Using real client material
Can we upload real, unpublished client material?
Yes. Draftwell AI is built for exactly that: management interview
responses, due diligence questionnaires, roadshow materials, bank OSS
outlines, financial information, industry consultant reports and other
deal documents. What you upload is used only for retrieval, analysis,
drafting, citation checking and information-request generation within the
matter you assign it to. It does not enter any shared library, and it is
never used for another client's matter.
Client material is held with matter-level isolation, encrypted storage,
controlled access and deletion on your instruction. Real matter material
is sent only to approved domestic enterprise model APIs. Those APIs
expressly commit not to use user data for training and to keep user
material confidential.
Firms differ in their AI, vendor and outsourcing approval policies. If
yours requires a vendor review, we can provide the data flow, model list,
subprocessor list, retention and deletion policy and access controls for
your firm to assess as a package.
Model training, providers and processing location
Will Draftwell AI or its model providers train on our material?
No. We do not use your uploaded files, extracted content, generated
drafts, lawyer edits, feedback or matter outcomes to train our own models,
and we do not add any of it to cross-client datasets, evaluation sets or
product-improvement corpora.
Real confidential matters use approved enterprise APIs only. Under the
applicable API terms, customer inputs, model outputs and feedback may not
be used for pre-training, fine-tuning, reinforcement learning, human
annotation, model evaluation, training dataset construction, or the
optimisation of models, algorithms or services. A provider may retain data
to the extent necessary and reasonable for legal obligations, content and
system safety, troubleshooting and ordinary service operation — that
retention is not a training licence.
Which models do you use? Could you switch models without telling us?
We operate a model whitelist for real confidential matters. In the
standard production environment, approved routes are limited to two
domestic enterprise APIs: the DeepSeek open platform and Alibaba Cloud
Bailian's first-party Qwen. A separately scoped deployment has its own
approved routes, agreed with your firm before it is enabled.
We will not silently move a confidential matter onto an unapproved
model, an offshore model, a consumer product or a model aggregator. This
is enforced in code: every model call is checked against the provider
allowlist first, and an unapproved provider — offshore, free-tier, or
without a written commitment — raises an error and stops, rather than
falling back or rerouting. If the primary model is briefly unavailable, the
job fails safely or waits to retry; it never lowers the data protection
standard to get through.
Does our material leave China in the standard production environment?
No. Our standard production environment, file storage, database, caches,
backups and model APIs are all deployed in, or confined to, approved
Chinese processing regions. Real confidential matters are not sent
to offshore model APIs, and are not moved offshore by load balancing,
error monitoring or analytics tooling. There is an additional structural
safeguard here: we have no third-party error monitoring or product
analytics integration at all, so there is no path by which data leaves the
country through instrumentation.
If we ever introduce a feature, provider or piece of infrastructure that
could involve offshore processing, we will review it before enabling it and
disclose it as required by contract and law — not treat it as an
unannounced back-end change.
Can you support overseas hosting or international model providers?
Yes, as a separately scoped deployment. Model and hosting choice
belongs to your firm: we can run drafting and research on international
frontier models, enabled only after that deployment's hosting location,
model providers, data flow and contractual terms have been approved.
What that never does is change the standard environment underneath
you. Our standard production environment remains in mainland China, and
we will not reroute an existing matter in the background.
Do you send our entire document set to the model?
No. We apply a minimum-necessary principle. Documents are stored,
parsed, classified and indexed inside our own controlled environment, and
only the pages, passages, tables or structured facts a given task requires
are sent to an approved model API.
Drafting one risk factor, for instance, does not put your whole document
set into a single model request. This reduces unnecessary exposure and
improves both accuracy and source traceability.
Does the public research feature send the issuer's name to a search engine?
At matter confirmation, we use public search engines to identify the
company's principal business and find comparable companies with similar
businesses.
After that, section drafting uses only the due diligence questionnaires,
management interviews, financial information and other matter material you
provide, and performs no external search.
Matter isolation
Could material from different clients, firms or matters mix?
No. Accounts and matters are the isolation boundary. Each matter's
source files, extracted text, structured facts, generation history,
citation records and caches are held separately, and every route that
reaches matter content checks membership before reading anything — a
non-member's request is refused before any content is touched.
Material in one matter never surfaces as a retrieval result in another,
and is not reachable by another client through a similar company name,
industry or terminology.
This is covered by an automated regression suite across every
content-bearing route, including a guard test that fails if a new route is
added without isolation coverage, so the protection cannot quietly decay.
Does our material go into your precedent database, or get used on other matters?
No. Our public precedent database and client confidential material are
two entirely separate data domains. The public database holds only lawfully
obtained public prospectuses, listing applications and other public-source
documents. What you upload does not enter it, and is not turned into
anonymised “learned experience” searchable by other clients.
This is absolute at the architectural level: our vector index covers the
public prospectus corpus only, and client uploads are never
converted into vectors or written to any shared index. So the
situation where the source file is deleted but its vectors linger does not
arise.
Even with issuer or matter names removed, we do not repurpose client
material for product training, template extraction or cross-client
knowledge reuse. That would require your separate, express, written and
revocable authorisation for defined content.
Can other lawyers at our firm see my matter?
Not unless the matter owner or an authorised administrator grants them
access. Buying the same Matter Pass, or belonging to the same firm, does
not by itself grant access to a matter; access follows membership of that
specific matter.
For shared matters we record members, roles, join times and
principal actions. Colleagues without access, other clients and ordinary
platform users cannot see the matter name, files, drafts or activity.
Our people's access
Can Draftwell AI staff or founders read the files we upload?
In the product: no. Our admin console has no interface
for viewing client file contents or draft text — admin views carry
account, job status, failure reason and order metadata only. An admin
account also cannot read matter content it is not a member of through the
ordinary routes.
Named personnel obtain time-limited, scope-limited, audited temporary
access only where you request technical support, where a security incident
requires investigation, or where the law clearly requires it. Access is
revoked afterwards and the activity stays in the security audit record.
Will support copy our material into a test environment while debugging?
No. Development, test and production are separate, and test environments
use public or synthetic material — our code repository contains no
real client material, and the DD questionnaires and management responses
used in testing are synthetic or publicly sourced. Engineers may not copy
the real client database, files or full prompts into a development
environment to reproduce a problem.
Where an issue genuinely cannot be investigated without client content,
we obtain the matter owner's authorisation first and work through
controlled, read-only, time-limited access in production wherever possible.
Any temporary copy is protected to the same standard and deleted promptly.
Do you use client material to improve prompts, the product or evaluation?
Not by default. We improve system performance from technical signals
that contain no client content — whether a job succeeded, processing
time, feature usage frequency, error class. We do not automatically add
client files, output drafts, lawyer edits or specific feedback to prompt
optimisation, evaluation sets or training material.
There is a structural advantage here: we have no third-party
product analytics or event tracking of any kind, so there is no
situation in which your usage is collected by an outside platform. The
operational information available to us is limited to job records in our
own database.
If we wanted to use a redacted sample from a specific matter for product
improvement, we would describe the scope and obtain express written
authorisation. Declining has no effect on your use of the service.
Encryption, logging and system security
Is our material encrypted?
Yes. Traffic between your browser and Draftwell AI is encrypted with
HTTPS/TLS. Source files, the database and backups use the cloud platform's
encryption-at-rest capability — which is the platform's control, not
something we implement ourselves, and we describe it that way deliberately.
File and draft downloads are served through session-authenticated
routes that re-check matter membership on every request. We do not use
long-lived public download URLs, so there is no situation in which a leaked
link is enough to retrieve a document.
Model API credentials, database passwords and other secrets live only in
controlled server-side environment variables or secret management —
never in front-end code, the browser, documentation or ordinary logs. A
dedicated continuous-integration workflow is configured to run blocking
secret scanning over the full repository history to keep credentials out.
Do your logs retain prompts, model output or file contents?
Our application logs and job records are not designed to hold client
file contents, complete prompts or complete model outputs. They record
technical metadata: job ID, matter ID, model provider, model name,
processing time, status and error class.
One fact worth stating: we use no third-party logging, error
monitoring or performance analysis platform. No Sentry, no APM, no
event tracking. Operational records stay in our own database and servers
and do not flow to any third party.
Provider errors are redacted before they are stored or displayed. A
provider SDK exception embeds the HTTP response body, and for a chat
completion that body echoes the prompt — which is your material. We
reduce these to the exception class, HTTP status code and request ID, with
a source-level test preventing the raw form being reintroduced.
In the rare case where content is genuinely needed to diagnose a fault,
we use an authorised temporary diagnostic procedure rather than switching
on full-text logging. Temporary content is access-limited, given a deletion
deadline, and kept separate from ordinary operational logs.
Does the issuer's identity appear in filenames, exports or payment records?
No, not in those surrounding identifiers. Draftwell AI uses the matter
name as its code name. Matter headings, job progress and export filenames
show that name rather than the issuer's company name. Payment channels see
the Draftwell AI brand, a random order number, amount and payment status;
they receive no issuer name, matter name or client-file content.
The issuer's company name is still used inside matter fields and draft
text where drafting requires it, and an exported prospectus draft may of
course contain that name as instructed by the lawyer. The commitment here
is that filenames, surrounding matter identifiers and payment records do
not create an additional identity disclosure; it is not a promise to remove
the issuer from the draft itself.
Service emails likewise do not place a matter name or issuer identity in
their subject or body, and the email call sites are covered by regression
tests.
Retention, deletion and termination
How long do you keep our matter material?
While a matter is in use, we keep its material as you instruct, so that
drafting, version recovery, citation checking and later revision remain
possible. A matter has no retention period of its own; it follows the
account that owns it. After 24 months without account
activity, that account's matter content is deleted. We send deletion
notices at 18 months and 22 months of
inactivity, and do not delete without a record that notice was sent. There
is no read-only or degraded stage in between: until deletion, a matter can
be read, exported and drafted in as normal.
If other members remain, ownership transfers to the longest-standing
remaining member instead of the matter being deleted because its former
owner is inactive. Where the account holds an unused credit balance, only
matter content is deleted: the account and the balance remain, and signing
in still reaches them. Where no balance remains, account identity and
credentials are anonymised after matter content is deleted, while
de-identified legal-acceptance evidence is retained. Order, payment and
invoice records are kept for their statutory periods and no longer point to
an identifiable person.
You may also delete an individual file or the whole matter before those
periods expire. We do not extend retention for model training or
cross-client product optimisation. Commercial entitlements and file
retention are separate: a Matter Pass runs for 24 months, and its expiry
only ends uncharged generation — it deletes nothing.
Underlying model providers may retain request data for as long as
necessary and reasonable to complete the request and for content and system
safety, troubleshooting, legal compliance and service operation. We cannot
presently require absolute zero retention from an underlying model, and we
approve only enterprise APIs whose retention purposes are limited and which
do not use retained content for training or model and service optimisation.
Can we delete a single file, a draft, or a whole matter?
Yes. You can delete an individual uploaded file or an entire matter.
Deleting a matter removes its storage tree from the live system (source
files, extracted content, checkpoints, generated drafts and exports) and
the associated database records (documents, jobs, draft versions, citation
records, information-request items). Existing download URLs stop working
immediately.
Data in backups is cleared on the backup rotation cycle, currently
7 days. Within
that window backups are used for disaster recovery only, and are never
restored into live business systems or otherwise processed.
Deletion completeness is covered by an automated test that builds a
matter with uploads, jobs, drafts, citations and information requests,
deletes it, and asserts that the storage tree is gone and no orphan rows
remain. The table list is enumerated from the schema itself, so a new
matter-scoped table is covered without anyone remembering to update the
test. A job still running when its matter is deleted aborts at its next
checkpoint rather than recreating the directory, and the credits it was
holding are released so you are not charged for a matter you deleted.
Can you confirm deletion afterwards?
Yes, on request. We can provide confirmation by email or formal letter
stating that the relevant live-system data has been deleted and that backup data will be
cleared within the established rotation cycle. The confirmation carries no
file contents — only the matter name, deletion scope, execution time
and backup clearance arrangement.
A tamper-evident, exportable deletion receipt is not built into the
system. We would assess that feature if a firm contract specifically
requires it.
Where law, financial audit, a security incident or a dispute requires a
small number of records to be kept, we limit them to necessary non-content
records and explain the basis and period.
If we stop using Draftwell AI, can we export before deleting?
Yes. You can download your uploaded source files, generated drafts (in
Word), version records and information-request exports at any time. These
downloads work whatever state the account is in and are not withheld
because payment has ended — downloading and deleting check matter
membership only, with no entitlement or credit check anywhere in the path,
and that behaviour is locked in by a regression test.
Export is currently item by item, per file and per draft. One-click
matter-level packaging is not a current feature; we can assess it if a
firm's handover or exit process specifically requires it.
Once you have exported, you can delete. Terminating the service does not
authorise us to keep using matter material for product research, model
training or other clients' work.
Subprocessors and provider changes
Besides the cloud platform and model providers, who else touches the data?
We can give you the complete list, because it is short. This is the
subprocessor list — there is no separate document.
We have no third-party product analytics, error
monitoring, support desk, CRM or advertising integration. There is no path
by which your files, prompts or model outputs reach a platform unrelated to
the service; payment channels do not receive that content.
What happens if a model provider or its terms change?
We keep model APIs and critical infrastructure under continuing vendor
management. When a provider changes its training, data use, retention,
region or subcontracting arrangements, we re-assess whether it still meets
our approval standard.
Where a change would materially reduce the protection of client data, we
do not simply carry the old approval forward. We suspend that route, switch
to another already-approved route, or notify clients where that is
warranted. A firm's contract can specify notification for material
subprocessor or processing changes.
Can we require that only a specific model is used?
Today: we can already fix the drafting model per matter,
but that control currently sits with our administrators rather than being
self-service. If your firm requires it, we will fix the route when the
matter is opened, and it will not switch to another model in the background.
A self-service matter-level model restriction interface is not built in.
We can assess it if your firm specifically requires self-service visibility
or control.
Restricting the model may affect speed, availability, feature behaviour
or cost, and we will say so before enabling it. Where no model meeting the
restriction is available, the job waits or fails — it does not work
around your restriction.
Can we ask for shorter retention, a dedicated instance or other configuration?
You can ask. Our standard service runs on a single security baseline.
For firm-level or multi-matter arrangements we can discuss shorter
Draftwell-side retention, specific model routes, dedicated cloud resources,
separate keys, custom access control or additional audit reporting.
Some requests are constrained by the fixed security and compliance
retention rules of the underlying model APIs. We can shorten our own
retention, but we cannot promise that a model provider performs no security
or statutory retention at all. We will be explicit about which parts are
technically configurable and which have to be solved in the provider
contract.
Incidents, continuity and independent validation
What happens if there is a breach or other security incident?
We contain the impact, preserve evidence, investigate scope and
remediate. Where an incident is confirmed to have affected client material,
we notify the affected clients as soon as reasonably practicable and keep
providing known impact, progress and recommended steps.
Notification does not wait until every technical detail is resolved
— but neither do we report every ordinary system fault as a data
breach. Our security contact is
security@draftwell.cn, monitored
by a founder. Our underlying providers' obligations to notify us of
incidents affecting client data rest on their published service terms.
Where we are today. Draftwell AI is run by two
founders, so an incident is handled and communicated by a founder
directly. At our current size we do not separately maintain a written
incident-response playbook, a provider escalation contact directory or a
tabletop-exercise programme. The commitments above describe the direct
response model we actually use; they do not imply that separate documents
or programmes exist. A firm engaging us can fix a specific
first-notification deadline in the Data Processing Addendum or order form.
We will reassess the need for separate procedures if the team, a client
contract or regulation requires them.
If the cloud platform or a model API goes down, could we lose material or drafts?
Saved files and drafts are not lost because a single model call or job
fails. Uploads are persisted before a job starts; the model call is a
processing step, not the only place the data lives. Matter state and
completed draft versions are held in the database and storage layer.
When a job fails, completed checkpoints are kept so you can retry or
resume from a recoverable stage, and a failed job never overwrites a
finished version with partial work. We back up the database and key matter
data, and verify the restore procedure.
Do you hold SOC 2, ISO 27001 or another security certification?
No. Draftwell AI is an early-stage company and holds no SOC 2, ISO 27001
or comparable certification. We will not borrow our cloud or model
providers' certifications to imply that we are certified ourselves.
What we offer instead is material you can actually check: the data flow,
the model and subprocessor lists, data regions, the retention and deletion
policy, access controls, incident arrangements, and the real state of our
security testing. We will pursue independent penetration testing and
appropriate certification as client requirements and our stage warrant.
Have you had a penetration test or code security review?
Today: no third-party penetration test has been carried
out. Authentication, authorisation, file upload and download, matter
isolation, background jobs and administration are covered by automated
tests and code review. Continuous-integration rules are also configured for
secret and dependency vulnerability scanning.
We will commission a third-party penetration test when a firm's
procurement requirements or our business stage warrants it; after that we
can provide a shareable summary or remediation note.
Security testing does not replace day-to-day engineering control. We
continue to maintain dependency scanning, secret checks, authorisation
regression tests and security-update rules, and set explicit remediation
deadlines for high-risk findings.
Output quality and professional responsibility
Could the model invent facts, or write another company's material into our draft?
Any generative model can produce errors, so we do not treat model
confidence as evidence of reliability. We reduce the risk of unsupported
statements through matter isolation, source retrieval, per-claim citation,
restrictions on how comparable material may be used, placeholders for
missing information, and the lawyer's review.
Comparable company material is used for structure, style and disclosure
scope only — it is not a source of fact about your applicant. A fact
without adequate support in your matter material is marked as outstanding
or to be confirmed, rendered as [●] with the responsible
party noted, rather than filled in by the model. The final draft still
requires the responsible lawyer's review.
How do we know which document a sentence came from?
Source traceability is a core design property. A factual statement
supported by matter material carries a citation marker in the browser, and
the lawyer can open the supporting document, page or passage. Word exports
preserve source references as footnotes.
A citation reflects the evidentiary source of a statement, not a final
judgement on legal sufficiency. Where a citation cannot be verified, where
sources conflict, or where material is insufficient, the uncertainty is
shown to the lawyer rather than quietly removed. If a source document is
later deleted, its citations are marked as pointing to a removed file
instead of continuing to present as ordinary supporting evidence.
Can Draftwell AI output be filed or sent to a client directly?
No. What we produce is a first draft for lawyer review and revision,
together with an information-request list — not a final legal opinion
or filing document. It removes a great deal of blank-page drafting, but the
responsible lawyer still has to verify facts, legal judgement, disclosure
adequacy, terminology consistency and the current state of the deal.
Citations, placeholders, information requests, adviser confirmation items
and version records support that review. We never submit unreviewed model
output to a regulator, a client or another deal party — the system has
no outbound submission capability of any kind.
Rights, confidentiality and contract
Who owns the material we upload and the drafts produced?
You retain your uploaded material and the intellectual property in it.
We take only the limited rights needed to process it in order to provide
the service, and gain no training, publication, resale or cross-client
rights by virtue of your upload.
Subject to your compliance with the applicable contract and payment
terms, you may use the drafts generated for your matter in your legal
services and deal work. We retain rights in the underlying software,
general workflows, public database, template logic and system technology
— which does not give us rights in your matter facts or confidential
content.
What confidentiality obligations does Draftwell AI carry?
We carry contractual confidentiality obligations over client material and
may use or disclose it only to provide, secure and support the agreed
service. Personnel and subprocessors who touch the material are bound by
confidentiality and security obligations no lower than the service
requires.
Confidentiality survives termination. Where disclosure is legally
required, we notify you promptly to the extent the law permits and limit
the scope of disclosure so far as we can. We treat client names and deal
names as confidential too — including by not naming them on our
website, on social media or in fundraising materials.
Will you sign our data processing agreement or complete our security questionnaire?
Yes. For firm-level or multi-matter procurement we can sign a reasonable
data processing addendum and complete vendor security, privacy and AI
questionnaires. We can supply the data flow, model and subprocessor lists,
data regions, retention and deletion policy, access controls, incident
arrangements and existing security testing material.
We distinguish honestly between controls we have completed, controls we
rely on our cloud or model providers to deliver, and certifications or
enterprise features we do not currently have and would assess only when a
concrete client or business-stage requirement arises. We do not use vague wording to overstate
our current security posture — this page is written on that principle,
which is why it says plainly where the answer is “not yet”.