Draftable is used by law firms, corporate legal teams, and regulated businesses to compare and clean documents that are confidential, privileged, or commercially sensitive. Our security programme is built around the high standards our customers expect of us.
Draftable is part of Affinda Holdings Pty Ltd. Our Information Security Management System is independently certified and covers the Draftable brand, across our cloud services and software our customers run on their own infrastructure.
Certificates and reports are published in our Trust Center.
Encrypted in transit and at rest. TLS 1.2 or 1.3 for everything in transit, AES-256 at rest. Legacy protocols and weak ciphers are prohibited by policy, not just discouraged.
Access is controlled and logged. Least-privilege access, multi-factor authentication, and logging of all access to customer data.
Built securely. A formal Software Development Life Cycle covering code review, change management, and security testing.
Resilient. Hosted on AWS with encrypted daily backups, documented and tested business continuity and disaster recovery plans, and object storage designed for 99.999999999% durability.
The most important thing to understand about Draftable security is that most of our products never receive your documents.
We welcome reports from the security community and operate a responsible disclosure programme with safe harbour for good-faith research. How to report a vulnerability
Our Trust Center holds our current certificates, attestation reports, and policy documents.