Security

Built for financial data. Designed to hold up.

Every design decision starts from the same question: what would a bank, a lawyer, or a business trusting us with their customer's bank information actually need to know?

Last updated July 14, 2026

Encryption, start to end

Sensitive financial information is encrypted at every stage — from the moment it's entered, while it's stored, and throughout any process that touches it. We use encryption standards consistent with what banks and financial institutions rely on, layered with additional protections designed around the sensitivity of data Drafsense handles.

Access controls

Every business's data is fully isolated from every other business using Drafsense. Access to sensitive systems is restricted on a strict need-to-know basis, monitored continuously, and reviewed regularly.

A permanent, tamper-resistant record

Every meaningful action taken in Drafsense — creating a check, capturing an authorization, accessing sensitive data — is permanently logged in a way that cannot be quietly altered or erased. If a question is ever raised about a specific check, there is a real record to point to.

Verified, not assumed

Before a check is created, the bank and routing information behind it is checked against authoritative, government-published data — not accepted blind. Combined with our authorization system, this significantly narrows the room for error or manipulation compared to manual, unverified check-writing tools.

Real authorization, not just a signature line

Every check created under Mandatory Authorization is tied to a documented consent record — captured directly from the payer, timestamped, and preserved. That record is what stands behind the check if it's ever questioned, not just a printed statement that a signature 'isn't required.'

Data retention, minimized by design

We keep sensitive information only as long as it's actually needed for its purpose, on a defined and enforced schedule, after which it is automatically and permanently removed. We do not accumulate sensitive data beyond what's necessary.

No custody of funds

Drafsense does not accept, transmit, or otherwise touch funds, and is therefore not a money transmitter or money services business. We never hold, transfer, or have custody of money at any point. We generate the draft; you deposit it through your own bank, the same as any check you'd write by hand.

A warning to anyone considering misuse

Using Drafsense to create a check without the account holder's real, documented authorization is not just a violation of our Terms of Service — it may be a serious federal and state crime, independent of anything Drafsense does.

  • Bank fraud (18 U.S.C. § 1344) — a federal offense punishable by up to 30 years in prison and substantial fines
  • Mail or wire fraud (18 U.S.C. §§ 1341, 1343) — where a scheme involves the mail or electronic transmission
  • Identity theft and aggravated identity theft (18 U.S.C. §§ 1028, 1028A) — where another person's bank account or identifying information is used without authorization, carrying mandatory additional prison time on top of any underlying offense
  • State-level check fraud, forgery, and identity theft statutes — which apply independently and vary by jurisdiction

Financial institutions are legally required to file Suspicious Activity Reports with federal regulators when they identify potential check fraud. Drafsense's audit records, authorization documentation, and account information may be provided to law enforcement, banks, or regulators in connection with any investigation into suspected misuse — and account activity connected to suspected fraud results in immediate suspension, reviewed at our discretion, without exception.

If you're operating in good faith, obtaining real authorization for every check you create, none of this applies to you. It exists for the small number of people who might otherwise think this platform is a place to hide.

Have a specific security question? support@drafsense.com