SuperNX / Security
Security & data handling
Your .prt files are your IP. This page states exactly what happens to an uploaded part — where it goes, who touches it, and when it is deleted. If a claim here ever drifts from what the service does, that is a bug: tell us and we fix one side or the other.
The short version
- Parts upload over TLS 1.3 to encrypted object storage; analysis runs server-side; the source .prt is deleted automatically ≤24 h after the analysis completes.
- The outputs — report and toleranced model — are yours. They persist until you delete them.
- Model-derived data (extracted feature data and rendered views) goes to Anthropic for AI inference under commercial API terms: not used to train models. Nothing goes to any other third party.
- No ads, no trackers on your data, no sale of uploaded content, no training on customer parts — ours or anyone else's.
- On-prem deployment (pilot) runs the whole pipeline inside your infrastructure — nothing leaves your site.
What happens to your file
- Upload. The browser sends a single .prt file (≤200 MB) over HTTPS to object storage on Cloudflare.
- Analysis. The service reads the model, extracts geometry and features, resolves declared fits through the published ISO 286 zones, and runs worst-case and statistical stack-up analysis.
- AI inference. Model-derived data — extracted feature parameters and rendered views of the part — is sent to Anthropic (Claude) to classify joints and infer assembly intent. See sub-processors below.
- Output. A traceable report and a toleranced NX model are written to your workspace.
- Deletion. The uploaded source file is deleted automatically — by default within 24 hours of the analysis completing. Your report and toleranced model remain until you delete them.
Data retention
| Data | Retention | Why it exists |
|---|---|---|
| Uploaded .prt source file | Deleted ≤24 h after analysis | Only needed while the analysis runs |
| Analysis report + toleranced model | Until you delete them | Your deliverable — the reason the tool exists |
| Account (email, display name) | Until you delete the account | Sign-in, via Firebase Auth |
| Operational logs | ≤30 days | Reliability and abuse prevention — metadata only (IDs, sizes, timings, status codes), never model content |
| AI inference payloads | Per Anthropic API terms | Not used for model training; transient abuse-monitoring retention may apply under Anthropic’s policies |
Sub-processors
| Provider | Role | What it can see |
|---|---|---|
| Cloudflare | Hosting, CDN, object storage, edge compute | Uploaded files at rest; request metadata |
| Google Firebase | Authentication | Email, display name, auth tokens |
| Anthropic (Claude API) | AI inference — joint/feature classification | Model-derived data: extracted feature parameters and rendered part views. Commercial API terms: inputs are not used for training |
There is no fourth column hiding anywhere — those three are the whole list.
What we deliberately never do
- No training on customer parts. Your uploads are not used to train any model — not ours, not Anthropic’s (their API terms).
- No human review by default. Engineers look at uploaded content only when you explicitly ask for help on a specific analysis.
- No sale or sharing of uploaded files, analysis content, or derived data.
- No advertising or third-party trackers on uploaded data.
Deployment options
- Cloud (default): everything on this page applies.
- On-prem: available for pilot engagements on the Team tier — the pipeline runs inside your infrastructure and nothing, including AI inference payloads, leaves your site. Talk to us.
Honest baseline
SuperNX is not SOC 2 or ISO 27001 certified today. We would rather show you the controls that actually exist — encrypted transport and storage, automatic deletion, a named sub-processor list, least-privilege internal access — than wave a certification we have not earned. Questions and due-diligence checklists: security@nxtolerance.com.
Report a vulnerability
Email security@nxtolerance.com; include reproduction steps and we acknowledge within 72 hours. Machine-readable contact: /.well-known/security.txt (RFC 9116).