Skip to content

Status and reliability

Citeable facts about how drophost stays online, what we do and do not promise for uptime, and how to report security issues. This is not a live incident board with historical SLAs.

Last updated: October 3, 2026

Claims you can cite

  • Link retention. Project URLs stay live until you delete the project (or we remove them for abuse, legal, or account closure reasons). Full policy: Retention and hosting.
  • Replace keeps the URL. Uploading a new file to the same project updates the bytes without minting a new path.
  • No published uptime percentage. drophost does not currently publish a numerical SLA or historical uptime metric on this page.
  • Hosting stack. The app runs as a Next.js service (typically on Vercel). Uploaded objects are stored in Cloudflare R2. Application data lives in Neon Postgres. Auth is Clerk. Billing is Autumn with Stripe payment processing.

What uptime means here

For drophost, "uptime" means recipients can open your share URL over HTTPS and the app can accept sign-in, publish, and project management. Share delivery depends on the app host, object storage, and DNS for drophost.space subdomains or custom domains.

We aim for reliable sharing. We do not guarantee uninterrupted or error-free operation. Maintenance, provider incidents, rate limits, and abuse mitigation can temporarily affect access — as stated in the Terms of Service.

Free projects may be rate-limited or removed for abuse or operational reasons. drophost is not a backup product.

How hosting works

Production pieces that matter for reliability:

  • Next.js app and edge delivery — typically Vercel
  • Cloudflare R2 — object storage for uploaded files and site assets
  • Neon (PostgreSQL) — projects, users, and related metadata
  • Clerk — authentication sessions
  • Autumn / Stripe — paid plan entitlements

Public files are served from project share routes (for example /s/{slug}), including named *.drophost.space hosts. Static sites are HTML, CSS, and JavaScript only — there is no PHP or Node runtime for visitor sites.

Details on how long content stays online are on Retention and hosting.

Security reporting

Report security vulnerabilities privately to savonen.emppu@gmail.com. The same contact is published in /.well-known/security.txt.

Do not use public issues for active exploits. Product feedback that is not a vulnerability can go through Feedback in the dashboard.

How this page is updated

When hosting providers, retention rules, or security contact methods change, we update this page and the retention policy. We do not invent outage history or uptime percentages here.

Also see Retention and hosting.