Trust
Security
Last updated August 29, 2026
1. Overview
This page describes how Voca Inc. approaches security for Draft. It is informational and does not modify our Terms of Service or Privacy Policy. We do not claim perfect security—no online service can.
2. Controls we use
Our current practices include:
- Encryption in transit (HTTPS/TLS) for the web application and APIs.
- Managed authentication and database services with access controls and row-level security where applicable.
- Least-privilege access for production systems; secrets stored in environment configuration rather than source control.
- Dependency and infrastructure providers that operate under their own security programs (for example cloud hosting, auth, and AI API vendors).
- Application-level abuse controls such as authentication requirements for product APIs and rate limits on public report submission.
3. Data handling
Customer Content and account data are stored in our primary application database and related object storage as needed to run the Service. AI providers receive the minimum prompt and media context required to return a response. Payment card data is handled by our payment processor, not stored on our application servers in full.
We retain operational logs for security, debugging, and billing integrity. Retention periods vary by log type.
4. Shared responsibility
You are responsible for protecting account credentials, choosing appropriate workspace members, and configuring connected social accounts carefully. Use strong unique passwords and keep devices updated.
5. Incidents and vulnerability reports
If we become aware of a security incident affecting your personal information, we will notify you and regulators as required by law.
If you believe you have found a vulnerability in Draft, please report it responsibly through the Report an issue control on the Draft site. Include steps to reproduce and avoid accessing other customers’ data. We ask that you give us a reasonable time to investigate before public disclosure.
6. What we do not claim (yet)
We do not currently advertise SOC 2, ISO 27001, or similar certifications on this page. When we complete independent audits or publish a subprocessors list with more detail, we will update this page rather than overstate our posture.
© 2026 Voca Inc. All rights reserved.