How we handle your CAD and data
In short
- We sign a mutual NDA before you send a single file.
- Only the engineers named on your project open your files. They work on encrypted machines that we own and operate in Türkiye.
- No cloud AI service processes your geometry, results or report, and nothing of yours is used to train any model.
- Project files are deleted 90 days after delivery, and we confirm the deletion in writing.
- We are not ITAR-registered and do not accept export-controlled defence data.
Who has access
Each project is assigned to named engineers. Every person with access has signed an individual confidentiality undertaking. No subcontractor and no software vendor sees your files. Access is recorded per project, and the record is available to you on request.
Where your files live
Project files are stored on machines we own and operate, with full-disk encryption (FileVault on macOS, BitLocker on Windows). No consumer cloud sync service (iCloud, Dropbox, Google Drive or similar) touches project folders. Simulations run on our own solver; nothing is sent to a cloud solver.
How files arrive and leave
After the NDA we send you a project link to our portal, served over TLS, where you upload CAD and later download the report. Files are never exchanged as email attachments or through messaging apps. Transfers between our own machines run over an encrypted private network.
Automation and AI
Meshing, solving and report assembly are automated with our own scripts, running on our own machines. Interpretation, findings and recommendations are written by our engineers. No cloud AI service receives your geometry, results or report, and nothing of yours is used to train any model, ours or anyone else's. If we ever change this, we will tell you first and it will happen only with your written agreement.
Retention and deletion
| What | How long |
|---|---|
| Pre-sales files without an order | 30 days after the decision or the last activity |
| Project inputs and intermediate files (CAD, mesh, study archives, logs, images) | 90 days after final delivery; 30 or 180 days on request |
| The delivered report and its assumption register | 5 years, as our engineering record for your protection and ours |
| Backups | expire 30 days after the source is deleted |
When a project is deleted we send you a written confirmation listing what was removed, when, and when the last backup copy expires.
Backups
Backups are encrypted, kept on media we control, and restore-tested. A deleted project is never backed up again; its last backup copy expires within 30 days.
What we are not
We are not certified to ISO 27001, SOC 2 or TISAX. Those programmes assume dedicated compliance staff, which a practice of our size does not have. We are not ITAR-registered. What we offer instead is the list on this page, and we answer security questionnaires line by line with "implemented", "partial" or "not implemented", never with a badge.
Export-controlled and defence data
We do not accept ITAR-controlled technical data, US Controlled Unclassified Information, or classified defence data of any country. Our intake form asks you to confirm the export status of your files. Where the status cannot be confirmed, we do not start.
Inquiry and personal data
To answer an inquiry we process the contact details and project context you give us. Inquiry contacts are kept for 90 days after the last exchange unless a project follows. If you request the sample report, we keep the email address you enter to send the link and at most one follow-up message, and delete it 90 days after the last activity. Project contacts are kept for the duration of the relationship and the statutory record-keeping period. For customers in the EU and the UK we sign the Standard Contractual Clauses or the UK Addendum on request; our data processing addendum is part of the contract pack. You may ask what we hold about you, and ask for correction or deletion, subject to legal and contractual record-keeping duties.
Simmetric Engineering Solutions is an independent engineering practice based in Türkiye. The registered identity and contact address of the data controller are listed in the service terms.
Incidents
If we discover an incident affecting your files, we tell you within 24 hours of discovery, say what was affected, and say what we did.
Questions
Write to us through the contact form or to the security contact given in your project agreement. We answer data questions before, during and after a project.