# CAD and data security

> How Mesh2Metal protects designs and request data with local browser analysis, TLS, encrypted storage, controlled access, and responsible disclosure.

Canonical: https://mesh2metal.com/security

__Specifications__
| CAD analysis | Local Runs in your browser; the source file stays on your device.        |
| ------------ | ------------------------------------------------------------------------ |
| Transport    | TLS Connections use encryption in transit.                               |
| Storage      | Encrypted at rest Cloud-provider storage protects retained request data. |

Mesh2Metal protects design data in three ways: CAD analysis stays in your browser and the source file never leaves your device; only summary numbers such as dimensions and volumes, a file hash, and the answers you type reach our systems. Connections use TLS, and stored data is encrypted at rest through our cloud providers.

## What remains on your device?

CAD analysis runs locally in your browser. Mesh2Metal can check STL, STEP/STP, 3MF, and OBJ files without receiving their source geometry. The browser keeps the CAD file on your device while the in-browser check calculates the values needed for a request. Those values can include dimensions and volumes. A file hash can identify a file reference without exposing the model itself.

Keeping the source file local means it does not become a copy in our cloud storage merely because you check it. Keep the original in your own controlled environment, and share only the request information you are ready for our team to review.

## What information reaches Mesh2Metal?

The request path is limited to information needed to understand your part and respond:

| Data category         | Sent to Mesh2Metal? | Purpose                                                                   |
| --------------------- | ------------------- | ------------------------------------------------------------------------- |
| CAD geometry          | No                  | The source file remains in your browser and on your device.               |
| Summary numbers       | Yes                 | Dimensions and volumes describe the request.                              |
| File hash             | Yes                 | A reference value distinguishes one file from another.                    |
| Answers you type      | Yes                 | Typed details give the team request context.                              |
| Bot-protection result | Limited             | A page check helps reduce automated abuse without receiving CAD geometry. |

Bot protection is separate from CAD analysis. It helps keep request forms available for genuine visitors and limits scripted misuse. The protection check does not require the source file.

## How is data protected?

Data sent to Mesh2Metal uses TLS in transit. Data retained by our cloud providers is encrypted at rest. The cloud layer is used for the limited request information described above, not for the source CAD file. Encryption protects data while it moves and while it is stored; access controls add another boundary around request records.

## Who can view request information?

Access is limited to the team handling your request. Team members see the summary numbers and answers needed to understand your requirements, plus the file hash used as a reference. NDAs are available on request. Contact us through the [contact form](https://mesh2metal.com/contact) before sharing project details that require contractual confidentiality.

## What about export-controlled technical data?

Please don’t send us export-controlled (ITAR/EAR) technical data until we have set up a compliant path with you — contact us first through the [contact form](https://mesh2metal.com/contact). Keep the source CAD file on your device until that conversation is complete.

## How do I report a security issue?

Responsible disclosure via the [contact form](https://mesh2metal.com/contact) helps Mesh2Metal investigate problems without exposing customer information. Report a suspected vulnerability, unintended data exposure, or privacy concern. Include clear reproduction steps when possible, but do not attach source CAD files, credentials, or other sensitive material. A useful report identifies the affected page and observed behavior.

## Questions

Where is my CAD file analyzed?

CAD analysis runs locally in your browser, and the source file stays on your device. Mesh2Metal receives only summary numbers, a file hash, and the answers you type.

Can a file hash reveal my part geometry?

No. A file hash contains no geometry; it only lets us recognize the same file again if you analyze it twice.

Can I request an NDA?

Yes. NDAs are available on request. Contact Mesh2Metal before sharing project details.

How should I handle ITAR or EAR data?

Please do not send export-controlled technical data until we have set up a compliant path with you. Contact us first.

Sources (2)

1. \[1\] [ CCPA ](https://oag.ca.gov/privacy/ccpa) , California Department of Justice
2. \[2\] [ STL format ](https://en.wikipedia.org/wiki/STL%5F%28file%5Fformat%29) , Wikipedia

## Check your part now.

Analyzed in your browser — your file never leaves your device.

[ Set up API ](https://mesh2metal.com/api#setup) [ Set up MCP ](https://mesh2metal.com/mcp#setup)

[ Drop your CAD STL · STEP · 3MF · OBJ ](https://mesh2metal.com/quote)
