CAD review, clearly
Security
Caddis serves everything over HTTPS. CAD files live in a private bucket that is never publicly listable; downloads use short-lived signed URLs issued only after we check that you own the file. Share tokens are stored only as hashes, and billing webhooks are signature-verified before we act on them.
Access is authorized per user by the Caddis API — the client cannot grant itself entitlement or reach another account's data. Share links are read-only, cannot download the source file, and can be revoked instantly by their owner.
Report a vulnerability to security@caddis.app. Please include steps to reproduce and do not access data that is not yours.
Our local-first promise
Cloud sync, source uploads, and share links are opt-in, per project. A local session is never turned into a cloud project unless you choose to save it.