Security

Your files never leave your browser.

That's not a promise. It's architecture. OrgDrift's scan engine runs entirely as client-side JavaScript — your HRIS, payroll, and ICM exports are parsed, compared, and scored on your own computer, the same way a calculator works. There is no upload step, no server-side processing, and no copy of your data for us to lose.

One exception, stated plainly: when you map columns, the header names from your file are sent to our mapping service so a language model can guess what GRS_PAY means. Header names only — never a row, never a cell, never an employee record. Turn on Private Mode and even that stops: mapping runs locally and the scan page makes no request carrying any part of your file.

Don't take our word for any of it. Load this page, disconnect your network, and run a scan in Private Mode. It completes. Software that works offline cannot be accessing your private information — and that is a stronger guarantee than any certificate we could buy.

Don't Take Our Word For It

Two ways to prove it in under a minute

This is a verifiable claim, not a marketing line. Invite your security team to run both tests during evaluation — we designed for that audience.

1 · The offline test

Load the scan workspace, then turn off Wi-Fi. Run your scan. It completes — because nothing is being sent anywhere.

2 · The network-tab test

Open your browser's developer tools (Network tab), run a scan with your real files, and watch the traffic. You will see zero requests carrying your file contents.

Full Disclosure

What leaves your browser, exactly

DataLeaves browser?Where it goes
Your CSV / Excel filesNeverProcessed in browser memory only
Employee names, emailsNeverRedacted by default before the engine sees them
Scan findings & reportsNeverStored in your browser; you choose what to export
Your sign-in emailYesAuthentication (magic link) + entitlement lookup
Payment detailsYesStripe — we never see card numbers
Scan count (a number)YesUsage metering, keyed to a SHA-256 hash

There is no customer-data database. Subprocessors: Vercel (serves the application code), Stripe (payments), Upstash (auth / entitlement metadata only — never file data).

One deliberate exception, governed in writing: in hands-on engagements, you share extracts with a named OrgDrift person through your own secure channel (your Box, SharePoint, or SFTP — never email), under a signed data-handling agreement, with verified destruction and a signed attestation at close. The product itself still never stores your data.

PII Governance

PII is blocked by default — disclosure is your documented decision

Under the OrgDrift Data Governance Framework (ODGF), restricted PII — SSNs, dates of birth, bank details, home addresses — is hard-blocked at file load. Names and emails are redacted automatically before any comparison runs; reconciliation works on employee IDs, not identities.

If your organization decides a name column is necessary, you can unblock it — but only after an explicit, per-column acknowledgment that you are disclosing PII under your organization's authority. That acknowledgment is recorded (who, when, which column) and stamped into the scan's evidence record. The default is always privacy; disclosure is always your documented choice.

Even disclosed values stay in your browser. Redaction controls what you see on screen and export — nothing is transmitted either way.

How Your Data Flows

Everything stays on your machine

Your CSV FileHR / ICM / CRM / PayrollYOUR BROWSERPapaParse + Pattern MatchingDrift Engine + SHA-256All processing happens hereYour ResultsFindings + EvidenceTRUST BOUNDARY — YOUR DEVICEOrgDrift ServersNothing transmitted
Security Architecture

Three layers of protection

Browser-Only Processing

  • All CSV parsing, comparison logic, and drift detection runs in your browser
  • No data is transmitted to OrgDrift servers
  • Files are purged from browser memory after processing
  • Works offline — disconnect WiFi after loading to verify

Enforced by Your Browser

  • Content Security Policy headers block all outbound data connections
  • Your browser — not our code — enforces these restrictions
  • Inspect headers yourself: DevTools > Network > Response Headers
  • No third-party scripts on analysis pages

Evidence Architecture

  • SHA-256 hashing on scan output — tamper-proof results
  • Timestamped Control Execution Records
  • No PII in metadata — only structural findings retained
  • Designed for audit-grade evidence without audit-grade risk
Methodology

The OrgDrift Integrity Score

A deterministic, reproducible measure of control drift. Published methodology. Locked version. No editorial weights.

The OrgDrift Integrity Score (ODIS) is a 300–850 metric that summarizes how accurately data propagates across your HR, payroll, ICM, and CRM systems — like a FICO score for your control environment. It is calculated from the same Control Execution Record an auditor would inspect — nothing else. The same CER inputs always produce the same ODIS. The score is deterministic, version-locked, and tied to the hash of the underlying record.

Five-Factor Model

Five dimensions. Weighted composite.

Control Pass Rate (30%)

Fraction of applicable controls with zero findings. The heaviest weight because passing controls are the primary evidence of a functioning control environment.

Material Exposure Ratio (25%)

Total finding exposure relative to the materiality threshold. Anchored to SAB 99 materiality tiers — customer-provided pretax income when available, otherwise derived from scan data.

Critical Finding Density (20%)

CRITICAL-severity findings per 1,000 employees. A single critical finding has outsized impact because it maps to a potential material weakness under PCAOB AS 2201.

Drift Velocity (15%)

Rate of change between snapshots, Bayesian-damped to avoid noise from one-time corrections. Measures whether drift is accelerating or decelerating.

Coverage Confidence (10%)

Fraction of in-scope systems actually scanned (HRIS, ICM, CRM, Payroll). Partial scans produce partial confidence. ODIS reflects that.

Every ODIS score links to the CER that produced it. Every CER carries the ODIS it generated. They are a matched pair and ship together, always.

Interpretation

What the number means.

800–850
ExcellentSystems are aligned. Unqualified audit opinion. No material drift detected within scan scope.
740–799
GoodMinor comments only. Isolated findings present, routine remediation recommended.
670–739
FairSignificant deficiency. Audit committee communication warranted. Controls require review.
580–669
PoorMaterial weakness indicated. May affect audit opinion. Remediation urgently recommended.
300–579
CriticalMultiple material weaknesses. Adverse audit opinion likely. Controls are not operating as designed within scan scope.

Band language maps to audit-standard practice (PCAOB AS 2201, COSO 2013 framework). OrgDrift did not invent these tiers.

How to Improve

Every score has a path.

Resolve findings by severity

Remediating a critical finding moves ODIS more than remediating a low-severity finding. The audit-standard weighting is preserved in the score.

Increase scan coverage

Running verification on a larger portion of in-scope records increases confidence and raises ODIS.

Expand systems in scope

Adding source systems to the Control Execution Record produces a more complete drift picture. More visibility, not less, raises the score.

Version

ODIS v0.9

OrgDrift commits to mechanical stability. The ODIS methodology published here is locked at v0.9 as of April 15, 2026. Any future change to factors, severity treatment, or score bands will be published as an explicit new version (v1.0, v2.0) with a migration note. We do not quietly re-weight.

ODIS-METHODOLOGY-v0.9 · Published draft, April 15, 2026.
SHA-256 canonical seal lands at v1.0 release — the v0.9 draft version is republished under the v1.0 hash on the same URL so evidence chains never break across the lock.
Proprietary

What stays under the hood.

The ODIS methodology — five-factor model, severity mapping, score bands, improvement levers, and reproducibility guarantees — is fully published above. The precise mathematical implementation is proprietary, in the same way FICO publishes how credit scores work without publishing the underlying algorithm. What matters for audit defensibility is determinism and reproducibility: the same Control Execution Record always produces the same ODIS, and both are cryptographically linked. That guarantee is what OrgDrift stands behind.

Infrastructure

Built on trusted foundations

Vercel
SOC 2 Type II certified infrastructure serving the application code
HTTPS / TLS 1.3
Encrypted page delivery on every request
Stripe & Upstash
SOC 2-certified payments + auth/entitlement metadata — never file data
No Customer-Data Store
Your files are never processed or retained server-side
Compliance Roadmap

Where we are today

OrgDrift is currently in beta with browser-only processing. Our current architecture requires no server-side data handling, which significantly reduces compliance scope.

SOC 2 certification is on our roadmap — and our architecture was built so the certification scope is small, because there is no customer-data environment to audit. The thin surface that does exist (authentication, billing) already runs on SOC 2-certified infrastructure.

In the meantime, we support security reviews directly: architecture walkthroughs with your security team, completed security questionnaires (CAIQ / SIG), and the verification tests above. Early design partners who need a certificate on file are invited to talk to us about jointly accelerating the SOC 2 timeline.

AI-powered features (finding narratives and column mapping) transmit only structural metadata — field names, severity levels, and exposure amounts. Employee names and identifiers are never included in AI API calls.

The one question to ask any vendor in this category

“When my payroll file is being analyzed, whose computer is it on?”

For workflow tools that ingest your data into their cloud, the answer is: theirs. For OrgDrift, the answer is: yours. That isn't just a security posture — it's why OrgDrift can act as an independent referee for your systems of record. A tool that holds your data can't be a neutral witness to it.

Resources

Share with your security team

Download our one-page security overview to forward to IT security or attach to vendor assessment forms.

Download Security Overview (PDF)

Questions about our security architecture? security@orgdrift.com