Security
3DScribe turns engineering data into interactive 3D and AI experiences for the people who need them: support teams, technicians, distributors, and customers. Most of those people should never receive your source CAD, and with our platform, they never do.
We give you layered control over exactly what leaves your organization, from full geometric simplification at publish time, to server-side delivery where no geometry reaches the viewer at all. You decide what each audience can see, ask, manipulate, and know. The platform enforces it.
Publish controls
Control what you publish.
Security starts before anything is delivered. 3DScribe Studio includes publish-time tools that let you strip sensitive content out of a scene entirely, so the published experience contains only what you intentionally approve.
Every scene you publish is a deliberate disclosure decision, made once, enforced everywhere that scene is delivered.
Selective publication
Delete bodies, parts, and entire assemblies from the published scene. Internal mechanisms, supplier components, and pre-release designs can be excluded from a scene while remaining intact in your source files. What you remove is not hidden in the delivered scene. It is absent from it.
Geometric merging and simplification
Fuse multiple parts into single bodies, decimate meshes to reduce fidelity, and flatten assembly structure. A merged, simplified body no longer carries your part boundaries, build logic, or design intent. The result is a scene that looks right and works for its audience, without functioning as a reusable engineering asset.
Derived, not converted
Published scenes are derived visualization assets. Your source CAD, B-rep geometry, feature history, tolerances, PMI, and manufacturing metadata are never part of a published scene in any form.
Server-side rendering
Control how it is viewed.
For your most sensitive scenes, we offer server-side rendering as a secure viewing option. The 3D scene lives and renders entirely on our infrastructure. The viewer receives a rendered image stream, never geometry.
There is nothing to extract from the client, because nothing three-dimensional is ever sent to it. No meshes, no derived geometry, no scene files. A viewer session contains pixels and interaction events, full stop.
This is the right choice when the audience is untrusted, the geometry is sensitive even in simplified form, or your security policy requires that model data never reside on an endpoint you do not control.
Coming soon
We are building a third delivery mode for teams that want client-side performance and reach without shipping geometry: a splat-based rendering pipeline with a dedicated secure viewer.
Instead of meshes, the client receives a derived volumetric representation generated from your approved scene. It is not CAD, it contains no B-rep, part hierarchy, tolerances, or manufacturing data, and it is designed to be useful only inside our viewer. The disclosure ceiling is explicit and set at publish time, not discovered after the fact.
This mode targets the cases where server-side rendering is not practical: large audiences, low-latency interaction, constrained networks, and immersive devices.
MCP
AI without exposure.
3DScribe scenes can be connected to AI agents through the Model Context Protocol. This is one of the most common questions we get from security teams, so here is exactly how it works.
The agent never receives CAD
No geometry of any kind, in any format, is ever sent to an AI model or agent. Not source CAD, not meshes, not derived geometry.
Agents work with derived data only
Part names and identities, assembly structure, metadata, authored descriptions, technical context, and approved media. All of it scoped by the same publication controls.
Visuals rendered server-side
When an agent needs to see something, we render a single image of the approved scene on our infrastructure and return it. The agent receives a picture, and nothing more.
Your rules apply to machines too
A part excluded from a published scene does not exist for the agent. A description you did not approve cannot be retrieved.
Platform
Platform security.
For security questionnaires, architecture reviews, or penetration test summaries, contact security@superobservation.com.
Encryption everywhere
Customer data is encrypted at rest and in transit across the platform.
SOC 2 in process
Our SOC 2 audit is in process as of August 2026, with completion estimated in late 2026. We are happy to share our current security documentation and progress under NDA.
Access control and tenancy
Customer data is logically isolated per tenant. Access to production systems is restricted, logged, and reviewed.
You own your data
Your CAD and derived assets remain yours. We do not train models on your proprietary data, and we delete customer data on termination in accordance with our data processing terms.
Coming soon
Some organizations cannot send CAD anywhere. Defense-adjacent programs, critical infrastructure suppliers, and manufacturers with strict customer security obligations sometimes need a simple answer to a hard requirement: the data never leaves the building.
For them, we are bringing the entire 3DScribe platform on premises. A single, dedicated AI appliance, deployed inside your facility, running the full pipeline locally: ingestion, semantic labeling, rendering, and the complete AI experience. No cloud dependency. No external network traffic. Optionally, no network at all.
Your most sensitive assemblies get the same conversational 3D experience as everything else, on hardware you can physically point to. Coming soon. If this is your requirement, we want to talk to you now: security@superobservation.com
This page describes platform capabilities at a summary level. For detailed architecture documentation, current compliance status, or a security review session with our engineering team, contact security@superobservation.com.