DrawingPhin Security

Last updated: August 5, 2026

DrawingPhin is built for mechanical drawings, FAIR generation, and AI-assisted drawing review. We understand that uploaded drawings may contain confidential engineering information, manufacturing requirements, quality requirements, customer data, and business-sensitive information.

This page explains the security practices and current security boundaries of DrawingPhin.

1. Security Model

These are the rules the product enforces today, not goals for a later release:

  • customer drawings are never public — no public folders, no permanent public URLs;
  • every file request is checked against the account that owns the file, and a request from any other account is answered as if the file did not exist;
  • uploaded drawings are encrypted before they are stored, each with its own key (section 5);
  • file access is authorized on the server, never by the browser;
  • AI and OCR processing runs through server-side systems;
  • AI provider credentials and API keys stay on the server and are never sent to the browser;
  • logs and analytics do not record drawing content;
  • Engineering Data, Personal Data, billing data, and operational logs are handled separately.

2. Protected Engineering Data

DrawingPhin treats uploaded drawings and related technical outputs as Engineering Data.

Engineering Data may include:

  • uploaded drawings and PDFs;
  • rendered drawing pages;
  • OCR text and bounding boxes;
  • extracted dimensions, tolerances, GD&T, datums, notes, and title block data;
  • FAIR characteristics and balloon numbers;
  • drawing review findings;
  • user corrections and confirmations;
  • exported files — FAIR forms as Excel (.xlsx), drawing review reports as PDF or Word (.docx).

Engineering Data is handled separately from Personal Data such as name, email address, billing information, IP address, and marketing preferences.

For more detail, see the Engineering Data & AI Policy and Privacy Policy.

3. Server-Side Processing

DrawingPhin uses backend services to handle uploads, permissions, AI/OCR processing, project state, credit usage, and exports.

The browser interface does not directly access raw storage, AI provider credentials, or final authorization logic. File access, export generation, and project retrieval all go through server-side permission checks.

4. File Storage and Access

Uploaded drawings and generated files are stored in protected cloud storage on Google Cloud infrastructure, located in the United States. Processing also happens in the United States.

Engineering files are not placed in public folders and are not reachable through permanent public URLs. Uploads and downloads use signed links that expire 15 minutes after they are issued.

Before a user can open a project or download an export, DrawingPhin verifies that the request is authenticated and that the requesting account owns the file. A request from any other account is answered as "not found", so the existence of a file is never disclosed to someone who does not own it.

5. Encryption

Drawings are encrypted both in transit and at rest.

In transit, all connections use TLS.

At rest, each uploaded drawing is encrypted with its own individual data key. That data key is itself encrypted by a managed key service, and only the encrypted form of the key is stored. The drawing and the key that opens it are never stored together in usable form, so access to the storage bucket alone does not yield readable drawings.

Beyond this description, we do not publish detailed key management or infrastructure configuration on a public page.

6. AI and OCR Providers

DrawingPhin does not use customer drawings, OCR results, FAIR data, drawing review findings, or user corrections to train AI models.

DrawingPhin may use third-party services for OCR, AI model processing, cloud storage, hosting, authentication, payments, analytics, email, monitoring, and security.

To run an analysis, your drawing is sent to the OCR and AI processing services that carry it out — drawing recognition, FAIR generation, auto-ballooning, or drawing review. Which providers are involved depends on the file type and on the analysis you request.

If you author custom review rules, the text of those rules is part of the review request and is sent to AI model providers together with the drawing. Do not put credentials, personal data, or information you are not permitted to share into rule text.

We may add, remove, or replace providers, models, infrastructure services, or processing methods without individual notice, provided that we continue to apply reasonable safeguards and the commitments described in our policies.

DrawingPhin does not authorize third-party AI or OCR providers to use customer Engineering Data to train their models unless the customer separately and explicitly agrees.

7. Access Control

DrawingPhin uses account-based access controls to separate user projects. A user can reach only the projects, uploaded files, processing results, and exports that belong to their own account or authorized team workspace.

The internal console our team uses to operate the service shows account and job metadata only: file name, part number, processing status, token usage, and cost. It does not display drawing images, extracted characteristics, review findings, or FAIR content.

Support or engineering access to the underlying Engineering Data is limited to cases where it is reasonably necessary, such as troubleshooting a reported problem, investigating a security issue, preventing abuse, complying with a legal obligation, or answering a support request from the user.

8. Logging and Analytics

DrawingPhin may collect technical logs and usage metrics to operate, secure, debug, and improve the service.

Examples include:

  • login events;
  • upload events;
  • processing status;
  • error codes;
  • processing time;
  • credit usage;
  • feature usage;
  • security events.

Logs and analytics do not record drawing images, full OCR text, or full FAIR output. Where a specific support request or security investigation requires more detail, that access follows section 7.

9. Data Retention and Deletion

Uploaded drawing files are deleted from DrawingPhin's storage automatically 30 days after they were last uploaded. Every stored drawing carries an expiry date, and a scheduled job runs daily to remove the ones that have passed it — both the encrypted file and the key material that opens it. Working on a drawing again renews its 30-day window, so an active project does not expire underneath you.

Analysis results and project history — characteristics, FAIR data, drawing review findings, and export records — are kept with your account so you can reopen, edit, and re-export past work.

Unconfirmed drafts are held in your own browser rather than on our servers, and you can clear them from your device at any time.

If you cancel your subscription, you can delete your files first. Anything still remaining is removed within 30 days of cancellation.

Deleting saved project history yourself, from inside the app, is not available yet. Until it is, email drawingphin@drawingphin.com and we will remove the data you identify from active systems, subject to backups, security logs, billing records, and legal retention limits.

10. Incident Response

If DrawingPhin becomes aware of a security incident, we will take reasonable steps to investigate, contain, and address the issue.

Depending on the nature of the incident, this may include:

  • identifying affected systems;
  • restricting access or rotating affected credentials;
  • assessing whether Engineering Data or Personal Data was involved;
  • fixing the issue;
  • documenting the cause;
  • notifying affected customers where required by law or contract.

11. Current Security Boundaries

DrawingPhin is an early-stage SaaS product. Unless separately agreed in writing, DrawingPhin does not currently claim or provide:

  • SOC 2 certification;
  • ISO 27001 certification;
  • FedRAMP authorization;
  • ITAR hosting;
  • CUI handling;
  • HIPAA compliance;
  • dedicated tenant infrastructure;
  • private cloud deployment;
  • customer-managed keys;
  • formal uptime SLA.

Customers with special security, regulatory, data residency, or procurement requirements should contact DrawingPhin before uploading restricted data.

12. Contact

For security questions, contact:

drawingphin@drawingphin.com