Skip to content
Back to Home
Claims last reviewed against the code · 30 Sep 2026

Security & Compliance

What DraftFlow does with your data, checked against the code and available operational evidence. Where a control does not exist yet, this page says so.

SHA-256
Signed QA records
AES-256-GCM
Sensitive fields
TOTP
MFA included
Singapore
App & database region

Defensible QA Records

DraftFlow records inspection and approval evidence for audit or dispute review. Witness-link snapshots are hash-bound; legal effect and evidentiary weight depend on the applicable facts, contract, method, and law.

Electronic Sign-off Evidence

Current external witness sign-offs retain signer identity, time, IP address, device information and signature method with the signed record. Some approvals made before 10 September 2026 lack a retained signature artifact and need re-attestation. These records may help authenticate an electronic record; legal effect depends on the applicable contract, consent, method and legislation.

Hold & Witness Point Release Evidence

Inspection & Test Plan HOLD and WITNESS points produce role-coded release records to support documented-information and production-control practices. DraftFlow is not ISO 9001 certified, and using it does not by itself establish customer or project compliance.

Tamper-Evident Snapshot Binding

For current OTP-backed witness links, DraftFlow hashes the inspection record — item text, acceptance criteria and attached evidence — when the link is issued. Later edits change that hash and can be detected. Older approvals without retained signature evidence need separate review.

OTP-Verified External Witness Links

External inspectors sign via a single-use, hash-stored token plus a one-time passcode delivered to the bound email, hard-locked after repeated failures. The signer never needs a DraftFlow account.

Append-Only Audit Trail

Sign-offs are retained on soft-delete — a user-initiated revoke never destroys the underlying signed record. Provenance (created vs. signed time, mint and redemption events) is preserved for the life of the project.

Evidence Export

Export retained project signatures with their audit details and content integrity hashes as a PDF for review in an audit or dispute. The export supports evidence review but does not determine legal admissibility or outcome.

Authentication & Access Control

Granular permissions ensure every user sees only what they need. Data boundaries are enforced at every layer.

Role-Based Access Control

Seven roles in your company — Drafting Manager, PM Director, Project Manager, Drafter, Estimator, Workshop Lead and Site Crew — each with permissions scoped to the work they do. DraftFlow support accounts are a separate account type outside your company.

Project-Level Permissions

Project Managers only see projects assigned to them. Drafters only access their assigned job numbers. Data boundaries are enforced at the API layer.

Company-Level Data Isolation

Authenticated queries for tenant-owned records are scoped to your company from the session token, never from the request body or URL. Public-token and system operations use separate controls. Tenant-isolation tests and a static tenant-safety check must pass in the pre-merge gate before a change is merged.

Account lockout and token revocation

Partial

Signing out revokes that token server-side immediately, across every server process. If you believe an account is compromised, an admin can set a new password or remove the member from Settings; either invalidates every token that account already holds, on its very next request. We do not currently show a list of signed-in devices, and there is no per-device revoke.

Single sign-on

Not available

Not built. There is no SSO or SAML integration today — everyone signs in with an email and a password, and can turn on TOTP two-factor for their own account. There is no way for an administrator to require MFA across the company yet. If SSO or enforced MFA is a hard requirement for your shop, email us and say which provider.

Multi-Factor Authentication

TOTP-based two-factor authentication with backup codes for account recovery. Compatible with all major authenticator apps.

Data Protection

Where your data lives, how it travels, and which parts we encrypt ourselves rather than inherit from our hosting providers.

AES-256-GCM on sensitive fields

Secrets DraftFlow holds on your behalf — webhook signing secrets and wall-display access tokens — are encrypted with AES-256-GCM by the application before they are stored. Whole-disk encryption of the database volume is handled by our hosting provider, not by us.

Browser and API transport

Traffic between your browser and DraftFlow uses HTTPS/TLS, with HTTP Strict Transport Security so browsers refuse to fall back to plain HTTP.

Singapore for the app, Australia for your files

The application, the PostgreSQL database and the cache run on Railway in the Southeast Asia (Singapore) region. Project files you upload — drawings, IFC models, mill certificates, dossiers, ITP evidence and record attachments — are stored in an Australian region (AWS ap-southeast-2, Sydney). Two exceptions are kept in the Singapore database instead: your company logo and drawn or typed signature images. Certifications such as SOC 2 and ISO 27001 belong to those providers and their underlying data centres, not to DraftFlow.

Database restore test

On 10 September 2026 we restored a logical database backup into a separate PostgreSQL service and verified all 121 tables against the source. That test did not cover uploaded files or a full application recovery.

Redis for sessions and limits

Rate-limiting counters and the revoked-token list are held in Redis so a revoked session stops working immediately across every server process.

Audit & Compliance

What gets recorded, what you can export, and which certifications we do and do not hold.

Audit logging

Role changes, admin password resets, user deactivation and deletion, share-link creation, use and revocation, ITP and QA sign-off events, imports and dossier generation are written to an audit log with the acting user and a timestamp, and — for most of them — the request IP address. Sign-in, failed sign-in and account-lockout events are recorded in our application logs rather than that audit log. It is a defined list of security and lifecycle events, not a log of every click.

Data handling and deletion

We collect only what the product needs to work. We handle export and deletion requests using the Australian Privacy Principles as our operating standard where practicable; the Privacy Act and every APP may not apply to every small-business activity. We do not claim a GDPR compliance posture, so if EU or UK law applies to you, ask us where your data sits before you rely on us. There is no self-serve “download everything” button yet.

SOC 2 Type II

Not started

DraftFlow holds no SOC 2 report. No auditor is engaged, no scope is agreed and no observation period has begun, so we publish no target date: a date with none of that behind it is a promise, not a plan. When those are arranged we will say so here, with the dates.

Exports that exist today

Progress and analysis reports as PDF or Excel, QA evidence bundles as tamper-evident PDF, timesheet exports for Xero and MYOB, and procurement exports for fabrication systems.

Infrastructure & Reliability

How the service stays up, and the limits and headers that protect it.

Health checks and restarts

Every service is health-checked and restarted automatically by the platform if it stops responding. We do not publish an uptime figure or offer a contractual SLA, because we have not measured one over a meaningful period.

Rate limiting

Redis-backed rate limits and account lockouts protect sign-in, registration, invitation acceptance, sensitive operations, and general API traffic.

Helmet Security Headers

Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and other security headers enforced on all responses.

What we do not have yet

The other half of a security page. We would rather you read these here than find them during an audit.

  • No point-in-time recovery

    We do not offer point-in-time recovery or a contractual recovery-time or data-loss target. A full recovery of the application and uploaded files has not yet been tested.

  • No certification of our own

    DraftFlow holds no SOC 2, ISO 27001 or equivalent certification, and none is currently in progress — no auditor, scope or observation period is arranged. Where our providers hold certifications, those are theirs.

  • No SSO, and no published SLA

    Sign-in is email and password, with optional TOTP two-factor that each user turns on for their own account. Uptime is monitored but not contractually guaranteed.

Have specific compliance requirements?

Security questionnaires are reviewed directly by the product and security owner. Responses distinguish implemented controls, partial controls, and capabilities that are not available.

Contact admin@draftflow.org