Your design IP is treated as the confidential asset it is
Schematics contain your company's most sensitive engineering work. CADY is built around the assumption that your files must never be accessible to anyone who isn't you.
How we protect your schematic data
Each measure below applies to all accounts on all plans from day one, not only to enterprise tiers.
All data between your client and the CADY API travels over TLS 1.3. Older TLS versions and plain HTTP are refused at the load balancer. HSTS headers enforce HTTPS on every response.
Uploaded schematic files and review reports are stored with AES-256 encryption on the storage layer. Encryption keys are managed by the cloud provider's KMS and rotated annually.
Each account's files are stored in an isolated namespace. No query path in the API can retrieve a file belonging to a different account. Access is enforced at the storage layer, not only at the application layer.
API keys carry a role scope (read-only, submit, admin) and can be revoked at any time from the Settings panel. Team plan members have individual keys; rotating one key does not affect other team members. Keys are hashed before storage and are never shown in logs.
Uploaded schematic files are retained for up to 90 days by default and then deleted automatically. Review reports follow the same schedule unless you explicitly export them. You can delete any review file from the dashboard at any time; deletion is applied within 24 hours across all storage replicas.
CADY's rule engine is a deterministic rule evaluator, not a model trained on customer submissions. Your schematics are never used to improve or train any AI or ML component. The violation report is produced entirely from rule logic, not from inference over prior user files.
CADY runs on a major cloud infrastructure provider in the EU-West region. Network ingress is restricted to the API endpoints. Internal services communicate on a private VPC with no public IPs. Automated dependency scanning runs on each deployment pipeline.
If you discover a security issue in CADY, please report it to [email protected]. We respond to initial reports within 2 business days. We request 90 days to investigate and remediate before public disclosure. We do not pursue legal action against good-faith researchers.
Questions about how CADY handles your data?
Our team answers security questions directly. No sales calls, no qualification process.