Private beta — invite only

Write your security policies once. Keep them current for good.

Somebody asked you for a policy — a customer, an insurer, a regulator. You wrote it. Then it sat in a shared drive and quietly went out of date. CraftAClause is where those documents live, get revised, and get flagged before they go stale.

63

Policy templates in the library, across access control, HR, continuity, and third-party risk.

13

Written specifically for SMBs, covering a wide range of industries.

Every

Version kept, with a full audit trail and one-click rollback to any earlier draft.

The actual problem

Policies don't fail loudly. They just get old.

Nothing breaks when a policy goes stale. There's no alert, no failing build. You find out at the worst possible moment.

Month 0

You write the policy for a customer security review. It's accurate, and everyone signs off.

Month 9

You've changed MDM vendors, moved to SSO, and hired a remote team. The document says none of it.

Month 18

A questionnaire lands with a two-week turnaround, and nobody can remember which file was the real one.

“But I can just use AI for this”

You've probably already tried the ChatGPT route.

So have we — CraftAClause runs on AI too. But a chat window hands you a document and walks away. The draft was never the hard part. Keeping it accurate, versioned, and findable a year from now is.

A chat window

One good draft, then you're on your own

  • The policy lives in a thread you'll never find again
  • Every document starts from a blank prompt — nothing remembers your business
  • No version history; last month's wording is simply gone
  • Nothing tells you when a policy has quietly gone stale
  • Copy, paste, reformat, and hope the file in the drive is the latest one
CraftAClause

The same AI, wrapped in a system that keeps it alive

  • Every policy has a home — versioned, searchable, and audit-ready
  • Answer questions about your business once; every draft after is written with them in hand
  • Full history and one-click rollback to any earlier version
  • Review reminders land before a document goes out of date
  • Branded PDF export and revocable share links, ready to hand an auditor

Same model under the hood. The difference is everything that happens after the draft.

How it works

Three steps, and then it looks after itself.

01

Start from something real

Pick from 63 reviewed templates, import a policy you already have, or describe what you need and let the builder draft it. You answer questions about your business once, and every policy after that is written with those answers in hand.

02

Shape it in the editor

Edit the document directly, or ask the AI co-editor for a change. It comes back with a specific before-and-after you can accept or reject line by line — not a wall of regenerated text you have to re-read from scratch.

03

Set a cadence and forget it

Choose every six months, yearly, or every two years. We email you when a review comes due, and the dashboard shows at a glance which documents are healthy and which have drifted.

What you get

Built around the part everyone skips: what happens after you publish.

Every draft is recoverable

Publishing snapshots the document. You can read any earlier version, see who changed what and when, and roll back to any point without losing the history in between.

  • Full version list per policy, with an audit trail of actions
  • One-click rollback that records itself as a new version
  • Export any version as a branded, print-ready PDF
v4Current — device encryption clause added14 Feb
v3Remote work section rewritten02 Dec
v2Reviewed, no changes18 Aug
v1Created from template27 Mar

A reviewer who reads the whole document

The co-editor works on the policy you actually have, not a generic sample. Ask it to tighten a clause, add a section, or check the document against a standard, and it proposes targeted edits with the reasoning attached.

  • Suggestions arrive as reviewable diffs, accepted one at a time
  • Section numbering and contents rebuild themselves as you edit
  • Your company profile shapes the language, so it isn't boilerplate
Suggested — Section 6, Vendor Access
Vendors are expected to follow our security requirements.
Vendors with access to production systems must complete a security review annually and accept the terms in Appendix B before access is granted.
Accept Reject

Share it without handing over a file

Send an auditor or a customer a read-only link instead of emailing a document that will be out of date the moment it lands. Revoke it when the review is over.

  • Public link, no account needed on the other end
  • Revocable at any time from the policy page
  • Invite colleagues to a shared workspace with their own access
Live craftaclause.com/share/a3f9…
Shared with an external reviewer Read-only
Revoke access Any time
The template library

Sixty-three starting points, not one generic pack.

Most policy tools hand you a single generic bundle. The library spans the documents small businesses actually get asked for — access control, HR, business continuity, third-party risk, and more — each one reviewed and ready to tailor to how you actually operate.

Access Control Business Continuity Security Operations Third-Party Risk Data Security Human Resources Physical Security Incident Response Remote Work Cryptography Governance & Compliance Infrastructure
Where we are

Early, and we'd rather say so.

CraftAClause is in private beta. Here's what works today and what doesn't, so you can decide whether it's worth your time yet.

Working now

  • AI policy builder and document co-editor
  • Version history, audit trail, and rollback
  • Review cadences with email reminders
  • Template library and import of existing policies
  • Branded PDF export and revocable share links
  • Team workspaces and passwordless sign-in

Not built yet

  • Billing — the beta is free while we're in it
  • Staff acknowledgements and attestation tracking
  • Slack and Teams notifications
  • Framework mapping to SOC 2 or ISO 27001 controls
  • SSO and SCIM provisioning

Built and hosted in the United States. Your account and policy data stay on US-based infrastructure, and the handful of services we rely on all process data in the US — see our subprocessors.

Get your policies somewhere they can't rot.

Tell us your email and we'll send an invite as spots open. No card, no call, no demo to sit through.