YOUR DRAWINGS · CONTROLLED ACCESS
Security and drawing data.
Drawings belong in a controlled company workspace. Access, processing routes and release decisions are part of the drawing workflow.
Company and drawing access
Company members can access their company’s jobs. CAD suppliers receive assigned work. Mechanical and electrical review permissions are separate. Private files are accessed through short-lived signed links after a server-side permission check.
Storage and international access
The intended production database and drawing storage are in the EU, with the Supabase project provisioned in Frankfurt. Vercel application execution must also be configured in an approved region. CAD staff may access assigned drawings from India. EU storage does not mean that all human access or every service’s metadata stays in the EU.
AI processing
Drawing processing is disabled unless its provider route and contract reference are approved in server configuration. The V2 integration uses Mistral’s EU document-processing endpoint and an approved AWS Bedrock EU route for drawing comparison. No global fallback is configured. AI identifies possible issues; a competent human reviewer makes the technical decision.
Client drawings must not be submitted to consumer AI products. Any contractual commitment about provider training, retention or regional processing must be confirmed for the actual account before activation. This page does not substitute for those terms.
Encryption, retention and deletion
The platform uses HTTPS for transport and provider-managed storage encryption. There is no claim of end-to-end encryption. Retention periods and backup deletion times must be agreed in your service terms. Request access or deletion assistance through your company’s customer-service ticket area; deletion is not represented as instantaneous removal from all backups.
Subprocessors and incidents
The service design uses Vercel, Supabase, an email provider and Stripe, with approved AI and CAD-processing providers where enabled. Drawing files are not included in email notifications or SEO analytics. Report suspected unauthorised access through customer service. Production incident contacts, subprocessor terms and transfer arrangements must be confirmed before accepting restricted client material.