Skip to content

Security Model

Dripelo is built with bank-grade security. Your sign-in is phishing-resistant, your funds are safeguarded, and you always stay in control.

How You Sign In

Dripelo uses passkeys instead of passwords. A passkey is created on your device and protected by your biometrics (Face ID, Touch ID, or fingerprint).

  • No passwords: Nothing to remember, nothing to leak
  • Phishing-resistant: A passkey is bound to Dripelo and can't be stolen or copied like a password
  • Device-bound: Your passkey lives in your device's secure hardware
  • Biometric protection: Every sensitive action needs your Face ID or fingerprint

Verified Identity

Your social handle, phone number, or email is linked to your account so people can pay you without account numbers:

  • Verified ownership: You prove you own the handle via OAuth, SMS, or email
  • Privacy preserved: Phone and email are stored as secure hashes, never in the clear
  • Permanent link: Once registered, your handle is bound to your account

Safeguarded Funds

  • Encryption: Your data is encrypted in transit and at rest
  • Hardware isolation: Sensitive systems run on isolated, secure hardware
  • Regulated: Dripelo follows identity verification (KYC) requirements as a regulated broker
  • You stay in control: No one can move your money without your approval

How Approvals Work

When you make an investment, send money, or change a sensitive setting:

  1. You authorize with your passkey (Face ID, fingerprint, etc.)
  2. Dripelo verifies the request against your account
  3. The action is completed securely
  4. Nothing happens without your explicit approval

Security Guarantees

  1. No single point of failure: Sensitive systems are isolated and independently protected
  2. Phishing-resistant: Passkeys are bound to Dripelo and cannot be stolen like a password
  3. You approve everything: No money moves without your authorization
  4. Hardware-backed: Critical infrastructure runs on isolated, secure hardware

Comparison

vs. Passwords

PasswordsDripelo
What you storeA secret to recallA passkey on your device
Can be phishedYesNo
If leakedAccount at riskNothing to leak
RecoveryReset email/SMSPasskey sync or backup recovery

vs. Traditional Brokers

Traditional brokerDripelo
Sign-inPasswordPasskey
Phishing-resistantRarelyYes
Your approval neededNot alwaysAlways

Is the code open-source?

Partially yes, and we'll strive to be fully open-source in the future.