Draftable is part of Affinda Holdings Pty Ltd. Our Information Security Management System is independently certified and covers the Draftable brand, across our cloud services and software our customers run on their own infrastructure.
Independently certified
ISO/IEC 27001:2022
Certified Information Security Management System covering the Draftable product family.
SOC 2 Type II
Independent attestation covering the Trust Services Criteria for Security.
Penetration testing
Our web application and API are tested by an independent third-party security firm.
Certifications are maintained on a recurring audit cycle. Where a certificate is within its recertification period, a bridging letter confirming continuity of the certified management system is made available alongside it. If you are completing a security review and need that letter, request it through the Trust Center or contact support@draftable.com.
Visit the Draftable (Affinda) Trust Center
Certificates, security practices, and policy documents. Most items are access-controlled and will prompt you to request access using your work email.
How we protect your data
Encryption
We maintain a formal cryptography standard defining which algorithms, key sizes, and protocol versions are permitted across every Draftable product and system.
Weak and legacy primitives, including MD5, SHA-1, DES, 3DES, RC4, and ECB mode, are prohibited rather than merely discouraged.
Access control and monitoring
Access to systems holding customer data is restricted to authorised personnel on a least-privilege basis and protected by multi-factor authentication. All read and write access to customer data is logged, and repositories of customer data are documented and reviewed at least quarterly.Secure development
Draftable follows a formal Software Development Life Cycle covering code review, change management, and security testing. Findings from penetration tests and vulnerability scanning are tracked to remediation against defined timeframes based on severity.Resilience and availability
Our cloud services run on Amazon Web Services. Customer documents are held in Amazon S3, designed for 99.999999999% durability, with application data in Amazon RDS.- Backups. Production databases are backed up daily and encrypted with AES-256, with a minimum retention period of 30 days unless a documented exemption applies.
- Compensating measures. Where conventional backups are not viable, such as for object storage at scale, documented compensating controls are used instead, including bucket versioning.
- Continuity. We maintain documented and tested business continuity and disaster recovery plans, with defined response teams and an order of succession.
Reporting a vulnerability
We operate a responsible disclosure programme and welcome reports from the security community. We commit to a timely response, an open dialogue through investigation and remediation, and attribution once a finding is validated and fixed. We provide safe harbour: we will not pursue legal action against researchers who test in good faith, avoid harm to Draftable or our customers, hold off on public disclosure until a mutually agreed date, and comply with applicable law.How to report a vulnerability
What we consider a vulnerability, what to include in a report, and where to send it.
Privacy and data protection
Our handling of personal data is governed by our Privacy Policy. We maintain a data protection policy and a data classification scheme, and customer data carries its own dedicated classification with controls applied accordingly. Where your organisation needs assurance beyond our standard terms, a confidentiality agreement or non-disclosure agreement can be negotiated.Security by product
How your documents are handled depends on which Draftable product you use. The most important distinction is whether comparison happens on your own machine or in our cloud.Draftable Legal and Business
Windows desktop software. Comparison runs locally and your documents are not uploaded to us.
Draftable API
Cloud-hosted comparison. You control the lifecycle of every document and comparison you submit.
Draftable Online
Our free browser-based comparison tool. Files are uploaded to us, so read this before using it for confidential material.
Completing a security review
1
Start with the Trust Center
Most standard questions on certifications, hosting, encryption, and testing are answered by the artefacts published at trust.affinda.com.
2
Request restricted documents
Attestation reports and internal policies are access-controlled. The Trust Center will prompt you to request access using your work email.
3
Send us anything still outstanding
For questionnaires, bespoke assurance requirements, or questions specific to your deployment, contact support@draftable.com.
Security and privacy FAQ
The questions we are asked most often during security reviews.
Accessing our compliance documentation
A walkthrough of the Trust Center and how to request access to restricted artefacts.

