SuperNX—Security

SuperNX / Security

Security & data handling

Your .prt files are your IP. This page states exactly what happens to an uploaded part — where it goes, who touches it, and when it is deleted. If a claim here ever drifts from what the service does, that is a bug: tell us and we fix one side or the other.

The short version

What happens to your file

  1. Upload. The browser sends a single .prt file (≤200 MB) over HTTPS to object storage on Cloudflare.
  2. Analysis. The service reads the model, extracts geometry and features, resolves declared fits through the published ISO 286 zones, and runs worst-case and statistical stack-up analysis.
  3. AI inference. Model-derived data — extracted feature parameters and rendered views of the part — is sent to Anthropic (Claude) to classify joints and infer assembly intent. See sub-processors below.
  4. Output. A traceable report and a toleranced NX model are written to your workspace.
  5. Deletion. The uploaded source file is deleted automatically — by default within 24 hours of the analysis completing. Your report and toleranced model remain until you delete them.

Data retention

DataRetentionWhy it exists
Uploaded .prt source fileDeleted ≤24 h after analysisOnly needed while the analysis runs
Analysis report + toleranced modelUntil you delete themYour deliverable — the reason the tool exists
Account (email, display name)Until you delete the accountSign-in, via Firebase Auth
Operational logs≤30 daysReliability and abuse prevention — metadata only (IDs, sizes, timings, status codes), never model content
AI inference payloadsPer Anthropic API termsNot used for model training; transient abuse-monitoring retention may apply under Anthropic’s policies

Sub-processors

ProviderRoleWhat it can see
CloudflareHosting, CDN, object storage, edge computeUploaded files at rest; request metadata
Google FirebaseAuthenticationEmail, display name, auth tokens
Anthropic (Claude API)AI inference — joint/feature classificationModel-derived data: extracted feature parameters and rendered part views. Commercial API terms: inputs are not used for training

There is no fourth column hiding anywhere — those three are the whole list.

What we deliberately never do

Deployment options

Honest baseline

SuperNX is not SOC 2 or ISO 27001 certified today. We would rather show you the controls that actually exist — encrypted transport and storage, automatic deletion, a named sub-processor list, least-privilege internal access — than wave a certification we have not earned. Questions and due-diligence checklists: security@nxtolerance.com.

Report a vulnerability

Email security@nxtolerance.com; include reproduction steps and we acknowledge within 72 hours. Machine-readable contact: /.well-known/security.txt (RFC 9116).