Security and source-file privacy

Your source model and published experience are not the same thing.

Cadloom keeps original product files inside the managed workspace and publishes only the optimized customer-facing version you approve.

01

Private source

STEP, STL, 3MF, GLB, and glTF uploads are used to prepare and manage the product. Source download links are not exposed through the public viewer.

02

Controlled publication

A customer-facing model becomes available only after an authorized user reviews and publishes it. Unpublishing removes public availability without deleting the working setup.

03

Approved websites

Platform publications can be restricted to configured websites. Embed policy is checked before the viewer is delivered.

04

Lifecycle controls

Revisions, publication status, downgrade grace, retention, and deletion are explicit operations rather than hidden side effects.

Operational safeguards

Designed for real product operations.

Cadloom uses separate development, QA, and production environments and keeps application services, model processing, storage, tasks, identity, and billing under environment-specific controls.

Encryption and transport

Hosted services use HTTPS and managed cloud storage. Sensitive credentials remain server-side and are not placed in public website code.

Role-aware access

Workspace roles limit account, billing, team, and editing capabilities while published viewers remain isolated from administration.

Retention and deletion

Account and product deletion workflows remove managed records and model assets according to the applicable retention policy.

Responsible analytics

Public analytics focus on aggregate viewer activity and do not claim customer-level revenue attribution.

Need a security review?

Start with the published-data boundary.

Tell us what your organization needs to understand about source files, websites, user roles, retention, or regional deployment.

Contact Cadloom ↗Read the Privacy Policy