We're at capacity. Please come back tomorrow.

Security and your data. Your parts are often someone's unreleased product. Here is exactly what happens to them.

Your workspace is yours

Every account has its own workspace. Every request is checked against it, so no other account can open your projects, files, chats or exports. A fork stays in the workspace it came from.

STEP files you attach stay exactly as you uploaded them. Extrastep designs around them but never changes their geometry, and a part you lock keeps its place.

Builds run in a sandbox

Your design is CadQuery source code. Each time it's built, it runs in a fresh, confined process that exists only for that job. The same applies when an attached STEP file is read.

  • The process never receives the service's credentials or keys.
  • It has limits on time, CPU, memory, file size and the number of processes it can start.
  • It has no network access.
  • It runs as its own unprivileged user, so one build cannot read another's files.
  • When the job ends, nothing it started keeps running.

The service checks each build's result against its request before storing it. Opening a project never runs its source code.

What the AI model receives

A turn sends the model what it needs to make and check your change:

  • your messages in that chat, and the geometry you reference in them
  • your design's source code and parameters
  • geometry, measurements and check results the agent asks for
  • images of your model, only when the agent captures a view to review

Nothing is sent between turns. Requests go to [Model provider] with response storage turned off. See the Privacy Policy for the providers that process your data.

Your source and exports

Apart from what the model receives during a turn, your design's source code leaves Extrastep only when you download it, on plans that include source download. Exports contain geometry and part names only.

Deleting your data

Deleting a project removes it from your workspace at once. Its history and every stored file that no other project of yours uses are then deleted. Forks keep their own history and design. To delete your account, email support@extrastep.ai.

Signing in

Accounts use Amazon Cognito: you sign in with Google, with Apple, or with your email address and a password, which goes to Cognito and never to our servers. A code sent to your email confirms the address. The page keeps no sign-in tokens: the service holds your session in HTTP-only cookies and checks every request's token: its signature, who issued it, who it's for, and when it expires. Signing out ends the session.

Where it runs

What Where
This website and the app's pages Amazon CloudFront and S3
Accounts, projects and stored files Amazon Web Services, [Region]
Building, checking and rendering designs [Compute provider]
The AI model [Model provider]

Reporting a security issue

Email support@extrastep.ai with what you found and how to reproduce it. Please give us time to fix it before you share it.