Security & Compliance
What DraftFlow does with your data, checked against the code and available operational evidence. Where a control does not exist yet, this page says so.
Defensible QA Records
DraftFlow records inspection and approval evidence for audit or dispute review. Witness-link snapshots are hash-bound; legal effect and evidentiary weight depend on the applicable facts, contract, method, and law.
Electronic Sign-off Evidence
Current external witness sign-offs retain signer identity, time, IP address, device information and signature method with the signed record. Some approvals made before 10 September 2026 lack a retained signature artifact and need re-attestation. These records may help authenticate an electronic record; legal effect depends on the applicable contract, consent, method and legislation.
Hold & Witness Point Release Evidence
Inspection & Test Plan HOLD and WITNESS points produce role-coded release records to support documented-information and production-control practices. DraftFlow is not ISO 9001 certified, and using it does not by itself establish customer or project compliance.
Tamper-Evident Snapshot Binding
For current OTP-backed witness links, DraftFlow hashes the inspection record — item text, acceptance criteria and attached evidence — when the link is issued. Later edits change that hash and can be detected. Older approvals without retained signature evidence need separate review.
OTP-Verified External Witness Links
External inspectors sign via a single-use, hash-stored token plus a one-time passcode delivered to the bound email, hard-locked after repeated failures. The signer never needs a DraftFlow account.
Append-Only Audit Trail
Sign-offs are retained on soft-delete — a user-initiated revoke never destroys the underlying signed record. Provenance (created vs. signed time, mint and redemption events) is preserved for the life of the project.
Evidence Export
Export retained project signatures with their audit details and content integrity hashes as a PDF for review in an audit or dispute. The export supports evidence review but does not determine legal admissibility or outcome.
Authentication & Access Control
Granular permissions ensure every user sees only what they need. Data boundaries are enforced at every layer.
Role-Based Access Control
Seven roles in your company — Drafting Manager, PM Director, Project Manager, Drafter, Estimator, Workshop Lead and Site Crew — each with permissions scoped to the work they do. DraftFlow support accounts are a separate account type outside your company.
Project-Level Permissions
Project Managers only see projects assigned to them. Drafters only access their assigned job numbers. Data boundaries are enforced at the API layer.
Company-Level Data Isolation
Authenticated queries for tenant-owned records are scoped to your company from the session token, never from the request body or URL. Public-token and system operations use separate controls. Tenant-isolation tests and a static tenant-safety check must pass in the pre-merge gate before a change is merged.
Account lockout and token revocation
PartialSigning out revokes that token server-side immediately, across every server process. If you believe an account is compromised, an admin can set a new password or remove the member from Settings; either invalidates every token that account already holds, on its very next request. We do not currently show a list of signed-in devices, and there is no per-device revoke.
Single sign-on
Not availableNot built. There is no SSO or SAML integration today — everyone signs in with an email and a password, and can turn on TOTP two-factor for their own account. There is no way for an administrator to require MFA across the company yet. If SSO or enforced MFA is a hard requirement for your shop, email us and say which provider.
Multi-Factor Authentication
TOTP-based two-factor authentication with backup codes for account recovery. Compatible with all major authenticator apps.
Data Protection
Where your data lives, how it travels, and which parts we encrypt ourselves rather than inherit from our hosting providers.
AES-256-GCM on sensitive fields
Secrets DraftFlow holds on your behalf — webhook signing secrets and wall-display access tokens — are encrypted with AES-256-GCM by the application before they are stored. Whole-disk encryption of the database volume is handled by our hosting provider, not by us.
Browser and API transport
Traffic between your browser and DraftFlow uses HTTPS/TLS, with HTTP Strict Transport Security so browsers refuse to fall back to plain HTTP.
Singapore for the app, Australia for your files
The application, the PostgreSQL database and the cache run on Railway in the Southeast Asia (Singapore) region. Project files you upload — drawings, IFC models, mill certificates, dossiers, ITP evidence and record attachments — are stored in an Australian region (AWS ap-southeast-2, Sydney). Two exceptions are kept in the Singapore database instead: your company logo and drawn or typed signature images. Certifications such as SOC 2 and ISO 27001 belong to those providers and their underlying data centres, not to DraftFlow.
Database restore test
On 10 September 2026 we restored a logical database backup into a separate PostgreSQL service and verified all 121 tables against the source. That test did not cover uploaded files or a full application recovery.
Redis for sessions and limits
Rate-limiting counters and the revoked-token list are held in Redis so a revoked session stops working immediately across every server process.
Audit & Compliance
What gets recorded, what you can export, and which certifications we do and do not hold.
Audit logging
Role changes, admin password resets, user deactivation and deletion, share-link creation, use and revocation, ITP and QA sign-off events, imports and dossier generation are written to an audit log with the acting user and a timestamp, and — for most of them — the request IP address. Sign-in, failed sign-in and account-lockout events are recorded in our application logs rather than that audit log. It is a defined list of security and lifecycle events, not a log of every click.
Data handling and deletion
We collect only what the product needs to work. We handle export and deletion requests using the Australian Privacy Principles as our operating standard where practicable; the Privacy Act and every APP may not apply to every small-business activity. We do not claim a GDPR compliance posture, so if EU or UK law applies to you, ask us where your data sits before you rely on us. There is no self-serve “download everything” button yet.
SOC 2 Type II
Not startedDraftFlow holds no SOC 2 report. No auditor is engaged, no scope is agreed and no observation period has begun, so we publish no target date: a date with none of that behind it is a promise, not a plan. When those are arranged we will say so here, with the dates.
Exports that exist today
Progress and analysis reports as PDF or Excel, QA evidence bundles as tamper-evident PDF, timesheet exports for Xero and MYOB, and procurement exports for fabrication systems.
Infrastructure & Reliability
How the service stays up, and the limits and headers that protect it.
Health checks and restarts
Every service is health-checked and restarted automatically by the platform if it stops responding. We do not publish an uptime figure or offer a contractual SLA, because we have not measured one over a meaningful period.
Rate limiting
Redis-backed rate limits and account lockouts protect sign-in, registration, invitation acceptance, sensitive operations, and general API traffic.
Helmet Security Headers
Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and other security headers enforced on all responses.
What we do not have yet
The other half of a security page. We would rather you read these here than find them during an audit.
No point-in-time recovery
We do not offer point-in-time recovery or a contractual recovery-time or data-loss target. A full recovery of the application and uploaded files has not yet been tested.
No certification of our own
DraftFlow holds no SOC 2, ISO 27001 or equivalent certification, and none is currently in progress — no auditor, scope or observation period is arranged. Where our providers hold certifications, those are theirs.
No SSO, and no published SLA
Sign-in is email and password, with optional TOTP two-factor that each user turns on for their own account. Uptime is monitored but not contractually guaranteed.
Have specific compliance requirements?
Security questionnaires are reviewed directly by the product and security owner. Responses distinguish implemented controls, partial controls, and capabilities that are not available.
Contact admin@draftflow.org