Skip to main content
Draftable is used by law firms, corporate legal teams, and regulated businesses to compare and clean documents that are confidential, privileged, or commercially sensitive. Our security programme is built around the high standards our customers expect of us.
Draftable is part of Affinda Holdings Pty Ltd. Our Information Security Management System is independently certified and covers the Draftable brand, across our cloud services and software our customers run on their own infrastructure.

Independently certified

ISO/IEC 27001:2022

Certified Information Security Management System covering the Draftable product family.

SOC 2 Type II

Independent attestation covering the Trust Services Criteria for Security.

Penetration testing

Our web application and API are tested by an independent third-party security firm.
Certificates and reports are published in our Trust Center, which is always the authoritative record of our current status rather than any date or figure quoted in documentation.
Certifications are maintained on a recurring audit cycle. Where a certificate is within its recertification period, a bridging letter confirming continuity of the certified management system is made available alongside it. If you are completing a security review and need that letter, request it through the Trust Center or contact support@draftable.com.

Visit the Draftable (Affinda) Trust Center

Certificates, security practices, and policy documents. Most items are access-controlled and will prompt you to request access using your work email.

How we protect your data

Encryption

We maintain a formal cryptography standard defining which algorithms, key sizes, and protocol versions are permitted across every Draftable product and system. Weak and legacy primitives, including MD5, SHA-1, DES, 3DES, RC4, and ECB mode, are prohibited rather than merely discouraged.

Access control and monitoring

Access to systems holding customer data is restricted to authorised personnel on a least-privilege basis and protected by multi-factor authentication. All read and write access to customer data is logged, and repositories of customer data are documented and reviewed at least quarterly.

Secure development

Draftable follows a formal Software Development Life Cycle covering code review, change management, and security testing. Findings from penetration tests and vulnerability scanning are tracked to remediation against defined timeframes based on severity.

Resilience and availability

Our cloud services run on Amazon Web Services. Customer documents are held in Amazon S3, designed for 99.999999999% durability, with application data in Amazon RDS.
  • Backups. Production databases are backed up daily and encrypted with AES-256, with a minimum retention period of 30 days unless a documented exemption applies.
  • Compensating measures. Where conventional backups are not viable, such as for object storage at scale, documented compensating controls are used instead, including bucket versioning.
  • Continuity. We maintain documented and tested business continuity and disaster recovery plans, with defined response teams and an order of succession.

Reporting a vulnerability

We operate a responsible disclosure programme and welcome reports from the security community. We commit to a timely response, an open dialogue through investigation and remediation, and attribution once a finding is validated and fixed. We provide safe harbour: we will not pursue legal action against researchers who test in good faith, avoid harm to Draftable or our customers, hold off on public disclosure until a mutually agreed date, and comply with applicable law.

How to report a vulnerability

What we consider a vulnerability, what to include in a report, and where to send it.

Privacy and data protection

Our handling of personal data is governed by our Privacy Policy. We maintain a data protection policy and a data classification scheme, and customer data carries its own dedicated classification with controls applied accordingly. Where your organisation needs assurance beyond our standard terms, a confidentiality agreement or non-disclosure agreement can be negotiated.

Security by product

How your documents are handled depends on which Draftable product you use. The most important distinction is whether comparison happens on your own machine or in our cloud.

Draftable Legal and Business

Windows desktop software. Comparison runs locally and your documents are not uploaded to us.

Draftable API

Cloud-hosted comparison. You control the lifecycle of every document and comparison you submit.

Draftable Online

Our free browser-based comparison tool. Files are uploaded to us, so read this before using it for confidential material.
Draftable Clean also processes documents entirely on the user’s machine, and the Self-Hosted API (APISH) runs inside your own infrastructure, so documents never reach Draftable at all.

Completing a security review

1

Start with the Trust Center

Most standard questions on certifications, hosting, encryption, and testing are answered by the artefacts published at trust.affinda.com.
2

Request restricted documents

Attestation reports and internal policies are access-controlled. The Trust Center will prompt you to request access using your work email.
3

Send us anything still outstanding

For questionnaires, bespoke assurance requirements, or questions specific to your deployment, contact support@draftable.com.

Security and privacy FAQ

The questions we are asked most often during security reviews.

Accessing our compliance documentation

A walkthrough of the Trust Center and how to request access to restricted artefacts.