Policy details
Local-first viewing
When you open a DWG or DXF in the viewer without clicking Share, parsing happens in your browser using WebAssembly CAD engines. Your drawing bytes do not leave your device during local review.
Share link security
- Share URLs use unguessable UUID identifiers.
- Files are served over HTTPS only.
- Links expire after 90 days by default.
- Recipients get view-only access no edit or re-download of source DWG on Free tier.
Account security
Passwords are hashed with scrypt before storage. Sessions use HTTP-only cookies. Email verification is required for registration to reduce fake accounts.
Infrastructure
Production deployments use TLS 1.2+, regular dependency updates, and restricted access to upload storage. We monitor for abuse and rate-limit authentication endpoints.
Report a vulnerability
Contact security@cadpeek.com with responsible disclosure details. We aim to respond within 72 hours.