SECURITY

CAD files are sensitive.

Designed to comply with most security requirements.

Last updated: August 2026

01 Infrastructure

  • Single-region GCP

    All data resides in Google's us-central1, defined in Terraform.

  • Encrypted

    TLS 1.3 in transit, AES-256 at rest.

  • Locked Down

    Geometry workers run on read only filesystems with network access restricted to only internal routes.

  • No third-party kernels

    No Parasolid, ACIS, or licensed code, and tight control of the geometry stack.

  • Minimal third-party provider use

    The only external provider is Sendgrid for sending transactional emails.

02 Data Retention

  • 90-day auto-deletion

    Automatic retention policies for files, toolpaths, and messages remove everything after 90 days. This is enforced by storage lifecycle rules on every bucket we write to, not by application code remembering to run.

  • Anonymous uploads: 1 hour

    If you upload without an account, 90 days does not apply to you. The file, the toolpath, and the throwaway session are swept about 1 hour after submission — the same window in which your result link works.

  • Deletion on request

    Email [email protected] for deletion of models added to our test corpus with "help improve NullCAM" reports.

  • Training data

    Geometry may be used to improve our algorithms during the 90-day retention window. Nothing is kept past it.

03 SOC2 Type II

SOC2 Type II certification is planned. If you need it, email [email protected] and we'll tell you when it ships.

Current Security Status

Beta
Product Stage
GCP
Infrastructure
90 days
Data Retention
Planned
SOC2 Type II