Security and data ownership
Putting your CAD geometry in front of customers is the part of this decision that makes engineering nervous, and rightly so. Your models are the product. This page is the direct answer to what your IT and security teams will ask.
Your models cannot be downloaded
This is the question that matters most and it deserves an unambiguous answer: customers cannot download your 3D models.
Models are encrypted end to end. A customer sees the geometry only in the way and at the time you allow, rendered for viewing — there is no export path, no "save as", and no supported workaround. The geometry never leaves your control, which is what makes it safe to put a real assembly in front of a dealer network rather than a simplified stand-in.
You own your data
Your models and parts data remain yours. Specifically:
- Origeq does not resell your data.
- Origeq does not train models on your data.
- Your data is not pooled with, or exposed to, other customers.
There is no clause anywhere that converts your engineering library into someone else's asset. If your legal team wants that in writing for a procurement file, ask and we will put it in the contract rather than leaving it as a marketing claim.
Access control
Access is role-based, and the boundaries are the ones an OEM actually needs:
- Customers see only their own equipment. A customer is scoped to the machines you have granted them, not to your catalog.
- Dealers see only what they sell and maintain. Dealer and distributor accounts on the Enterprise plan are scoped by territory and relationship, so one dealer cannot see another's install base.
- You decide the sharing model. The same assembly can be an open link on a public support page, a QR code printed on the machine, or something only a logged-in account can reach.
Optional client logins let you tighten this over time without rebuilding anything you have already published.
Where the boundary sits
Being precise about this saves a round-trip in most RFPs:
- What is protected: the underlying 3D geometry, which cannot be extracted.
- What is deliberately visible: part numbers, part names and the structure of the assembly. That is the whole point of the product — a catalog that hides the parts list is not a catalog.
If your concern is that competitors could enumerate your parts list, the correct control is access scoping (put it behind a login) rather than an expectation that the catalog will conceal it.
Compliance status, stated plainly
Origeq is not SOC 2 or ISO 27001 certified today.
The platform is built API-first following SOC 2 and ISO 27001 practices, and formal certification is on our active roadmap rather than something we already hold. We would rather lose a deal on that than win one on an implication.
If certification is a hard gate for your procurement process, tell us early. We will give you the current status, what is in progress, and a realistic date, and you can decide from there. Ask us through the RFP process and it will be in writing.
Performance is a security question too
An access-controlled system that is painful to use gets worked around — people email files to each other instead. Models that take 30 to 60 minutes to open in a CAD application load in Origeq in seconds, which is what keeps the controlled path the path of least resistance.
White labelling
On the Enterprise plan the catalog runs on your own domain, with your branding and colours. Customers stay inside your brand rather than being handed off to a third-party tool, which is both a trust and a security posture question for most OEMs.
Questions we have not answered here
Hosting region, retention, sub-processors and incident response are all reasonable questions with answers that depend on your deployment. They belong in a real conversation rather than a marketing page — send them through the RFP process or email us and you will get specifics.