Security
Security
Business workflows contain internal procedures and partner information. This page explains how DrillSpark handles and protects that data, listing only the measures we actually run.
Last updated: September 27, 2026
Your content and AI
- Your content is never used to train AI
- AI features use the Google Gemini API (paid tier) and the OpenAI API. Under both API terms, submitted content is not used for model training. DrillSpark does not provide your diagrams for training either.
- Sent to AI only to generate a response
- Content is sent to the AI provider only when you use chat or generation, and only to produce that response. Requests pass through Cloudflare AI Gateway.
Transport and storage
- Encrypted in transit
- The site and APIs are served over HTTPS (TLS) only, and HSTS prevents unencrypted connections.
- Encrypted at rest
- Diagrams, projects, and account data are stored in the database (Supabase) and encrypted at rest.
- Where data is stored
- The database runs in the AWS Asia Pacific (Seoul) region. Backups are taken daily, stored in a Google Cloud US region, and deleted automatically after 7 days.
- No direct database access from outside
- All direct connections to the database are denied. The app reads and writes only through access-controlled APIs.
Access control
- Other people's diagrams are blocked at the database
- Every table has row-level access control (Row Level Security). When your browser reads from the database, it never returns data you are not allowed to see.
- APIs that handle your data check your sign-in
- Server APIs that handle diagrams, accounts, or billing verify your sign-in token and reject requests that target another person's account or billing.
- Permissions on the Organization plan
- Give each member one of four roles: owner, admin, editor, or viewer. Mark a folder as restricted and only the people on its list can open it.
- Audit log on the Organization plan
- Who added members, changed roles, shared-folder access, public links, the trash, or the subscription — and when — is recorded. Entries cannot be changed, owners and admins can review them in organization settings, and they are kept for one year.
Application safety
- Shared diagrams render safely
- Rendered diagrams are stripped of scripts and other dangerous elements before display. Diagram types with known vulnerabilities are not rendered.
- Browser-side defenses
- Pages are served with security headers, including a ban on being embedded in other sites (clickjacking).
- Protection against abuse
- AI generation is rate-limited. Requests over the limit are rejected.
- Ongoing vulnerability management
- We regularly check the libraries we use for known vulnerabilities and update them, and review the app against common attack procedures.
Payments
- DrillSpark never holds your card details
- Payments are processed by Stripe. Card numbers are stored only by Stripe and never reach DrillSpark's servers or database.
Analytics
- Session recording on public pages only
- We use Google Analytics and Microsoft Clarity to improve the site. Clarity, which records the screen, runs only on public pages such as the landing page, articles, templates, and legal pages — never in the editor, dashboard, shared views, or presentations.
Services we run on
DrillSpark runs on the services below. Each provider's security and certifications are published on their own pages.
Contact
For security questions, security questionnaires from your company, or vulnerability reports, please reach us through the contact form.
