Security
Security & enterprise readiness
Which data CadPilot processes, what an AI model can see and how you control it – in brief. The details are in the guide for the IT review and in the threat model.
Data and connections
| Question | Answer |
|---|---|
| Where does CadPilot run? | Locally on the CATIA workstation, as its own process with the user’s rights. |
| Does CadPilot open network connections? | No. CadPilot talks to the AI client via stdio (locally) and to CATIA via COM; there is no open port and no HTTP transport. |
| What does the AI model see? | What the AI client passes on: your request and the tool results – feature, parameter and document names, values and measurements, part numbers, properties, bills of materials and file paths. No CAD files and no geometry. The client connects to the provider you choose. |
| How do I limit that? | Switch on the data filter (part numbers and names as pseudonyms), restrict tool groups; screenshots as images are off by default – or use a local model. |
| What is logged? | In safe mode no paths or values in the log. Optionally a session report with a hash chain that shows what went out. |
Controls
Safe mode
Save and export only into the working folder, in-place save blocked, never overwrite; paths checked before every CATIA call.
Data filter (optional)
Replaces part numbers and names by pseudonyms; the mapping stays in memory. Pattern-based – unknown patterns are a known limit.
Session report
JSONL with a SHA-256 chain and a Markdown summary without model data.
Central configuration
20 switches via environment variable or configuration file; invalid values stop the server.
No script interface
No tool runs macros or arbitrary CATIA commands; modifying tools are marked for the client.
Supply chain
Few dependencies, vulnerability scan before every version, SBOM (CycloneDX) and SHA-256 checksums.
Deployment options
Local model
Model on your own hardware – no data leaves the company. For strictly confidential projects.
EU tenant
AI service with data processing in the EU under your contracts.
Cloud service
With data filter and session report; clarify with IT, data protection and, if applicable, the customer first.
Documents for IT
Guide for the IT review
Data flows, installation without administrator rights, switches, recommendations.
Operation and help
Update, roll back, report problems, remove.
IT package (PDF) and SBOM
Threat model, switches and software bill of materials of every version – on request or with the delivery.
There is no external security audit and no certification. The code reviews were reviews by a second AI model; an independent audit would be listed separately.