Security
Straight answers for the person doing diligence
Somebody at your firm has to satisfy themselves that this software belongs on your network and near your clients' information. This page is written for that person. It says where data lives on each edition, what we do and don't do with it, and one thing about our installers we would rather you hear from us than from a warning dialog.
Where your data lives
This is the question that matters most, and the answer is different on each edition, because that is the point of offering four of them.
- Single User Desktop
- Everything stays on your computer: the software, your libraries, your documents. There is no account and no server. Even license verification happens on the machine, so the application needs no internet connection to work. The only network contact is an optional check for available updates, and you can decline it.
- RediDraft™ Classic
- Every draft is assembled on your own workstation. No variable data is sent to the server and no finished drafts are stored there. What lives on the server is your library: your Form Volumes and the language your firm has written. That server is either RediDraft Cloud or one you host yourself, and if you host it, nothing leaves your walls at all.
- Private Web
- One installation, one database, one firm: yours. It runs on a server inside your building or in a cloud account your firm owns, so libraries, Form Volumes, and client work all sit on infrastructure under your own security policies. There is no shared tenancy and no commingled data, and nothing about your practice reaches our servers.
- SaaS Web
- Your firm's libraries live in our hosted environment. Assembled documents do not: when you draft in a browser, each document is generated, delivered to your machine, and removed from our servers. Work in the desktop client instead and the document is never generated on our side at all, because the client asks the server which pieces of the library it needs and builds the document on your workstation. Your clients' answers never leave it.
That last point is worth restating, because it is the answer to the most common objection we hear from careful firms. Choosing a hosted deployment does not have to mean typing client information into somebody else's website. The desktop client is included with every seat on both web editions, and the difference is architectural rather than a setting you have to trust us about.
Nothing is generated, so nothing leaks to a model
RediDraft™ is deterministic document assembly. Every word in every document comes from language your attorneys wrote and approved, and the same inputs produce the same document every time. There is no generative AI anywhere in the drafting path, which means there is no prompt carrying your client's circumstances to a model in someone else's cloud, and no third-party AI vendor in your data flow to assess.
If your firm is being asked to document its AI exposure, this is a short section to write .
Offline libraries, and why editing still needs a connection
The desktop client can pin the libraries a user needs, keeping an encrypted, self-contained copy on that machine so they can read and assemble documents on a plane or at a courthouse with no network. Your administrator sets how long a pin stays valid, and refreshing one is a deliberate act.
Editing library content still requires a live connection, and that is a deliberate restriction rather than a limitation we haven't gotten to yet. It means there is exactly one authoritative copy of your firm's library at all times. Nothing is ever merged in the background or quietly reconciled between machines.
About the Windows install warning
Better you hear this from us than from your screen. Our Windows desktop applications are not code signed, so the first time you run the installer, Windows shows a blue "Windows protected your PC" panel. Click "More info," then "Run anyway," and it installs normally. You will see it once. Our macOS applications are signed, so none of this applies there.
We know how that looks, and we have decided to live with it. A code signing certificate does not tell you software is safe; it tells you a certificate authority confirmed a company name and cashed a check. Malware ships with valid certificates often enough that the assurance is thinner than it appears, and the cost recurs every year for a company our size. We would rather put that money into the product and tell you plainly what to expect.
What we offer instead is something you can actually check: every release is published with a SHA-256 checksum, so you can confirm the file you downloaded is the file we built. That tells you more than a publisher name does, and it costs you nothing to verify.
On RediDraft™ One, you can sidestep the question entirely. Private Web and SaaS Web are complete in the browser. Nothing is installed on any workstation, so there is no installer to warn about and no exception for anyone to make. The desktop client is an option for people who prefer a native application, never a requirement, and a firm can run every seat in a browser without giving up a single feature.
Where it genuinely matters is Classic. The desktop client is the only way to use Classic, so there is no browser to fall back on. If your firm's policy forbids unsigned Windows executables outright, or your workstations use application allowlisting, your administrator will need to approve RediDraft™ explicitly rather than relying on a publisher rule. That is worth finding out before a rollout rather than during one. Send them to us and we will give them the checksums and whatever else they need.
What we never do
- We don't sell or mine your content. Not to anyone, for any purpose, and it is never used to train an AI system.
- We don't hold your work hostage. On the editions that run on your own hardware, the software keeps working if a license lapses. Only updates and support end.
- We don't phone home from the desktop. Single User Desktop verifies its license locally. The one outbound call is an optional update check you can decline.
- We don't outsource the answer. Questions about any of this reach the US team that builds and runs the software, not a support vendor reading from a script.
If your IT provider or malpractice carrier needs something this page doesn't cover, ask. You will get an answer from someone who worked on the software rather than a form response, and if the honest answer is "we don't do that," you will get that too.