Drawn AI is two people routinely given access to other businesses' live systems. This page sets out how that access is requested, how narrowly it is held, and how it ends. Every control here is one two founders can genuinely operate, and specific enough to hold us to. We hold no certifications, and say so plainly.
1. Our security principles
- Least privilege. The narrowest access that does the job, read-only where enough, only while the work runs — not "admin because it's simpler".
- Minimum necessary data. We would rather query data where it lives than copy it — what we do not hold cannot be lost by us.
- Your systems stay yours. Accounts we use are created by you, visible in your logs, revocable without asking us.
- A short chain of custody. Two named people touch client systems: Liam and Jacob. No support tier, no offshore team, no contractors — a smaller attack surface, and a straight answer to "who accessed this?".
We align with the ACSC Essential Eight where it applies at our size — patching, MFA, restricting admin privileges, backups — but have not been assessed against any maturity level, and claim none.
2. Access to client systems
Our work connects to systems you already run — CRM, accounting, ERP, payments, document stores, HR — holding data about your customers and staff. That access is the real risk you are asked to accept.
How access is requested and approved
- We write down what we need before asking — the system, the permission level, why, and for how long.
- You approve it through your own named authoriser, and you create the account. We never create accounts in your environment for ourselves.
- It is recorded in a per-client register: system, account, permission level, grant and removal dates.
How access is held
- Named individual accounts. Liam and Jacob each have their own login — never a shared or generic "consultant" account, and never a staff member's. If your logs show an action, they show who took it.
- Read-only by default, with write and admin rights requested only for the task needing them, and time-boxed rather than left standing.
- MFA on every account we hold in your systems. Where one cannot enforce it, we agree a compensating control in writing.
- Credentials live in a dedicated password manager — individual accounts, multi-factor authentication, nothing shared in plain text — never in email, chat, spreadsheets or code. Better still: SSO or a scoped key, sharing no secret.
- Production is separated from development. We never develop in your live environment.
How access ends
| Trigger | What happens |
|---|---|
| A project ends | We list every account, you disable them, we confirm in writing |
| Subscription terminates | All access surrendered within 5 business days; see our Terms and Conditions |
| Device lost or credential exposed | Credentials rotated immediately, and you are told |
| At any time, for any reason | You revoke it yourself |
We reconcile that register against your systems quarterly.
Your right to audit and revoke. Ask at any time for a written list of every account we hold in your environment; we provide it within 5 business days. Revoke any of it at any moment, without notice or explanation — if that stops work, that is ours to schedule around.
3. Data handling
- We access in place rather than copy, copying only where a build requires it — a migration, an index, a document pipeline.
- Client environments stay separate. One client's system never reads another's.
- Test data. We build against synthetic or de-identified data wherever workable. Where a test needs production data we ask first, take the smallest extract, and delete it afterwards.
- Deletion. Working copies are deleted on request, and on termination within 30 days of the export window closing, except records law requires us to keep (APP 11.2).
4. Encryption
- In transit. Everything we build uses HTTPS with modern TLS (1.2 or above); administrative and database access runs over encrypted channels.
- At rest. Client data sits in reputable cloud platforms that encrypt stored data and backups, and we enable encryption options where a platform makes them a choice.
- On our devices. Full-disk encryption; secrets in a password manager, never in plain files.
Standard, current, correctly configured encryption — not "bank-grade" or "military-grade".
5. Hosting and location
Everything that touches your data runs in Melbourne. Including the AI.
| Purpose | Provider | Region |
|---|---|---|
| Hosting, databases, file storage, backups | Amazon Web Services | AWS Asia Pacific (Melbourne) — Australia |
| AI and large language model processing | Anthropic Claude via Microsoft Azure and Amazon Bedrock | Azure Australia Southeast (Melbourne) and AWS Asia Pacific (Melbourne) — Australia |
| Error monitoring and application logging | Self-hosted by Drawn AI | Australia |
| Business email | Private Email (Namecheap) | United States |
| Card payments | Stripe | Australia, with processing also in the United States |
Cross-border. Hosting, AI processing, logs and backups are all in Melbourne. Two things are not: our business email, hosted in the United States, and card payments through Stripe.
Be aware what that means for support. Email is our support channel, and support email carries screenshots, error output and record extracts — real client data, in a US-hosted mailbox. If your obligations do not allow that, say so during scoping: we can arrange onshore email, or run support through a channel inside your own environment.
We also will not overclaim on control. Our Australian regions are operated by overseas-headquartered providers, and we accept their standard terms rather than negotiating our own — so we do not assert that Australian hosting alone removes us from APP 8. We take reasonable steps to satisfy ourselves each provider handles information consistently with the Australian Privacy Principles, which means relying on their published contractual and security commitments.
Source code lives in private repositories restricted to the two of us. No client data, credentials or personal information goes into source control (see section 11), so it is not a disclosure of your information.
6. AI and model providers
- What is sent, and to whom. Only what a feature needs — a document to classify, a record to summarise — never your database wholesale. We name every model provider before we build, and do not swap providers mid-engagement without telling you.
- Provider retention. Where a provider offers a setting disabling training on submitted data or limiting retention, we enable it. We will not promise a setting a provider does not offer, or call data "never stored" when their terms say otherwise.
- No raw training, ever. We never use client data in raw form to train models — not ours, not a provider's, not a shared model other clients benefit from.
- De-identified and aggregated only. Product improvement uses accuracy measures, error patterns and usage statistics, never content. De-identification is real protection but not a guarantee — nobody can promise data could never be re-identified — so we keep its scope narrow.
- You can opt out entirely, at no charge, or require Australian-region models or no external model calls.
7. Devices and workstations
- Full-disk encryption and automatic screen lock on every device used for client work
- Prompt updates, and reputable endpoint protection
- No client data on personal or family devices, in personal cloud accounts or consumer messaging apps
8. Third parties and subcontractors
We use no subcontractors. All client work is done by Liam and Jacob. If that changes we will tell the affected client beforehand, and bind any subcontractor in writing to obligations at least as strict as those we owe you.
We rely on the providers in section 5 and use their security features rather than working around them. We cannot audit a major cloud provider, and will not pretend otherwise.
9. Incident response and breach notification
The Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988 (Cth)) applies where a breach is likely to result in serious harm.
| Stage | What we do | Timeframe |
|---|---|---|
| Contain | Cut off access, rotate credentials, stop the bleeding | Immediately on becoming aware |
| Notify the affected client | What we know, what we do not, what we are doing | Without undue delay — target: 24 hours |
| Assess | Whether an eligible breach occurred and serious harm is likely | Within 30 days, faster wherever possible |
| Notify OAIC and affected individuals | Where serious harm is likely | As soon as practicable after assessment |
| Report | Written account of cause, impact and fix | 10 business days |
What you can expect. Liam or Jacob owns the response, giving you facts as we establish them, separated from what is unconfirmed. Where it involves data we process for you, you lead the response: we do not notify your customers or regulator unless you ask in writing. We will not wait to establish a legal obligation before telling you.
10. Business continuity
A fair question for a two-person supplier, answered squarely:
- Backups. Systems we host are backed up daily, retained 30 days, encrypted at rest. We test restores quarterly — an untested backup is an assumption.
- Both founders can run everything. Either of us can access, deploy or restore any client system. If one is unavailable the other continues: response times may stretch, access does not break.
- If both were unavailable, your systems remain yours, accounts are in your own name, and your deliverables and documentation are yours under our Terms and Conditions.
- Source code and documentation. Your deliverables sit in a repository we grant you standing read access to on request — during the engagement, not only at exit — documented to architecture, integrations, credentials and deployment.
- Export at any time. A full export of your data in a common, usable format, at any point in the subscription, at no charge, within 5 business days.
11. Secure development
- Two-person code review. Every meaningful change is reviewed by the other founder before production — genuinely enforceable at two people.
- Secrets never in source control. Repositories are private and scanned for committed secrets; anything exposed is rotated, not merely deleted from history.
- Dependencies. We keep libraries current, monitor published vulnerabilities, and patch promptly — prioritising anything internet-facing or handling client data.
- Staged deployment. Changes pass through development and testing first; deployments are logged and reversible.
12. What we ask of clients
| What Drawn AI does | What the client does |
|---|---|
| Requests the minimum access needed, in writing | Approves it through a named authoriser, granting no more |
| Uses named individual accounts with MFA | Creates them, and enforces MFA in your systems |
| Protects credentials in a password manager | Removes our access at the end, and verifies it is gone |
| Secures the systems and code we build | Manages your users, offboards leavers, secures what we do not control |
| Keeps backups of what we host | Keeps independent backups, and meets its own regulatory obligations |
13. Reporting a vulnerability or security concern
Found a vulnerability in our website or a system we built? Email policies@drawnai.app with "Security" in the subject and enough detail to reproduce it. We acknowledge within 2 business days, and give you an assessment and remediation plan within 10 business days.
We will not pursue legal action against anyone reporting a vulnerability in good faith, provided you do not access, alter or destroy data beyond what is needed to demonstrate it, do not degrade a service, and give us a reasonable chance to fix it first. We run no bug bounty and cannot pay for reports.
14. Certifications and assurance
Honestly: we hold no security certifications. No ISO 27001, no SOC 2, no IRAP assessment, no independent penetration test, no assessed Essential Eight maturity, no security team, no round-the-clock monitoring. A two-person partnership claiming otherwise is worth a second look.
What we do instead:
- Complete your security questionnaire or vendor assessment on request, at no charge, answering "no" where the answer is no
- Sign a reasonable security schedule, data processing agreement or confidentiality deed — APP-equivalent obligations, breach timeframes, audit rights
- Accommodate client-imposed controls: Australian-only hosting, no external model calls, access reviews on your schedule
The Privacy Act's $3 million small business exemption remains in force as at August 2026, but is scheduled for removal. Rather than argue which side of a moving line we sit on, we follow the Australian Privacy Principles regardless — our finance, mining and health clients require it contractually anyway. APP 11 requires reasonable steps to protect personal information; this page is our account of them.
If your procurement requires a certified supplier, tell us early. We would rather lose the work than misrepresent our position.
Contact us
Security questions, questionnaires, incidents and disclosures:
- Email: policies@drawnai.app
- Website: drawnai.app
- Business: Drawn AI, ABN 89 787 755 848 — a partnership in Melbourne, VIC and Queensland, serving clients Australia-wide.
Security enquiries go straight to Liam and Jacob. Regulators: the OAIC, oaic.gov.au or 1300 363 992, and the ACSC, cyber.gov.au or 1300 292 371. The Privacy Act 1988 (Cth): legislation.gov.au.
See also our Privacy Policy, Terms and Conditions and Cookie Policy.