That's not a promise. It's architecture. OrgDrift's scan engine runs entirely as client-side JavaScript — your HRIS, payroll, and ICM exports are parsed, compared, and scored on your own computer, the same way a calculator works. There is no upload step, no server-side processing, and no copy of your data for us to lose.
One exception, stated plainly: when you map columns, the header names from your file are sent to our mapping service so a language model can guess what GRS_PAY means. Header names only — never a row, never a cell, never an employee record. Turn on Private Mode and even that stops: mapping runs locally and the scan page makes no request carrying any part of your file.
Don't take our word for any of it. Load this page, disconnect your network, and run a scan in Private Mode. It completes. Software that works offline cannot be accessing your private information — and that is a stronger guarantee than any certificate we could buy.
This is a verifiable claim, not a marketing line. Invite your security team to run both tests during evaluation — we designed for that audience.
Load the scan workspace, then turn off Wi-Fi. Run your scan. It completes — because nothing is being sent anywhere.
Open your browser's developer tools (Network tab), run a scan with your real files, and watch the traffic. You will see zero requests carrying your file contents.
| Data | Leaves browser? | Where it goes |
|---|---|---|
| Your CSV / Excel files | Never | Processed in browser memory only |
| Employee names, emails | Never | Redacted by default before the engine sees them |
| Scan findings & reports | Never | Stored in your browser; you choose what to export |
| Your sign-in email | Yes | Authentication (magic link) + entitlement lookup |
| Payment details | Yes | Stripe — we never see card numbers |
| Scan count (a number) | Yes | Usage metering, keyed to a SHA-256 hash |
There is no customer-data database. Subprocessors: Vercel (serves the application code), Stripe (payments), Upstash (auth / entitlement metadata only — never file data).
One deliberate exception, governed in writing: in hands-on engagements, you share extracts with a named OrgDrift person through your own secure channel (your Box, SharePoint, or SFTP — never email), under a signed data-handling agreement, with verified destruction and a signed attestation at close. The product itself still never stores your data.
Under the OrgDrift Data Governance Framework (ODGF), restricted PII — SSNs, dates of birth, bank details, home addresses — is hard-blocked at file load. Names and emails are redacted automatically before any comparison runs; reconciliation works on employee IDs, not identities.
If your organization decides a name column is necessary, you can unblock it — but only after an explicit, per-column acknowledgment that you are disclosing PII under your organization's authority. That acknowledgment is recorded (who, when, which column) and stamped into the scan's evidence record. The default is always privacy; disclosure is always your documented choice.
Even disclosed values stay in your browser. Redaction controls what you see on screen and export — nothing is transmitted either way.
A deterministic, reproducible measure of control drift. Published methodology. Locked version. No editorial weights.
The OrgDrift Integrity Score (ODIS) is a 300–850 metric that summarizes how accurately data propagates across your HR, payroll, ICM, and CRM systems — like a FICO score for your control environment. It is calculated from the same Control Execution Record an auditor would inspect — nothing else. The same CER inputs always produce the same ODIS. The score is deterministic, version-locked, and tied to the hash of the underlying record.
Fraction of applicable controls with zero findings. The heaviest weight because passing controls are the primary evidence of a functioning control environment.
Total finding exposure relative to the materiality threshold. Anchored to SAB 99 materiality tiers — customer-provided pretax income when available, otherwise derived from scan data.
CRITICAL-severity findings per 1,000 employees. A single critical finding has outsized impact because it maps to a potential material weakness under PCAOB AS 2201.
Rate of change between snapshots, Bayesian-damped to avoid noise from one-time corrections. Measures whether drift is accelerating or decelerating.
Fraction of in-scope systems actually scanned (HRIS, ICM, CRM, Payroll). Partial scans produce partial confidence. ODIS reflects that.
Every ODIS score links to the CER that produced it. Every CER carries the ODIS it generated. They are a matched pair and ship together, always.
Band language maps to audit-standard practice (PCAOB AS 2201, COSO 2013 framework). OrgDrift did not invent these tiers.
Remediating a critical finding moves ODIS more than remediating a low-severity finding. The audit-standard weighting is preserved in the score.
Running verification on a larger portion of in-scope records increases confidence and raises ODIS.
Adding source systems to the Control Execution Record produces a more complete drift picture. More visibility, not less, raises the score.
OrgDrift commits to mechanical stability. The ODIS methodology published here is locked at v0.9 as of April 15, 2026. Any future change to factors, severity treatment, or score bands will be published as an explicit new version (v1.0, v2.0) with a migration note. We do not quietly re-weight.
The ODIS methodology — five-factor model, severity mapping, score bands, improvement levers, and reproducibility guarantees — is fully published above. The precise mathematical implementation is proprietary, in the same way FICO publishes how credit scores work without publishing the underlying algorithm. What matters for audit defensibility is determinism and reproducibility: the same Control Execution Record always produces the same ODIS, and both are cryptographically linked. That guarantee is what OrgDrift stands behind.
OrgDrift is currently in beta with browser-only processing. Our current architecture requires no server-side data handling, which significantly reduces compliance scope.
SOC 2 certification is on our roadmap — and our architecture was built so the certification scope is small, because there is no customer-data environment to audit. The thin surface that does exist (authentication, billing) already runs on SOC 2-certified infrastructure.
In the meantime, we support security reviews directly: architecture walkthroughs with your security team, completed security questionnaires (CAIQ / SIG), and the verification tests above. Early design partners who need a certificate on file are invited to talk to us about jointly accelerating the SOC 2 timeline.
AI-powered features (finding narratives and column mapping) transmit only structural metadata — field names, severity levels, and exposure amounts. Employee names and identifiers are never included in AI API calls.
“When my payroll file is being analyzed, whose computer is it on?”
For workflow tools that ingest your data into their cloud, the answer is: theirs. For OrgDrift, the answer is: yours. That isn't just a security posture — it's why OrgDrift can act as an independent referee for your systems of record. A tool that holds your data can't be a neutral witness to it.
Download our one-page security overview to forward to IT security or attach to vendor assessment forms.
Download Security Overview (PDF)Questions about our security architecture? security@orgdrift.com