Skip to main content
These are the questions we are asked most often by security, procurement, and legal teams assessing Draftable. For the underlying artefacts, see our Trust Center.

Certifications and assurance

Yes. Draftable is part of Affinda Holdings Pty Ltd, which holds ISO/IEC 27001:2022 certification. The certified scope explicitly names the Draftable brand and covers both solutions deployed in Affinda-operated cloud environments and software run by customers on their own self-managed infrastructure.The current certificate is available in the Trust Center. Where the certificate is within its recertification period, a bridging letter confirming continuity of the certified management system is provided alongside it. Ask us if you need that letter for your review file.
Yes. We hold a SOC 2 Type II attestation covering the Security trust services criteria, prepared by an independent service auditor. The report is confidential and access-controlled. Request it through the Trust Center, where you will be prompted to submit your work email.
Yes. Our web application and API are tested by an independent third-party security firm. Findings are formally tracked, remediated against severity-based timeframes, and retested to confirm closure.An executive summary of the most recent test is available on request through the Trust Center. Full technical reports are provided under NDA where there is a legitimate need.
Yes, after written consent and mutual agreement on the testing scope. Contact support@draftable.com to start that conversation.If you run Draftable Legal, Business, Clean, or the Self-Hosted API, the deployment sits inside your own environment and is yours to test.
Cover is in place. We do not publish the details, but documentation can be provided on request through the Trust Center.

Where our documents go

It depends entirely on the product.
  • Draftable Legal, Business, and Clean are Windows desktop applications. Comparison and metadata cleaning run on the user’s own machine and your documents are not uploaded to us.
  • Draftable API Self-Hosted (APISH) runs inside your own infrastructure. Documents never reach Draftable.
  • Draftable API is cloud-hosted, so documents you submit are processed and stored on our infrastructure, with lifecycle controls you operate.
  • Draftable Online is our free browser tool, so files are uploaded to us.
See Document security with Draftable Legal and Business for the desktop detail, including the short list of outbound connections the application does make.
Our cloud services run on Amazon Web Services infrastructure operated by Draftable, using Amazon S3 for document storage and Amazon RDS for application data.
Accounts created through draftable.com are hosted in our US data centre. We also operate an EU data centre and can provision your account there on request. Other regions are possible where there is enough customer commitment to support the deployment. Contact support@draftable.com to discuss your requirements.
Access to customer data is restricted to authorised personnel on a least-privilege basis, protected by multi-factor authentication, and logged.Where a support issue genuinely requires us to see a file, sharing is always initiated by you. Draftable Legal also includes a Create safe file for sharing feature that scrambles document content before it is sent, and administrators can disable file sharing with support entirely through Group Policy.

Data handling

For the authenticated Draftable API, data is retained until you delete it. You control the lifecycle: set an expires value on a comparison for automatic cleanup, or delete comparisons on demand through the API or SDKs.For Draftable Online, which requires no account, a comparison is retained until deletion is requested. See Document security with Draftable Online.For the desktop products, retention is not applicable. We never hold the documents in the first place.Retention is governed by service-wide controls rather than per-customer arrangements.
The data is made immediately inaccessible to all requests. A copy may persist in encrypted backups, which age out automatically. The maximum period for which data may remain in backups following a deletion request is 30 days.
Yes, in transit and at rest.
  • In transit: TLS 1.2 or TLS 1.3 only. TLS 1.1 and below, and all versions of SSL, are prohibited by policy.
  • At rest: AES with 256-bit keys, including database backups. Keys are held in an approved key management service with restricted access and rotation at least every 12 months.
No. Draftable’s comparison algorithm is fully deterministic and rules-based. It uses expert-system-style rules rather than machine learning, probabilistic inference, neural networks, or large language models.We do not use documents submitted by our commercial customers to train any model, and we will not.For customers in regulated industries this is often the point that matters most: because the algorithm is deterministic, the same inputs always produce the same output, which makes results auditable and repeatable.
Yes. Our standard confidentiality terms are set out in the terms and conditions for the relevant product. Where you need more than that, a confidentiality agreement or non-disclosure agreement can be negotiated. Contact support@draftable.com.

Operations and incidents

We maintain a documented incident response plan, with a defined response team and executive escalation. It sits alongside our business continuity and disaster recovery plans. Affected customers are notified in line with that plan and our contractual and regulatory obligations.
Production databases are backed up daily and encrypted with AES-256, with a minimum retention period of 30 days unless a documented exemption applies. Where conventional backups are not viable, documented compensating controls such as object versioning are used instead. Document storage sits on Amazon S3, which is designed for 99.999999999% durability.
Through our responsible disclosure programme. We aim to respond quickly, keep an open dialogue through investigation and remediation, and credit researchers once a finding is validated and fixed. We offer safe harbour for good-faith research.See Vulnerability Reporting for what to include and where to send it.
Yes. Start with the Trust Center, which answers most standard questions and holds our certificates, attestation reports, and policy documents. For anything still outstanding, send the questionnaire to support@draftable.com and we will work through it with you.

Still need something?

Security and compliance at Draftable

Our full security programme: certifications, encryption standards, resilience, and secure development.