Security & Enterprise

Enterprise control over your engineering data

Turn technical drawings into usable 3D data, with enterprise options for hosting, AI providers, access and data handling.

Voluminate Enterprise supports organizations with specific requirements around how their engineering data is processed. Discuss the deployment configuration, contractual terms and supporting documentation your organization needs.

Your Enterprise configuration

Data Sovereignty & Hosting

  • EU-only or dedicated hosting region
  • Private cloud / single-tenant deployment
  • On-prem / air-gapped deployment available

AI & Subprocessor Control

  • AI learning opt-out
  • Subprocessor exclusion list — choose which AI providers may process your data
  • Zero Data Retention agreements with all routing partners
  • Anonymization layer before data leaves your environment

Data Lifecycle

  • Instant, on-demand data deletion
  • Configurable retention windows

Compliance & Legal

  • ISO 27001 / SOC 2 available on request
  • TISAX (automotive) available on request
  • Signed DPA with named DPO
  • Custom NDA / MSA terms

Access & Audit

  • SSO/SAML, RBAC, audit logs
  • IP allowlisting
  • Bring-your-own-key encryption

Support

  • Custom SLA
  • Dedicated account manager

Enterprise features are scoped per engagement — book a call to discuss your specific requirements.

Understand how your data is processed

Review how Voluminate handles uploaded drawings, generated models, AI processing and human engineering review. Our privacy notice and subprocessor disclosures explain processing categories, locations, retention and data transfers. For organization-specific requirements, discuss the relevant configuration and documentation with our team.

For demanding industrial environments

Manufacturing, aerospace and defence organizations can have specific requirements for engineering-data processing and procurement.

Working with sector-specific security or technical-data requirements? Contact us to review your required hosting, processing providers, access policies and deployment configuration.

Security, compliance & procurement requirements

Have specific security or procurement requirements? Discuss your requirements with us—including the frameworks, regulations and classifications below—to define the appropriate deployment, data-handling configuration and supporting documentation.

Requirements for discussion; applicability and supporting evidence are assessed per engagement. This list does not represent certifications or approvals held by Voluminate.

Enterprise security & EU / NATO

  • ISO/IEC 27001:2022 (ISO 27001), ISO 27017, ISO 27018
  • SOC 2 Type II, ISO/IEC 42001
  • NIS2 (Directive 2022/2555), Article 21 supply-chain security
  • Cyber Resilience Act, EU AI Act
  • EU Common Military List, EU Dual-Use Regulation 2021/821
  • EDF / EDIP eligibility
  • NATO RESTRICTED, C-M(2002)49, NCIA / NSPA requirements
  • AQAP-2110, AQAP-2210, EN/AS 9100

Germany

  • BSI C5 Type 1 / Type 2
  • VS-NfD, VS-NfD-Merkblatt, Verschlusssachenanweisung, Geheimschutzhandbuch
  • Geheimschutzbetreuung (BMWE), Sicherheitsbescheid, VS-Vertraulich
  • AWG / AWV, Ausfuhrliste Teil I A, BAFA
  • ISO 27001 auf Basis IT-Grundschutz / IT-Grundschutz
  • NIS2UmsuCG, DSGVO / BDSG, AVV, subprocessor lists
  • Souveränität / sovereign cloud, CLOUD Act exposure requirements
  • TISAX

United Kingdom

  • Cyber Essentials / Cyber Essentials Plus
  • Defence Cyber Certification (DCC), DCC Level 0
  • DEFCON 658, Def Stan 05-138 Issue 4, Cyber Security Model (CSMv4)
  • Cyber Risk Profile (CRP) Levels 0–3
  • OFFICIAL / OFFICIAL-SENSITIVE, DEFCON 660, NCSC Cloud Security Principles
  • SECRET / List X requirements
  • UK Strategic Export Control Lists, Export Control Order 2008, OGELs
  • MOD Secure by Design, JOSCAR
  • Procurement Act 2023, National Security Act 2023
  • UK GDPR / DPA 2018, AUKUS ITAR exemption

United States

  • ITAR (22 CFR 120–130), USML technical data
  • EAR (15 CFR 730–774), 600-series / 9x515 ECCNs
  • CUI, DFARS 252.204-7012, NIST SP 800-171 Rev 2
  • CMMC 2.0, DFARS 252.204-7021
  • FedRAMP Moderate / equivalency, DoD Cloud SRG IL2 / IL4 / IL5
  • SPRS score, FIPS 140-3
  • Section 889 NDAA, FASCSA orders, 1260H list
  • NIST SSDF (SP 800-218), CISA secure software attestation
  • FOCI / DCSA facility clearance

France

  • SecNumCloud (ANSSI), II 901 / Diffusion Restreinte

Enterprise roadmap · controlled-data architecture

Full Control

Alongside our existing Enterprise offering, we are developing a dedicated architecture for controlled technical data. Full Control is an enterprise roadmap capability, with customer-specific review of the complete processing path.

  • Jurisdiction-pinned hosting across the controlled-data processing path
  • Provider allowlists restricted to self-hosted or customer-approved routes
  • Named, approved engineering reviewers with nationality and access checks
  • Customer-specific data flows and retention policies
Discuss your Enterprise configuration