Executive Summary
AI-generated analysis for Drift
Drift (drift.com), a conversational marketing and sales platform now operating under the Salesloft brand, presents a Moderate Risk (Tier 3) profile based on independently sourced evidence. The platform handles customer engagement data at a medium data access level, warranting structured due diligence before procurement or renewal. Positive signals include:
Key Findings
- A 30-year-old domain with no blacklist presence on SURBL, Spamhaus DBL, or Malware detection service
- A minimal infrastructure footprint of just 2 open ports (80, 443) behind Cloudflare CDN, with zero known CVEs — well below the SaaS industry average of 8–12 open ports
- A clean IP abuse score of 0% with whitelisted CDN infrastructure
- An HTTP security grade of B (70/100) with HSTS enabled
- A SOC 2 compliance claim on the vendor's published security page, pending independent verification
- No adverse media, no sanctions matches, and no regulatory enforcement findings Several concerns require attention before this vendor can be fully cleared. The domain registration expires in 21 days — while the domain is managed by SafeNames Ltd., an enterprise-tier registrar with automatic renewal capabilities, the proximity of expiration warrants explicit confirmation. A documented security incident involving Drift and its parent company Salesloft was discussed in the technical community in September 2025, referencing impact on downstream customers including Cloudflare users; this incident requires clarification from the vendor. Additionally, no publicly accessible AI data usage policy was found, which is a meaningful gap for a platform with conversational AI features. Subprocessor data could not be automatically parsed from the vendor's published page, and certificate management practices across 27 certificate authorities should be reviewed. Overall, Drift presents a manageable risk profile contingent on resolution of the security incident disclosure, domain renewal confirmation, SOC 2 report verification, and AI data handling clarification. Conditional approval is appropriate pending these items.
Independence Statement
All evidence in this report was sourced independently by ThirdProof through external data queries conducted without vendor participation or notification.