Data security and confidentiality

How we handle your data

Draftwell AI processes real, unpublished Hong Kong IPO material. This page answers the questions a law firm's vendor review asks, including the ones where the honest answer is “not yet”.

Last reviewed 21 August 2026

The facts

These are the facts of the standard production environment. A separately scoped deployment carries its own hosting and model routes, approved with your firm and set out in its own contract.

Application servers, database, uploaded files, backupsAlibaba Cloud, China
Drafting and research model APIsDeepSeek open platform and Alibaba Cloud Bailian first-party Qwen, both approved China routes. They are the default because they keep your material in China and out of training; other frontier models are available in a separately scoped deployment
Any other model routeNone in this environment. A provider allowlist in our code refuses every provider outside the approved set
Third-party analytics, error monitoring, support SDKsNone at all. There is no Sentry, no APM, no event tracking and no advertising SDK anywhere in the code
Vector indexing of client materialNone. Vector search covers only the public prospectus corpus. Material you upload is never converted into vectors or written to any index
Transactional emailAlibaba Cloud / Alibaba Enterprise Mail, China; email addresses and necessary notification content only
PaymentsAlipay, WeChat Pay and transfer methods expressly shown in the product; no matter content
Code repositoryPrivate GitHub repository (offshore). It contains no real client material — test fixtures are synthetic or publicly sourced

Using real client material

Can we upload real, unpublished client material?

Yes. Draftwell AI is built for exactly that: management interview responses, due diligence questionnaires, roadshow materials, bank OSS outlines, financial information, industry consultant reports and other deal documents. What you upload is used only for retrieval, analysis, drafting, citation checking and information-request generation within the matter you assign it to. It does not enter any shared library, and it is never used for another client's matter.

Client material is held with matter-level isolation, encrypted storage, controlled access and deletion on your instruction. Real matter material is sent only to approved domestic enterprise model APIs. Those APIs expressly commit not to use user data for training and to keep user material confidential.

Firms differ in their AI, vendor and outsourcing approval policies. If yours requires a vendor review, we can provide the data flow, model list, subprocessor list, retention and deletion policy and access controls for your firm to assess as a package.

Model training, providers and processing location

Will Draftwell AI or its model providers train on our material?

No. We do not use your uploaded files, extracted content, generated drafts, lawyer edits, feedback or matter outcomes to train our own models, and we do not add any of it to cross-client datasets, evaluation sets or product-improvement corpora.

Real confidential matters use approved enterprise APIs only. Under the applicable API terms, customer inputs, model outputs and feedback may not be used for pre-training, fine-tuning, reinforcement learning, human annotation, model evaluation, training dataset construction, or the optimisation of models, algorithms or services. A provider may retain data to the extent necessary and reasonable for legal obligations, content and system safety, troubleshooting and ordinary service operation — that retention is not a training licence.

Which models do you use? Could you switch models without telling us?

We operate a model whitelist for real confidential matters. In the standard production environment, approved routes are limited to two domestic enterprise APIs: the DeepSeek open platform and Alibaba Cloud Bailian's first-party Qwen. A separately scoped deployment has its own approved routes, agreed with your firm before it is enabled.

We will not silently move a confidential matter onto an unapproved model, an offshore model, a consumer product or a model aggregator. This is enforced in code: every model call is checked against the provider allowlist first, and an unapproved provider — offshore, free-tier, or without a written commitment — raises an error and stops, rather than falling back or rerouting. If the primary model is briefly unavailable, the job fails safely or waits to retry; it never lowers the data protection standard to get through.

Does our material leave China in the standard production environment?

No. Our standard production environment, file storage, database, caches, backups and model APIs are all deployed in, or confined to, approved Chinese processing regions. Real confidential matters are not sent to offshore model APIs, and are not moved offshore by load balancing, error monitoring or analytics tooling. There is an additional structural safeguard here: we have no third-party error monitoring or product analytics integration at all, so there is no path by which data leaves the country through instrumentation.

If we ever introduce a feature, provider or piece of infrastructure that could involve offshore processing, we will review it before enabling it and disclose it as required by contract and law — not treat it as an unannounced back-end change.

Can you support overseas hosting or international model providers?

Yes, as a separately scoped deployment. Model and hosting choice belongs to your firm: we can run drafting and research on international frontier models, enabled only after that deployment's hosting location, model providers, data flow and contractual terms have been approved.

What that never does is change the standard environment underneath you. Our standard production environment remains in mainland China, and we will not reroute an existing matter in the background.

Do you send our entire document set to the model?

No. We apply a minimum-necessary principle. Documents are stored, parsed, classified and indexed inside our own controlled environment, and only the pages, passages, tables or structured facts a given task requires are sent to an approved model API.

Drafting one risk factor, for instance, does not put your whole document set into a single model request. This reduces unnecessary exposure and improves both accuracy and source traceability.

Does the public research feature send the issuer's name to a search engine?

At matter confirmation, we use public search engines to identify the company's principal business and find comparable companies with similar businesses.

After that, section drafting uses only the due diligence questionnaires, management interviews, financial information and other matter material you provide, and performs no external search.

Matter isolation

Could material from different clients, firms or matters mix?

No. Accounts and matters are the isolation boundary. Each matter's source files, extracted text, structured facts, generation history, citation records and caches are held separately, and every route that reaches matter content checks membership before reading anything — a non-member's request is refused before any content is touched.

Material in one matter never surfaces as a retrieval result in another, and is not reachable by another client through a similar company name, industry or terminology.

This is covered by an automated regression suite across every content-bearing route, including a guard test that fails if a new route is added without isolation coverage, so the protection cannot quietly decay.

Does our material go into your precedent database, or get used on other matters?

No. Our public precedent database and client confidential material are two entirely separate data domains. The public database holds only lawfully obtained public prospectuses, listing applications and other public-source documents. What you upload does not enter it, and is not turned into anonymised “learned experience” searchable by other clients.

This is absolute at the architectural level: our vector index covers the public prospectus corpus only, and client uploads are never converted into vectors or written to any shared index. So the situation where the source file is deleted but its vectors linger does not arise.

Even with issuer or matter names removed, we do not repurpose client material for product training, template extraction or cross-client knowledge reuse. That would require your separate, express, written and revocable authorisation for defined content.

Can other lawyers at our firm see my matter?

Not unless the matter owner or an authorised administrator grants them access. Buying the same Matter Pass, or belonging to the same firm, does not by itself grant access to a matter; access follows membership of that specific matter.

For shared matters we record members, roles, join times and principal actions. Colleagues without access, other clients and ordinary platform users cannot see the matter name, files, drafts or activity.

Our people's access

Can Draftwell AI staff or founders read the files we upload?

In the product: no. Our admin console has no interface for viewing client file contents or draft text — admin views carry account, job status, failure reason and order metadata only. An admin account also cannot read matter content it is not a member of through the ordinary routes.

Named personnel obtain time-limited, scope-limited, audited temporary access only where you request technical support, where a security incident requires investigation, or where the law clearly requires it. Access is revoked afterwards and the activity stays in the security audit record.

Will support copy our material into a test environment while debugging?

No. Development, test and production are separate, and test environments use public or synthetic material — our code repository contains no real client material, and the DD questionnaires and management responses used in testing are synthetic or publicly sourced. Engineers may not copy the real client database, files or full prompts into a development environment to reproduce a problem.

Where an issue genuinely cannot be investigated without client content, we obtain the matter owner's authorisation first and work through controlled, read-only, time-limited access in production wherever possible. Any temporary copy is protected to the same standard and deleted promptly.

Do you use client material to improve prompts, the product or evaluation?

Not by default. We improve system performance from technical signals that contain no client content — whether a job succeeded, processing time, feature usage frequency, error class. We do not automatically add client files, output drafts, lawyer edits or specific feedback to prompt optimisation, evaluation sets or training material.

There is a structural advantage here: we have no third-party product analytics or event tracking of any kind, so there is no situation in which your usage is collected by an outside platform. The operational information available to us is limited to job records in our own database.

If we wanted to use a redacted sample from a specific matter for product improvement, we would describe the scope and obtain express written authorisation. Declining has no effect on your use of the service.

Encryption, logging and system security

Is our material encrypted?

Yes. Traffic between your browser and Draftwell AI is encrypted with HTTPS/TLS. Source files, the database and backups use the cloud platform's encryption-at-rest capability — which is the platform's control, not something we implement ourselves, and we describe it that way deliberately.

File and draft downloads are served through session-authenticated routes that re-check matter membership on every request. We do not use long-lived public download URLs, so there is no situation in which a leaked link is enough to retrieve a document.

Model API credentials, database passwords and other secrets live only in controlled server-side environment variables or secret management — never in front-end code, the browser, documentation or ordinary logs. A dedicated continuous-integration workflow is configured to run blocking secret scanning over the full repository history to keep credentials out.

Do your logs retain prompts, model output or file contents?

Our application logs and job records are not designed to hold client file contents, complete prompts or complete model outputs. They record technical metadata: job ID, matter ID, model provider, model name, processing time, status and error class.

One fact worth stating: we use no third-party logging, error monitoring or performance analysis platform. No Sentry, no APM, no event tracking. Operational records stay in our own database and servers and do not flow to any third party.

Provider errors are redacted before they are stored or displayed. A provider SDK exception embeds the HTTP response body, and for a chat completion that body echoes the prompt — which is your material. We reduce these to the exception class, HTTP status code and request ID, with a source-level test preventing the raw form being reintroduced.

In the rare case where content is genuinely needed to diagnose a fault, we use an authorised temporary diagnostic procedure rather than switching on full-text logging. Temporary content is access-limited, given a deletion deadline, and kept separate from ordinary operational logs.

Does the issuer's identity appear in filenames, exports or payment records?

No, not in those surrounding identifiers. Draftwell AI uses the matter name as its code name. Matter headings, job progress and export filenames show that name rather than the issuer's company name. Payment channels see the Draftwell AI brand, a random order number, amount and payment status; they receive no issuer name, matter name or client-file content.

The issuer's company name is still used inside matter fields and draft text where drafting requires it, and an exported prospectus draft may of course contain that name as instructed by the lawyer. The commitment here is that filenames, surrounding matter identifiers and payment records do not create an additional identity disclosure; it is not a promise to remove the issuer from the draft itself.

Service emails likewise do not place a matter name or issuer identity in their subject or body, and the email call sites are covered by regression tests.

Retention, deletion and termination

How long do you keep our matter material?

While a matter is in use, we keep its material as you instruct, so that drafting, version recovery, citation checking and later revision remain possible. A matter has no retention period of its own; it follows the account that owns it. After 24 months without account activity, that account's matter content is deleted. We send deletion notices at 18 months and 22 months of inactivity, and do not delete without a record that notice was sent. There is no read-only or degraded stage in between: until deletion, a matter can be read, exported and drafted in as normal.

If other members remain, ownership transfers to the longest-standing remaining member instead of the matter being deleted because its former owner is inactive. Where the account holds an unused credit balance, only matter content is deleted: the account and the balance remain, and signing in still reaches them. Where no balance remains, account identity and credentials are anonymised after matter content is deleted, while de-identified legal-acceptance evidence is retained. Order, payment and invoice records are kept for their statutory periods and no longer point to an identifiable person.

You may also delete an individual file or the whole matter before those periods expire. We do not extend retention for model training or cross-client product optimisation. Commercial entitlements and file retention are separate: a Matter Pass runs for 24 months, and its expiry only ends uncharged generation — it deletes nothing.

Underlying model providers may retain request data for as long as necessary and reasonable to complete the request and for content and system safety, troubleshooting, legal compliance and service operation. We cannot presently require absolute zero retention from an underlying model, and we approve only enterprise APIs whose retention purposes are limited and which do not use retained content for training or model and service optimisation.

Can we delete a single file, a draft, or a whole matter?

Yes. You can delete an individual uploaded file or an entire matter. Deleting a matter removes its storage tree from the live system (source files, extracted content, checkpoints, generated drafts and exports) and the associated database records (documents, jobs, draft versions, citation records, information-request items). Existing download URLs stop working immediately.

Data in backups is cleared on the backup rotation cycle, currently 7 days. Within that window backups are used for disaster recovery only, and are never restored into live business systems or otherwise processed.

Deletion completeness is covered by an automated test that builds a matter with uploads, jobs, drafts, citations and information requests, deletes it, and asserts that the storage tree is gone and no orphan rows remain. The table list is enumerated from the schema itself, so a new matter-scoped table is covered without anyone remembering to update the test. A job still running when its matter is deleted aborts at its next checkpoint rather than recreating the directory, and the credits it was holding are released so you are not charged for a matter you deleted.

Can you confirm deletion afterwards?

Yes, on request. We can provide confirmation by email or formal letter stating that the relevant live-system data has been deleted and that backup data will be cleared within the established rotation cycle. The confirmation carries no file contents — only the matter name, deletion scope, execution time and backup clearance arrangement.

A tamper-evident, exportable deletion receipt is not built into the system. We would assess that feature if a firm contract specifically requires it.

Where law, financial audit, a security incident or a dispute requires a small number of records to be kept, we limit them to necessary non-content records and explain the basis and period.

If we stop using Draftwell AI, can we export before deleting?

Yes. You can download your uploaded source files, generated drafts (in Word), version records and information-request exports at any time. These downloads work whatever state the account is in and are not withheld because payment has ended — downloading and deleting check matter membership only, with no entitlement or credit check anywhere in the path, and that behaviour is locked in by a regression test.

Export is currently item by item, per file and per draft. One-click matter-level packaging is not a current feature; we can assess it if a firm's handover or exit process specifically requires it.

Once you have exported, you can delete. Terminating the service does not authorise us to keep using matter material for product research, model training or other clients' work.

Subprocessors and provider changes

Besides the cloud platform and model providers, who else touches the data?

We can give you the complete list, because it is short. This is the subprocessor list — there is no separate document.

SubprocessorPurposeData reachedRegion
Alibaba CloudApplication hosting, database, file storage, backupsAll matter contentChina
DeepSeek open platformDrafting and research model APIThe relevant excerpts each request needsChina
Alibaba Cloud Bailian (first-party Qwen)Drafting, research and auxiliary model APIAs aboveChina
GitHubSource code hostingNo client content. The repository holds no real client materialOffshore
Alibaba Cloud / Alibaba Enterprise MailVerification and necessary service emailEmail address and notification type; no matter contentChina
Alipay and WeChat PayPayment, refund and reconciliationOrder number, amount and payment status; no matter contentChina

We have no third-party product analytics, error monitoring, support desk, CRM or advertising integration. There is no path by which your files, prompts or model outputs reach a platform unrelated to the service; payment channels do not receive that content.

What happens if a model provider or its terms change?

We keep model APIs and critical infrastructure under continuing vendor management. When a provider changes its training, data use, retention, region or subcontracting arrangements, we re-assess whether it still meets our approval standard.

Where a change would materially reduce the protection of client data, we do not simply carry the old approval forward. We suspend that route, switch to another already-approved route, or notify clients where that is warranted. A firm's contract can specify notification for material subprocessor or processing changes.

Can we require that only a specific model is used?

Today: we can already fix the drafting model per matter, but that control currently sits with our administrators rather than being self-service. If your firm requires it, we will fix the route when the matter is opened, and it will not switch to another model in the background.

A self-service matter-level model restriction interface is not built in. We can assess it if your firm specifically requires self-service visibility or control.

Restricting the model may affect speed, availability, feature behaviour or cost, and we will say so before enabling it. Where no model meeting the restriction is available, the job waits or fails — it does not work around your restriction.

Can we ask for shorter retention, a dedicated instance or other configuration?

You can ask. Our standard service runs on a single security baseline. For firm-level or multi-matter arrangements we can discuss shorter Draftwell-side retention, specific model routes, dedicated cloud resources, separate keys, custom access control or additional audit reporting.

Some requests are constrained by the fixed security and compliance retention rules of the underlying model APIs. We can shorten our own retention, but we cannot promise that a model provider performs no security or statutory retention at all. We will be explicit about which parts are technically configurable and which have to be solved in the provider contract.

Incidents, continuity and independent validation

What happens if there is a breach or other security incident?

We contain the impact, preserve evidence, investigate scope and remediate. Where an incident is confirmed to have affected client material, we notify the affected clients as soon as reasonably practicable and keep providing known impact, progress and recommended steps.

Notification does not wait until every technical detail is resolved — but neither do we report every ordinary system fault as a data breach. Our security contact is security@draftwell.cn, monitored by a founder. Our underlying providers' obligations to notify us of incidents affecting client data rest on their published service terms.

Where we are today. Draftwell AI is run by two founders, so an incident is handled and communicated by a founder directly. At our current size we do not separately maintain a written incident-response playbook, a provider escalation contact directory or a tabletop-exercise programme. The commitments above describe the direct response model we actually use; they do not imply that separate documents or programmes exist. A firm engaging us can fix a specific first-notification deadline in the Data Processing Addendum or order form. We will reassess the need for separate procedures if the team, a client contract or regulation requires them.

If the cloud platform or a model API goes down, could we lose material or drafts?

Saved files and drafts are not lost because a single model call or job fails. Uploads are persisted before a job starts; the model call is a processing step, not the only place the data lives. Matter state and completed draft versions are held in the database and storage layer.

When a job fails, completed checkpoints are kept so you can retry or resume from a recoverable stage, and a failed job never overwrites a finished version with partial work. We back up the database and key matter data, and verify the restore procedure.

Do you hold SOC 2, ISO 27001 or another security certification?

No. Draftwell AI is an early-stage company and holds no SOC 2, ISO 27001 or comparable certification. We will not borrow our cloud or model providers' certifications to imply that we are certified ourselves.

What we offer instead is material you can actually check: the data flow, the model and subprocessor lists, data regions, the retention and deletion policy, access controls, incident arrangements, and the real state of our security testing. We will pursue independent penetration testing and appropriate certification as client requirements and our stage warrant.

Have you had a penetration test or code security review?

Today: no third-party penetration test has been carried out. Authentication, authorisation, file upload and download, matter isolation, background jobs and administration are covered by automated tests and code review. Continuous-integration rules are also configured for secret and dependency vulnerability scanning.

We will commission a third-party penetration test when a firm's procurement requirements or our business stage warrants it; after that we can provide a shareable summary or remediation note.

Security testing does not replace day-to-day engineering control. We continue to maintain dependency scanning, secret checks, authorisation regression tests and security-update rules, and set explicit remediation deadlines for high-risk findings.

Output quality and professional responsibility

Could the model invent facts, or write another company's material into our draft?

Any generative model can produce errors, so we do not treat model confidence as evidence of reliability. We reduce the risk of unsupported statements through matter isolation, source retrieval, per-claim citation, restrictions on how comparable material may be used, placeholders for missing information, and the lawyer's review.

Comparable company material is used for structure, style and disclosure scope only — it is not a source of fact about your applicant. A fact without adequate support in your matter material is marked as outstanding or to be confirmed, rendered as [●] with the responsible party noted, rather than filled in by the model. The final draft still requires the responsible lawyer's review.

How do we know which document a sentence came from?

Source traceability is a core design property. A factual statement supported by matter material carries a citation marker in the browser, and the lawyer can open the supporting document, page or passage. Word exports preserve source references as footnotes.

A citation reflects the evidentiary source of a statement, not a final judgement on legal sufficiency. Where a citation cannot be verified, where sources conflict, or where material is insufficient, the uncertainty is shown to the lawyer rather than quietly removed. If a source document is later deleted, its citations are marked as pointing to a removed file instead of continuing to present as ordinary supporting evidence.

Can Draftwell AI output be filed or sent to a client directly?

No. What we produce is a first draft for lawyer review and revision, together with an information-request list — not a final legal opinion or filing document. It removes a great deal of blank-page drafting, but the responsible lawyer still has to verify facts, legal judgement, disclosure adequacy, terminology consistency and the current state of the deal.

Citations, placeholders, information requests, adviser confirmation items and version records support that review. We never submit unreviewed model output to a regulator, a client or another deal party — the system has no outbound submission capability of any kind.

Rights, confidentiality and contract

Who owns the material we upload and the drafts produced?

You retain your uploaded material and the intellectual property in it. We take only the limited rights needed to process it in order to provide the service, and gain no training, publication, resale or cross-client rights by virtue of your upload.

Subject to your compliance with the applicable contract and payment terms, you may use the drafts generated for your matter in your legal services and deal work. We retain rights in the underlying software, general workflows, public database, template logic and system technology — which does not give us rights in your matter facts or confidential content.

What confidentiality obligations does Draftwell AI carry?

We carry contractual confidentiality obligations over client material and may use or disclose it only to provide, secure and support the agreed service. Personnel and subprocessors who touch the material are bound by confidentiality and security obligations no lower than the service requires.

Confidentiality survives termination. Where disclosure is legally required, we notify you promptly to the extent the law permits and limit the scope of disclosure so far as we can. We treat client names and deal names as confidential too — including by not naming them on our website, on social media or in fundraising materials.

Will you sign our data processing agreement or complete our security questionnaire?

Yes. For firm-level or multi-matter procurement we can sign a reasonable data processing addendum and complete vendor security, privacy and AI questionnaires. We can supply the data flow, model and subprocessor lists, data regions, retention and deletion policy, access controls, incident arrangements and existing security testing material.

We distinguish honestly between controls we have completed, controls we rely on our cloud or model providers to deliver, and certifications or enterprise features we do not currently have and would assess only when a concrete client or business-stage requirement arises. We do not use vague wording to overstate our current security posture — this page is written on that principle, which is why it says plainly where the answer is “not yet”.

Asking us something else

If your firm's vendor review needs something this page does not cover, write to security@draftwell.cn and we will answer it directly, including where the answer is that we have not built it yet. That address is also where you report a suspected security issue.