data between their endpoints.
  • P2P by design: in most sessions, the media doesn't transit Drovio servers.
  • Data minimization: only the strictly necessary user data is stored.
  • No card data: payments handled by Stripe, a PCI-compliant provider.
  • On-premises option: a fully self-hosted deployment with no Internet dependency for customers with the highest requirements.