Security & Privacy
The safest place for applicant data is nowhere.
AuditDraw was designed from the beginning to go above and beyond on data security, because applicant information deserves nothing less. The principle is simple:
Hold sensitive data for as short a time as possible. Protect it heavily while it exists. Destroy it the moment the work is done.
Zero-persistence by design
AuditDraw does not keep records or a standing database of applicant data. Information exists only temporarily, inside the isolated environment that processes your lottery, and is purged completely once results are moved to delivery. Because there is no lasting repository of applicant personal information, there is nothing for a database breach to expose.
An untouched copy of your original source file is returned to you inside your deliverables archive, for your own records. On our side, it's gone.
Encrypted in transit. Encrypted at rest. Multi-key by design.
Data is encrypted whenever it moves and wherever it is processed. Transmissions use modern TLS encryption, and data is encrypted at rest during processing. Decryption requires several keys located across different systems rather than any single key, so even in the unlikely event of a breach, encrypted data stays unreadable without all of the pieces.
One isolated server per lottery. No internet, in or out.
Each lottery is processed on a dedicated server that spins up for that drawing alone, runs with no internet access in either direction, and generates its records before the data is purged. Applicant data is never exposed to human eyes during automated runs. The public report, certificate, and verification registry are all built to confirm the integrity of the process without revealing personal information.
Your policies, enforced by the platform.
Government and government-adjacent agencies often have to demonstrate that a vendor's access controls line up with their own security policies. With AuditDraw, that alignment is straightforward. When your account is created, the person in charge becomes the account manager (a role you can reassign at any time), and a granular permission system sets exactly what each member access.
The same control extends to the records themselves. The account manager names exactly who may download or receive deliverables, can maintain a standing list of addresses every completed lottery's archive is automatically sent to, and decides whether archives and reports remain available for download afterward, and for how long. Throughout, deliverables stay encrypted and behind the same permission and access controls.
Up to 100 people from your team or agency, using work email addresses on the same domain, can join the account at no additional cost.
More on billing, spend limits & service optionsFor IT & security teams
In summary, AuditDraw uses:
- Encryption in transit and at rest, with multi-key decryption across separate systems
- Isolated, internet-free processing on a dedicated server per lottery
- Zero-persistence data handling: no standing database of applicant PII
- Role-based access controls with granular per-member permissions
- Configurable login policy and optional IP allowlisting
- Layered request security with single-use tokens and flood protection
The layered security flow, multi-key decryption model, and our handling procedures can be reviewed in more depth on request. We'd be happy to work with your security staff and map our controls to your requirements.
Contact us for a security reviewSecurity your team can approve. A process your board can trust.
Create your AuditDraw account today. Registration is free and takes only a few minutes.*
*Accounts requiring manual eligibility review are typically confirmed within 1–2 business days.