SOC2C

Is this your company? Buyers are checking DraftWise Inc here. Claim draftwise.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
DraftWise Inc logo

DraftWise Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

DraftWise Inc is SOC 2 Type II compliant. DraftWise Inc also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

A secure end-to-end drafting and negotiation AI platform designed for transactional lawyers. Leverage client preferences embedded in your data to deliver flawless drafts every single time — within seconds.

Compliance & infrastructure

Documents

31
Documents

Compliance leadership

The person who leads DraftWise Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. DraftWise Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is DraftWise Inc SOC 2 compliant?
DraftWise Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is DraftWise Inc ISO 27001 certified?
According to DraftWise Inc's public trust center, DraftWise Inc is ISO 27001 certified. On SOC2C this listing is Listed.
Is DraftWise Inc GDPR compliant?
According to DraftWise Inc's public trust center, DraftWise Inc is GDPR compliant. On SOC2C this listing is Listed.
Is DraftWise Inc SOC 2 Type I or Type II?
DraftWise Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use DraftWise Inc's SOC 2 for a vendor risk assessment?
Yes. DraftWise Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by DraftWise Inc

Reproduced from DraftWise Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Draftwise approach security?
Draftwise strictly adheres to industry standards for highly sensitive data. Our engineering and security teams have deep experience building secure deployments for global companies and government agencies and hold multiple patents in data, AI, and application security. Draftwise has been certified for Cyber Security Essentials Plus and is SOC2 Type II compliant.
Does Draftwise provide enterprise-grade security?
Draftwise has been certified for Cyber Security Essentials Plus (UK Cybersecurity standard) and is SOC2 compliant. We strictly adhere to industry standards for highly sensitive data and can further configure the security architecture to your specific requirements. Our engineering and security teams have deep experience building secure deployments for global companies and government agencies and hold multiple patents in data and application security.
What about encryption and audit logs?
Firm data is encrypted at rest & in transit. We use the following protocols: At Rest: AES-256 encryption algorithm. In Transit: Data transmission via HTTPS using TLSv1.2 or TLSv1.3. We use AWS CloudWatch for audit logs and monitoring services. Logs are collected and stored from resources, applications, and services we deploy in near-real-time. We have rules-based and composite high-resolution alerting in place. We apply anomaly detection to our container/applications. Logs are retained for up to two years. Any additional questions about encryption or audit trails/logs can be directed to sales@draftwise.com.
What does "flexible & secure deployment" entail?
Draftwise is designed with technologies trusted by S&P 500 companies and intelligence agencies. We provide a variety of deployment configurations to support your firm’s technology and compliance requirements, including both cloud and on-premise deployment options. We offer containerized, access-controlled, auto-scaling SaaS offering, implemented with state-of-the-art security practices adopted by most secure S&P 500 companies and world governments. We have a control framework, audit alerting, and routine security evaluation.
Deploying on the cloud with DraftWise
Firms have two options when deploying on the cloud with Draftwise. We can deploy a private tenant or private cloud specific to your firm in a region of your choosing. By default, no data leaves the VPC or is visible to any other Draftwise customers and network access can be globally restricted to only firm IP subnets. We can also deploy to your firm’s existing cloud infrastructure, either in a standard containerized approach (helm chart and private image registry), VM images, or Linux binaries. We can either administer and upgrade the software or provide instructions for firm IT to self-service. Our software can be deployed with a small resource footprint and scaled as usage grows. AI features are not available with this deployment method.