Security your CISO signs off on.
SAML 2.0 SSO and SCIM, per-organization data isolation, and multi-cloud by design — backed by SOC 2 Type II, ISO 27001, and GDPR compliance.
Secure by design.
Enterprise identity
SAML 2.0 SSO and SCIM provisioning via Okta, Entra ID, and your IdP.
Data isolation
Each organization's data is logically isolated with strict access controls.
Encryption everywhere
TLS 1.3 in transit and AES-256 at rest, with managed keys.
Multi-cloud by design
Choose where workloads run; EU data processing is available.
API key auth
Scoped keys with configurable permissions, rotation, and usage monitoring.
Compliant & audited
SOC 2 Type II, ISO 27001, and GDPR, with regular penetration testing.
Single sign-on, provisioned automatically.
Connect your identity provider over SAML 2.0 for SSO, and let SCIM provision and de-provision users as your directory changes. End users can also sign in with email/password or OAuth via Google and Microsoft — all managed with secure tokens.
Audited, certified, and documented.
The platform is independently audited against SOC 2 Type II and certified to ISO 27001, with GDPR compliance, a DPA, and subprocessor transparency. EU data processing is available, and the platform undergoes regular penetration testing.
Isolated tenants, encrypted end to end.
Each organization's data is logically isolated with strict access controls that prevent cross-organization access. Data is encrypted with TLS 1.3 in transit and AES-256 at rest. Workflow execution logs are retained for 30 days, and your data can be deleted at any time, including on account deletion.
Defense in depth, by default.
Role-based access
Least-privilege roles with full audit logging on every action.
Key rotation
Rotate scoped API keys and monitor usage without downtime.
Human-in-the-loop
Approval checkpoints and traceability on every workflow run.
Incident response
A documented response process with status reporting.
How a request stays isolated and encrypted.
Every API call is authenticated by a scoped key, routed to the calling organization's isolated data, encrypted in transit and at rest, and logged for audit — retained for 30 days.
From sign-on to audit log.
Connect identity
Wire up SAML 2.0 SSO and SCIM provisioning from Studio — no code required.
Run securely
Execute at scale with scoped API keys, tenant isolation, and encryption.
Review & audit
Approve where it matters; every action is logged, traceable, and exportable.
What teams ask before they commit.
Is Draft & Goal SOC 2 compliant?
Yes. Draft & Goal is independently audited against SOC 2 Type II and certified to ISO 27001, with GDPR compliance, a DPA, and subprocessor transparency. The platform also undergoes regular penetration testing, so security controls are verified by third parties rather than simply claimed.
Does Draft & Goal support single sign-on and SCIM provisioning?
Yes. Draft & Goal connects to your identity provider, including Okta and Entra ID, over SAML 2.0 for SSO, and SCIM provisions and de-provisions users automatically as your directory changes. End users can also sign in with email and password or via OAuth with Google and Microsoft, all managed with secure tokens.
How does Draft & Goal keep each customer's data isolated?
Each organization's data is logically isolated with strict access controls that prevent any cross-organization access. All data is encrypted with TLS 1.3 in transit and AES-256 at rest with managed keys, workflow execution logs are retained for 30 days, and your data can be deleted at any time, including on account deletion.
Can Draft & Goal process our data in the EU?
Yes. Draft & Goal is multi-cloud by design, so you choose where workloads run, and EU data processing is available for teams that need European data kept in region. GDPR compliance, a DPA, and subprocessor transparency support the data-protection review your legal and security teams will run.
How are API keys managed and secured in Draft & Goal?
API access uses scoped keys with configurable permissions, usage monitoring, and rotation without downtime. Every call is authenticated by its key, routed to the calling organization's isolated data, encrypted in transit and at rest, and logged for audit, giving security teams a complete trail of programmatic access.
Show us the workflow.
We'll show you the 10x.
Bring the marketing workflow that eats your week. We'll build it live, with your data and your models, in 30 minutes.