Security
Last updated: July 1, 2026
OrgDrafter is designed to handle sensitive organizational and workforce data responsibly. This page describes our approach to protecting that data. We believe that transparency about our actual practices is more valuable than broad claims.
Data protection
Customer data is logically separated by organization. Each customer's data is accessible only within their own workspace. The application is designed to keep sensitive organizational information confidential and isolated from other customers' data.
Authentication and access
Access to the application is restricted to authenticated users with authorized accounts. Access controls are based on assigned permissions, limiting what each user can see and do within the service.
Data in transit
Data transmitted between your browser and the application is protected using encrypted connections.
Infrastructure
The application is hosted on cloud infrastructure operated by reputable third-party providers. We rely on those providers' physical and operational security controls as part of our overall approach.
Monitoring
We use operational monitoring and logging to help maintain the reliability and security of the service. These tools help us detect and respond to issues as they arise.
Customer data
Customers retain ownership of the data they upload to OrgDrafter. We access customer data only to the extent necessary to provide and support the service. We do not use customer data for purposes beyond operating the application on the customer's behalf.
Our approach
We continue to evolve our security practices as the product and customer base grow. We would rather describe what we do accurately than claim practices we cannot yet substantiate.
Reporting a vulnerability
If you believe you have identified a security issue, please contact us at admin@orgdrafter.com. We review reported security issues and prioritize investigation based on their potential impact.