Security and data

What leaves your workstation, what is kept, and the one setting that stops storage and training.

In this section

The short version

  • Your SOLIDWORKS files are not uploaded. What leaves the machine is derived context, field by field in what leaves the workstation.
  • The exception is a drawing standard, which you upload on purpose: the reference drawings, and any part or assembly you submit with them, are stored in full. Your CAD files.
  • By default on Free, Student and Professional, your content is stored and may be used to train CADABRA’s models. The default, by plan.
  • One account setting stops both, "Do not store my data", off by default. What changes when it is on.
  • On Enterprise, zero retention is configured for your organization when the agreement is set up. The plan tier does not switch it on. The default, by plan.
  • Stored chats, attachments, standards files and feedback are encrypted at rest under a key held in a hardware-backed vault, separate from the data. Always on for Enterprise, one setting away on every other plan. Encryption.
  • The providers whose models generate your output are contractually barred from training on your content. Sub-processors.
  • CADABRA does not sell customer data, and does not share it with third parties for their own purposes.

Running a vendor security review

CADABRA answers a security questionnaire directly, against the controls in place today.

Read in this order, then send yours.

  1. Data handling, which is written in the order a review asks.
  2. Privacy policy §3 for retention and training, §6 for the third parties involved, §7 for how long each category is kept.
  3. The EULA, which is the binding version of the training and retention terms.
  4. Security for the control summary, and status for uptime and incidents.
  5. Send the questionnaire.

Support answers within one business day. Vulnerability reports go to team@cadabrai.com, also published at /.well-known/security.txt.

Questions

Do you train on my CAD files?
By default on Free, Student, Standard and Professional, yes: the EULA and privacy policy state that CAD geometry, prompts, and metadata may be used to operate, maintain, and improve CADABRA and its AI models. You can stop it at any time with the data setting in your dashboard, which takes effect from the moment you turn it on rather than retroactively. On Enterprise, zero-retention handling is configured as part of the agreement.
How do I stop CADABRA training on my designs?
Turn on the data setting in the dashboard under Preferences. It processes your designs, prompts, and files only to answer the request in front of it, keeps none of them on CADABRA’s servers, and excludes them from training. The trade-off is that it also turns off cloud chat history and cross-device recall, because both are stored data. It is included with every plan.
What security controls does CADABRA have?
CADABRA answers a security questionnaire directly, against the controls in place today. Single sign-on and role-based access on Enterprise. Encrypted in transit. A second at-rest layer under a key held in a hardware-backed vault separate from the data, one setting on every plan. Indexed CAD content filtered to the account that wrote it. Only the context a given prompt needs is loaded at run time. A 90-day expiry on the operational logs CADABRA keeps about the service. Zero-retention handling on Enterprise, configured per organization.
Where does CADABRA process our CAD data?
CADABRA runs as an add-in on your workstation and reaches a hosted processing environment for inference. It does not run offline. Enterprise runs in a dedicated cloud tenancy under zero-retention handling, so prompts and model context are processed to answer the request and kept on no CADABRA server. Your vault is never uploaded wholesale: what leaves the workstation is the context a given prompt needs.