What's Built In
Security is not an add-on at Drift—it’s built into every layer of how the product works. From encryption to admin policies and compliance controls, we’ve designed the platform to keep sensitive workbook and document data protected without interrupting your Excel workflow.


Data Isolation
Tenant-scoped storage; least-privileged services

Encryption
TLS 1.2+ in transit; AES-256 at rest

No Model Training
We don’t train public models on your data

User Controls
User controlled data, and data deletion

SSO + MFA
SAML/OIDC integration (Okta, Azure AD, Google)

Compliance
SOC 2 Type II (in progress), GDPR/CCPA supported

Testing
Annual independent penetration testing & monthly scans

Subprocessors
Minimal, transparent, contractually bound


Encryption
TLS 1.2+ in transit; AES-256 at rest


Data Isolation
Tenant-scoped storage; least-privileged services


No Model Training
We don't train public models on your data


SSO + MFA
SAML/OIDC integration (OKTA, Azure AD, Google)


Compliance
SOC 2 Type II (in progress), GDPR/CCPA supported


Testing
Annual independent penetration testing & monthly scans


User Controls
Retention, deletion, and write-back policies


Subprocessors
Minimal, transparent, contractually bound
These safeguards ensure that only you control what’s uploaded, how long it’s retained, and whether it’s deleted.
Drift protects the platform; you decide how it’s used. That balance of trust and control is what makes Drift secure by design
How Drift Handles Your Data

Data We Collect
-
Documents you upload while using Drift
-
Account information like username, email, and organization
-
Usage telemetry like clicks and errors

How Your Data Is Handled
-
Files uploaded and chat content are encrypted at rest and in flight and never handled by outside of Drift or our subprocessors
-
Our subprocessors are contractually bound, vetted for security and compliance, and continually reviewed

Security Inside Excel
-
Drift is a sandboxed and secured browser window in Excel. It does not have access to your data and can only make outbound requests to Drift APIs, Stripe (for payment processing), and Microsoft (for account authentication)