🔒

Security & Compliance

Security & Compliance

 

Why is CAD ROOMS a secure choice for managing CAD files and engineering data?

CAD ROOMS is built specifically for engineering teams that need to manage sensitive CAD files, product data, and collaboration workflows securely. Unlike generic file-sharing tools, CAD ROOMS combines secure cloud infrastructure, role-based access, file version control, contribution workflows, and audit-friendly processes to help teams protect engineering IP while collaborating efficiently.

Is CAD ROOMS ISO 27001 certified?

Yes. CAD ROOMS is ISO/IEC 27001 certified for the applicable scope of our Information Security Management System (ISMS). Our ISMS has been audited by an independent third party against rigorous international standards for managing information security risks. A copy of the certificate is available on request.

How is my data encrypted?

All data on CAD ROOMS is encrypted in transit and at rest:
  • In transit → TLS 1.2+ for all connections between your device and CAD ROOMS.
  • At rest → AES-256 encryption for stored files and metadata.
  • Key management → Encryption keys are managed according to CAD ROOMS' internal security policies and reviewed regularly.

How does CAD ROOMS control access to customer data?

CAD ROOMS follows a least-privilege access model. Access to customer data is limited to authorized personnel who need it to provide support, maintain the platform, or meet security and compliance obligations. Access is reviewed regularly and protected by internal security controls.

Where is my data stored?

CAD ROOMS is hosted on Amazon Web Services (AWS) in the European Union, with primary infrastructure located in Frankfurt, Germany.
Customer project data, including CAD files and related metadata, is stored and processed within the EU, helping customers meet GDPR and data residency requirements.

Is CAD ROOMS GDPR compliant?

CAD ROOMS is designed to support compliance with the EU General Data Protection Regulation (GDPR). We:
  • Process personal data transparently and lawfully.
  • Support data subject requests, including access, deletion, and portability.
  • Sign a Data Processing Agreement (DPA) with customers on request.

Does CAD ROOMS back up customer data?

Yes. CAD ROOMS maintains backups to support platform reliability, disaster recovery, and business continuity. Backup procedures are managed according to our internal security and operational policies.

What happens to my data if I delete it or close my account?

Customers can request deletion of their data in accordance with contractual and legal requirements. When data is deleted, CAD ROOMS removes or anonymizes it according to our data retention policies, except where retention is required for security, legal, or compliance purposes.

How does CAD ROOMS handle security incidents?

CAD ROOMS maintains internal procedures for identifying, investigating, and responding to potential security incidents. If an incident affects customer data, we notify affected customers in accordance with applicable laws, contractual obligations, and our incident response process.

How can I request your ISO 27001 certificate or DPA?

Email us at support@cadrooms.com and we will share:
  • Our current ISO 27001 certificate
  • A Data Processing Agreement (DPA)
  • A security overview of our platform
Enterprise customers can also request a completed security questionnaire.
 
 
Â