HeyDrop

For CIOs, IT directors & procurement

Pass procurement on the first call.

The procurement checklist the unapproved card apps in your org fail on every line. SOC 2-aligned controls, GDPR-clean data handling, and contracts your legal team can sign without redlines.

4.9on 18,000+ reviews·300,000+ professionals·137 countries

Why InfoSec keeps blocking this

Three reasons every digital-card platform fails procurement.

01

Unapproved apps today.

Right now, your sales team is using a consumer-grade card app from the App Store - no SSO, no audit log, no DPA, no idea where the data lives. InfoSec finds out at the worst possible moment.

02

Offboard = unbounded risk.

VP of Sales leaves Friday. Her wallet pass with the company logo and 'VP, Acme' stays in 800 prospect phones until the heat death of the universe. There is no revoke button on a paper or consumer-grade card.

03

Brand walks out as 5,000 versions.

5,000 employees, 5,000 different cards, 5,000 different shades of 'the brand.' Your $5M rebrand is invisible because there's no enforcement layer between brand guidelines and what reps actually print.

A procurement-ready platform

Built to pass the security review on the first call.

SSO + SCIM = enforced identity. (coming soon) Google and Microsoft SSO are next on the roadmap; SAML and SCIM follow. Auto-provision on hire date, auto-revoke on departure date. Zero employees with active cards 90 days after they leave - by construction. Today, CSV bulk import and 30-second deactivation cover the same lifecycle.

Custom domain + brand-locked template. Cards live on cards.yourcompany.com, not heydrop.app. Brand template enforced at the org level - colors, fonts, logo, layout, mandatory fields. The 5,000-employee brand audit becomes a checkbox.

Audit log + DPA + subprocessors list. (coming soon) DPA with EU SCCs at /security/dpa. Subprocessors list at /security/subprocessors. Encryption in transit and at rest, scoped OAuth (we hold tokens, not passwords). Account activity reports on request today; the full exportable audit log ships with the enterprise security release. The artefacts your InfoSec team asks for are already published.

Enterprise capabilities

What's actually included on Enterprise plans.

The features procurement asks for and the features that actually matter once you're live.

SSO + SCIM (coming soon)

Google + Microsoft SSO next on the roadmap, SAML + SCIM 2.0 to follow. Auto-provision and auto-revoke against your IdP.

Custom domain

cards.yourcompany.com - SSL provisioned, traffic routed, brand intact end-to-end.

Exportable audit log (coming soon)

Every admin action timestamped. CSV export for InfoSec. Retention configurable per contract.

GDPR-clean by design

GDPR-clean data handling, encryption in transit and at rest, scoped OAuth, full data-subject controls.

Dedicated CSM + QBRs (coming soon)

Named CSM, white-glove onboarding, quarterly business reviews, direct escalation channel.

Brand-locked at scale

Brand template enforced across 5,000+ seats. Multiple templates per group. No drift, ever.

What changes for the org

From contract signature to next year's audit.

Quarter 1

Pilot to 500 seats, brand-locked.

SSO (coming soon) connected, custom domain provisioned, brand template approved, pilot rolled out to one division. CSM runs onboarding sessions for admins.

Quarter 2

5,000 seats live. Unapproved card apps retired.

Full org rollout. The five consumer-grade card apps your reps were using get retired in the IDP. One platform, one audit trail (coming soon), one billing line.

Year 1

Audit closes early.

Auditor asks for the offboarding log. Export takes 30 seconds. Asks for the brand-template versioning. Available in the admin panel. The card platform is no longer a security exception waiting to happen.

100-10k

Seats per deployment

GDPR

Infrastructure + data residency

Custom

Domain + branding end-to-end

Named CSM

Plus quarterly business reviews

Used by enterprise teams

Procurement-ready, security-reviewed, ops-loved.

Field, sales, marketing and people teams across the UK, US and GCC putting HeyDrop into production at enterprise scale.

JW
GBUnited Kingdom

Sales

Three quarters in. Our SDR team scanned 4x more booth leads than last year, and HubSpot was clean for the first time since I joined.
JW
James Whitfield
VP of Sales, Northwall Partners (London)
ER
USUnited States

Marketing

We rolled HeyDrop out to 200+ employees in a week. Zero IT tickets and lead source attribution we can finally trust in HubSpot.
ER
Elena Rodriguez
Marketing Director, GlobalBrand Co. (New York)
KM
AEUnited Arab Emirates

Mobile Workforce

في معارض GITEX، فريقنا التقط ضعف عدد العملاء المحتملين خلال نصف الوقت.
KM
خالد المنصوري
مدير تطوير الأعمال، Gulf Vantage Group (دبي)
SM
USUnited States

HR & Admins

Onboarding takes 90 seconds and saves us thousands a year on reprints.
SM
Sarah Martinez
Head of People Ops, Linthorpe Health (Boston)

Platform

All-in-one networking platform

Built for IT to deploy, RevOps to measure, and every employee to use.

c

For your company

Web admin panel for card management, brand control and performance tracking across the org. Custom domains and dedicated CSM (coming soon) on Enterprise.

e

For your employees

QR code, Apple/Google Wallet card and mobile app to share, scan and push contacts straight to the CRM.

c

For your clients

Branded micro-websites that make it easy to exchange contacts and stay connected with your business.

A real procurement timeline

From security review to org-wide live.

Week 1-4

Security review: Trust Center, security questionnaire under NDA, DPA + EU SCCs reviewed by legal, subprocessors list logged. Pen-test summary on request. Most reviews close inside 4 weeks.

Week 5-8

Contract finalized. CSM kicks off rollout - SSO (coming soon) config, custom domain SSL provisioned, brand template + multi-template architecture approved by Marketing. Pilot division onboarded.

Week 9-16

Org-wide rollout. Five-thousand seats live in waves by division. Shadow-IT card apps decommissioned in IdP. Quarterly review scheduled. Pipeline-from-events attribution ships in HubSpot.

The artefacts InfoSec asks for

Already published.

Trust Center at /security. DPA at /security/dpa with EU SCCs. Subprocessors list at /security/subprocessors. Privacy policy, security practices, data deletion procedures all live. Security questionnaire shared under NDA on request. Open the Trust Center.

  • Custom domain provisioning included on Enterprise plans.
  • Multiple brand templates per division - Sales vs. Field vs. Executives.
  • Audit log (coming soon) exportable to CSV - InfoSec gets a real artefact, not a screenshot.
Enterprise admin panel showing audit log (coming soon), brand templates, and SSO configuration (coming soon)

Procurement-ready

Book a security review.

Custom pricing for 100+ seats. Multi-year commits and rollout services available. Pilot in parallel with paper while contracts close.

CIO & procurement FAQ

FAQ

What's the SSO and SCIM story? (coming soon)

Google and Microsoft SSO are in development and next on the published roadmap, followed by Okta, Azure AD, and SAML 2.0. SCIM 2.0 provisioning ships with the SAML release - auto-onboard the day someone starts in your IdP, auto-revoke the day they leave. Today, CSV-driven bulk provisioning covers onboarding and offboarding.

Is HeyDrop SOC 2 certified?

SOC 2 Type II is on our published security roadmap. Today we operate to SOC 2 controls (encryption in transit and at rest, scoped access, vendor management, incident response). We can share our security questionnaire and ISO 27001-aligned controls map under NDA. See the Trust Center for what's live today vs. roadmap.

Where is data hosted and what's the data-residency story?

Hosted in encrypted US data centers (AWS us-east-1 / us-west-2). GDPR compliance is covered by our DPA with EU Standard Contractual Clauses, and AWS is certified under the EU-US Data Privacy Framework for lawful international transfers. Subprocessors list published at /security/subprocessors and updated under change-control.

Can we use our own domain - cards.acme.com?

Yes. Custom domain (e.g. cards.acme.com) is included on Enterprise plans. SSL provisioned, traffic routed, brand intact end-to-end. The recipient experience is yours, not heydrop.app.

What's the audit log story for compliance reviews? (coming soon)

Audit logging ships with the enterprise security release on our published roadmap, alongside SSO. Today, admin actions are tracked internally and account activity reports are available on request - auditors get a CSV, not a screenshot.

Do we get a dedicated Customer Success Manager? (coming soon)

A named CSM with quarterly business reviews is coming to Enterprise plans. Today, every Enterprise rollout gets white-glove onboarding - rollout plan, brand template setup, training for admins and end-users - plus a direct escalation channel to the founding team.

What's the DPA and contracting process?

Standard DPA available at /security/dpa with EU SCCs included. Master Services Agreement available for negotiation; we accommodate enterprise legal review. Typical signature cycle: 2-4 weeks depending on your contracting team. Pilot can start in parallel with paper.

What's pricing for an enterprise rollout?

Custom - based on seat count, contracting depth, and rollout services scope. As a reference: 500 seats lands well below comparable enterprise platforms; 5,000+ seats benefits from volume pricing. Multi-year commitments unlock further discount. Talk to sales.