This page covers the desktop products. If you use the cloud-hosted Draftable API or Draftable Online, your documents are processed on our infrastructure and different handling applies. For company-wide certifications and controls, see Security and compliance at Draftable.
Your documents stay on your machine
When a user compares two documents, every stage of that work happens locally:- Documents are read from local disk, your network shares, or your document management system.
- Conversion, comparison, and rendering all run in processes on the user’s own machine.
- Outputs such as PDF redlines, Word tracked-changes documents, and side-by-side views are written back to locations you control.
What does leave the machine
The application makes a small number of outbound HTTPS connections, none of which carry document content. Two are required and two are optional.Telemetry
Telemetry helps us understand how the product is used and where it can be improved. It is designed so that it cannot identify a person:- No personally identifiable information is collected. No names, no email addresses.
- No potentially identifiable information is collected either. Telemetry is not linked to specific users, licences, IP addresses, or organisations.
- Data captured covers usage counts, file types and sizes in kilobytes, feature usage, performance timings, error rates, system configuration, and interaction patterns.
- Telemetry is never used for direct sales or marketing.
Product Telemetry
Full detail on what telemetry captures and how it is used. A complete field list is available on request.
Error reporting
If the application hits an unexpected error, it can send a diagnostic report to help us fix the problem. These reports carry diagnostic information, not your documents. Users can disable error reporting in settings, and administrators can disable it through Group Policy.Sharing files with support is always your decision
Occasionally a comparison problem can only be diagnosed by looking at the files involved. Draftable never takes those files automatically. Instead:- Sharing is user-initiated. Nothing is sent unless someone actively chooses to send it.
- The application includes Create safe file for sharing (called the Document Obfuscator before version 26.6), which scrambles the content of a document pair first, so we receive the structure needed to reproduce the fault without the confidential text.
- Administrators can switch the capability off entirely through Group Policy, so that obfuscated documents cannot be sent at all, including from within error dialogs.
How to create a safe file for sharing
What the process does to your document, so you can decide whether to use it.
Document management system connections
Draftable integrates with iManage, NetDocuments, SharePoint, Worldox, and Epona. These integrations connect the desktop application directly to your own DMS. Documents move between your DMS and the user’s machine; they do not route through Draftable. Authentication is handled by your DMS using your existing identity and access controls, including single sign-on and conditional access where you have them configured.Office and Outlook add-ins
Draftable’s Office and Outlook add-ins communicate with the desktop application overlocalhost on the user’s own machine. Comparison still happens locally.
Administrator controls
Draftable Legal is built for managed enterprise deployment, and the security-relevant behaviour above is centrally controllable.- Deployment options. A per-user EXE installer with automatic updates, or a machine-wide MSI for enterprise, Citrix, and RDS environments where you want to control update timing yourself.
- Group Policy. ADMX and ADML templates are provided so that settings can be managed through your existing Group Policy infrastructure, or through Microsoft Intune.
- Policy precedence. Settings resolve in a fixed order, with machine and user policy taking precedence over user-set preferences, so a policy you set cannot be overridden locally.
Most common registry configurations
The settings administrators most often apply, including privacy and telemetry controls.
System and network requirements
Specifications and connectivity to confirm before deployment.

