Trust Center
Estimasys treats quoting as a technical product, not as a channel for capturing commercial information. This page documents exactly what we do with your CAD files, who we share them with, how we isolate the operation, and what contractual commitments support this. If you are responsible for compliance, due diligence or vendor evaluation, this page was written for you.
How we handle your CAD files
Encryption
- TLS 1.3 in transit between your browser and our infrastructure.
- AES-256 at rest, including meshes and intermediate representations derived from the original file.
Isolated processing
Geometric analysis services run in a segregated environment, with access restricted to the components that execute the quoting process. All access is logged in an auditable way.
Never used to train AI
Your CAD files, your quotes and any derivative of them are not used to train AI models, ours or third parties'.
Retention
| Category | Period |
|---|---|
| Anonymous sessions (files + results) | up to 24h after analysis |
| Registered accounts | until manual deletion, or 12 months after last access |
| Technical logs (without file content) | up to 180 days |
| Billing data | 5 years (tax legislation) |
User anonymization
You control what goes into the upload. If the file carries sensitive commercial context (customer name in metadata, descriptive file name, custom properties), anonymizing before submission is the most direct way to reinforce confidentiality. See section 6. How to anonymize files before upload.
Company structure
Who operates Estimasys
Estimasys Ltda. — CNPJ 58.446.002/0001-99 · São Paulo/SP and Porto Alegre/RS (Tecnopuc).
Contractual commitments
Estimasys's Terms of Use establish that:
- Customer data is not sold. We do not sell, rent or transfer files, quotes or contacts to any party.
- End customers are not contacted using platform data. We do not use information obtained on Estimasys (geometry, history, usage pattern) to commercially approach the end customers of our users.
Any internal violation of these rules is treated as a critical security event, with public disclosure and proportional accountability.
What we do NOT do with your data
- We DO NOT train AI models with your CAD files or your quotes.
- We DO NOT share files without your explicit consent.
- We DO NOT sell, rent or transfer data to advertisers or commercial third parties.
- We DO NOT use cross-site tracking cookies.
- We DO NOT contact your end customers based on data obtained from the platform.
- We DO NOT maintain a backdoor for administrative access to customer files without an auditable trail.
Who we share data with
The list is short and is here in full:
- Cloud infrastructure providers, under contractual confidentiality clauses.
- Payment processors, exclusively for billing purposes.
- Public authorities, under a valid court order.
Nothing beyond that. Under no circumstances are files or quotes shared with manufacturers, marketplaces or third-party tools without explicit action from the user.
How to anonymize files before upload
If confidentiality in your case requires reinforcement, these practices are simple and work for any flow:
Rename the file
Instead of customer-X-chassis.step, use part-001.step.
Starting with a neutral name eliminates the trace before upload even happens.
Clean CAD metadata
Most systems (SolidWorks, Fusion 360, NX, CATIA) let you clear author, comments and custom properties before exporting to STEP. In SolidWorks: File → Properties → Custom, remove sensitive fields before Save As → STEP.
Anonymize 2D drawings
Before uploading a PDF or DWG, hide the title block, drawing number and customer name. Geometry remains interpretable for the analysis; commercial identifiers do not.
Audit
Access logs
Every registered account can request the complete log of access to their data, including:
- When each file was accessed.
- Which internal service performed the access.
- Which operations were performed (analysis, conversion, report generation).
Logs are immutable (append-only) and cover the trailing 180-day period.
How to request
Send an email to contact@estimasys.com with subject
Audit log request — [your registered email].
We respond within 5 business days with the complete report.
DPO
Data Protection Officer (DPO): contact@estimasys.com.
Related documents
- Privacy Policy — version 2.1 (May 5, 2026)
- Terms of Use — version 2.1 (May 5, 2026)
- Compliance: LGPD (Law 13,709/2018)
Update history
| Version | Date | Change |
|---|---|---|
| 1.0 | Jun 9, 2026 | Initial publication of the Trust Center. |
This page is factual by design. If something here is unclear or you identify
an inconsistency between what we describe and what you actually observed using the platform,
write to contact@estimasys.com with subject
Trust Center feedback. We respond.