Security

Last updated: July 1, 2026

OrgDrafter is designed to handle sensitive organizational and workforce data responsibly. This page describes our approach to protecting that data. We believe that transparency about our actual practices is more valuable than broad claims.

Data protection

Customer data is logically separated by organization. Each customer's data is accessible only within their own workspace. The application is designed to keep sensitive organizational information confidential and isolated from other customers' data.

Authentication and access

Access to the application is restricted to authenticated users with authorized accounts. Access controls are based on assigned permissions, limiting what each user can see and do within the service.

Data in transit

Data transmitted between your browser and the application is protected using encrypted connections.

Infrastructure

The application is hosted on cloud infrastructure operated by reputable third-party providers. We rely on those providers' physical and operational security controls as part of our overall approach.

Monitoring

We use operational monitoring and logging to help maintain the reliability and security of the service. These tools help us detect and respond to issues as they arise.

Customer data

Customers retain ownership of the data they upload to OrgDrafter. We access customer data only to the extent necessary to provide and support the service. We do not use customer data for purposes beyond operating the application on the customer's behalf.

Our approach

We continue to evolve our security practices as the product and customer base grow. We would rather describe what we do accurately than claim practices we cannot yet substantiate.

Reporting a vulnerability

If you believe you have identified a security issue, please contact us at admin@orgdrafter.com. We review reported security issues and prioritize investigation based on their potential impact.