The DROP workflow, operationalized end-to-end.
DropAudit turns the California Delete Act's recurring obligations into a structured, audit-ready operating system for your privacy and compliance team.
1. Receive your DROP deletion list
You authenticate to DROP with your own credentials and download your deletion list each cycle, then send it to DropAudit. Planned intake paths are file upload, SFTP, and a signed ingestion API. We never access DROP, and the data model is designed for hashed identifiers only — never raw PII in transit.
- You retrieve, we ingest
- Signed payload verification
- Identifier-only data model
2. Match identifiers against internal systems
Deterministic and probabilistic matching against your CRM, warehouse, marketing stack, and identity graph. Every match is logged with confidence.
- Hashed email / phone matching
- Deterministic & probabilistic
- Confidence scoring + thresholds
3. Create deletion & suppression tasks
Auto-generate deletion tasks with owners, SLAs, and approval gates. Persistent suppression prevents re-ingestion on future data loads.
- SLA timers per request
- Approval workflows
- Persistent suppression list
4. Route requests to vendors & service providers
Dispatch deletion instructions to downstream processors via API, email, or webhook. Track acknowledgments and escalate stalled vendors.
- Native vendor connectors
- Email-based fallback
- Acknowledgment tracking
5. Export audit-ready evidence
Generate immutable evidence packs with hashes, timestamps, and chain of custody — formatted for CPPA inquiries and internal audit.
- Immutable cryptographic logs
- Per-cycle evidence packs
- PDF + CSV exports
Built to be defensible in front of the CPPA.
SOC 2 architecture
Designed against SOC 2 Type II controls. DropAudit is not SOC 2 certified today — see the Security page for current status.
Identifier-only model
Designed to work in hashes, so raw consumer PII stays in your stack.