Security
Last updated September 9, 2026
The short version
Draven is given access to the two things a business can least afford to lose control of: its mail and its calendar. Everything below is what we do about that. If a claim is not on this page, we are not making it.
Your data is separated by account
Every record in Draven belongs to exactly one account, and ownership is checked against your session on every single request rather than assumed from the page you came from. There is no shared pool and no cross-account lookup.
The same rule applies to the connections you authorize. A request made from your account can only reach the Google account you connected to it. Draven never answers one customer’s question with another customer’s data, and it is not technically able to.
Access, credentials and encryption
All traffic to getdraven.com and to the Draven application is served over HTTPS. Passwords are stored only as salted hashes, never in a form we or anyone else could read back.
The tokens that let Draven reach your Google account are encrypted before they are written down, and are decrypted only in the moment a request you made needs them. Disconnecting your Google account deletes the stored credential immediately, and you can revoke access independently at myaccount.google.com/permissions.
We ask for the least access that works
Connecting Google is optional, and Draven runs without it. When you do connect, we request only the permissions the features actually use, and Drive and Sheets are requested read only. What each permission is used for is listed in full in our privacy policy.
Draven reads your data to carry out what you asked and to assemble your daily brief. It does not scan your account for any other purpose, and it does not keep a copy of your mailbox or your calendar.
Your data is never training data
We do not use your content to train, retrain, or improve any generalized artificial intelligence or machine learning model, our own or anyone else’s. Content sent to a language model to produce an answer is covered by API terms that prohibit training on it.
Draven’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell or transfer your Workspace data, and we do not use it for advertising.
Service providers
Running Draven takes a small number of infrastructure providers, for hosting, for the language model that generates responses, and for transactional email. Each is bound by contract to process data only to provide that service to us, and none of them are permitted to use it for their own purposes.
Beyond the language model provider named in our privacy policy, we do not publish the list. If you are evaluating Draven and your procurement process needs it, write to security@getdraven.com and we will provide it under a mutual NDA.
Deleting your data
You can disconnect a connected account at any time from inside Draven. To delete your Draven account and everything in it, email privacy@getdraven.com. We action it and confirm to you when it is done.
Reporting a vulnerability
If you believe you have found a security issue, we want to hear about it before anyone else does. Email security@getdraven.com with enough detail to reproduce it. We acknowledge every report we receive and will keep you updated until it is resolved.
We will not pursue legal action over research carried out in good faith: work only against your own account, do not access or modify anyone else’s data, do not degrade the service for other people, and give us a reasonable window to fix the issue before publishing. We do not run a paid bounty program today, and we will credit you if you would like us to.
Where we are today
Draven is an early product from a small company, and we would rather tell you that than imply otherwise. We hold no third party security certification at this time, and we will say so plainly on this page until that changes rather than gesturing at one we do not have.
If your organization has a security review we need to pass, send it to security@getdraven.com and we will answer it honestly, including where the answer is no.