Security

Security

Business workflows contain internal procedures and partner information. This page explains how DrillSpark handles and protects that data, listing only the measures we actually run.

Last updated: September 27, 2026

Your content and AI

Your content is never used to train AI
AI features use the Google Gemini API (paid tier) and the OpenAI API. Under both API terms, submitted content is not used for model training. DrillSpark does not provide your diagrams for training either.
Sent to AI only to generate a response
Content is sent to the AI provider only when you use chat or generation, and only to produce that response. Requests pass through Cloudflare AI Gateway.

Transport and storage

Encrypted in transit
The site and APIs are served over HTTPS (TLS) only, and HSTS prevents unencrypted connections.
Encrypted at rest
Diagrams, projects, and account data are stored in the database (Supabase) and encrypted at rest.
Where data is stored
The database runs in the AWS Asia Pacific (Seoul) region. Backups are taken daily, stored in a Google Cloud US region, and deleted automatically after 7 days.
No direct database access from outside
All direct connections to the database are denied. The app reads and writes only through access-controlled APIs.

Access control

Other people's diagrams are blocked at the database
Every table has row-level access control (Row Level Security). When your browser reads from the database, it never returns data you are not allowed to see.
APIs that handle your data check your sign-in
Server APIs that handle diagrams, accounts, or billing verify your sign-in token and reject requests that target another person's account or billing.
Permissions on the Organization plan
Give each member one of four roles: owner, admin, editor, or viewer. Mark a folder as restricted and only the people on its list can open it.
Audit log on the Organization plan
Who added members, changed roles, shared-folder access, public links, the trash, or the subscription — and when — is recorded. Entries cannot be changed, owners and admins can review them in organization settings, and they are kept for one year.

Application safety

Shared diagrams render safely
Rendered diagrams are stripped of scripts and other dangerous elements before display. Diagram types with known vulnerabilities are not rendered.
Browser-side defenses
Pages are served with security headers, including a ban on being embedded in other sites (clickjacking).
Protection against abuse
AI generation is rate-limited. Requests over the limit are rejected.
Ongoing vulnerability management
We regularly check the libraries we use for known vulnerabilities and update them, and review the app against common attack procedures.

Payments

DrillSpark never holds your card details
Payments are processed by Stripe. Card numbers are stored only by Stripe and never reach DrillSpark's servers or database.

Analytics

Session recording on public pages only
We use Google Analytics and Microsoft Clarity to improve the site. Clarity, which records the screen, runs only on public pages such as the landing page, articles, templates, and legal pages — never in the editor, dashboard, shared views, or presentations.

Services we run on

DrillSpark runs on the services below. Each provider's security and certifications are published on their own pages.

Contact

For security questions, security questionnaires from your company, or vulnerability reports, please reach us through the contact form.

Confirm