Trust Security & privacy.
One page, two sections. Short, because the long version reads like every other security page.
If you have a question we don't answer here, email
[email protected].
01
What we do today
- ✓ HTTPS-only — TLS terminated at Cloudflare edge; internal hops via cert-manager wildcard.
- ✓ Encryption at rest — Customer-provided STEP files and converted glTF assets sit on encrypted S3-compatible storage.
- ✓ Per-token viewer URLs — Public viewer URLs use random 24-character tokens; not enumerable. Set assets to private to require auth (Pro).
- ✓ Security headers — X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin.
- ✓ Self-hosted infrastructure — Single-tenant k3s cluster on Pogodan-operated hardware; no shared multi-tenant SaaS plane between Quidities customers.