Security, Privacy, and Compliance

We take your data privacy and security seriously, and make it a priority to protect your data and be transparent about how and when it is used.


General Data Protection Regulation

The European Union General Data Protection Regulation (GDPR) is in effect as of May 25th, 2018. We work hard to make sure that you can stay compliant while using our services, and take privacy and data security seriously. You can see our GDPR badge in places that are recently updated or especially relevant for your employees and operations in the EU.


Have more questions about security?

Read our comprehensive FAQs here or get in touch through chat or by emailing privacy@drafted.us


Top Security and Privacy Features

Any questions? Drop us a line at support@drafted.us


Authentication & Passwords

Drafted supports SSO using OAuth2 for Google Sign In. For other users, Drafted uses Argon2id password hashing and best practices in implementation. Don't worry, we didn't forget the salt.


GDPR Ready

We follow GDPR principles, including explicit consent, purpose limitation, security, the right to be forgotten, and more. You can read our new Privacy Policy to learn more about how we use and safeguard your privacy and data.


Access Control & Encryption

Our employees know how to handle your data - we enforce multi-factor authentication for all internal systems and third party services where it is supported, and an internal data access policy is required learning for new employees. No data on Drafted is ever transmitted on an un-secure connection, even between internal microservices.


Cloud Data Protection Standards

Drafted services run on Amazon Web Services (AWS) and DigitalOcean which are physically secure, employ modern software security techniques, and require multi-factor authentication for access. The AWS and DigitalOcean clouds meet several global security standards such as ISO 27001 and SOC.


Disaster Recovery

Data backups are handled by Heroku's Data Safety and Continuous Protection backups. Continuous nightly backups that are physically and logically separated allow for secure and reliable rollbacks and retrieval in an emergency.


Continuous Vulnerability Management

We use a third party service to ensure that all of our dependencies are up-to-date and patched if a patch is available. When new known vulnerabilities are found, we are immediately notified with a recommended action to take. Critical vulnerabilities are typically patched same day and non-critical within 2 weeks.