DOC GID-LGL-001PRIVACY POLICY — INTERIM POLICY v0.1REV 2ca48122026-07-10

Privacy policy

How Gauge.ID handles the geometry you send us. This is an interim policy — the full policy and a data processing agreement (DPA) are provided during pilot contracting.

STATUS — INTERIM

Gauge.ID’s formal privacy policy is being finalized for enterprise procurement and regulated-industry review (AS9100, ISO 13485, ITAR-aware deployments). The sections below state our operating posture during this period. Nothing on this sheet replaces the contracted policy and DPA.

01 — Data handling

CAD geometry submitted to Gauge.ID is processed for the sole purpose of generating a canonical identity. We do not sell, share, or use customer geometry to train external models.

Where deployment topology permits, identity computation can run on derived representations without retention of source files.

02 — Encryption & hosting

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Hosted evaluations run on cloud providers holding SOC 2 Type II attestations, with isolated tenant environments. GaugeID LLC has not yet completed its own SOC 2 audit; our controls and roadmap are available under NDA.

03 — Jurisdiction & residency

On-premise and private-cloud deployments are available for organizations with strict data residency, ITAR, or export-control requirements.

04 — Contact

For DPA requests, security questionnaires, or evaluation-period legal terms, contact legal@gaugeid.com.

POLICY v0.1 · LAST UPDATED 2026-05-03 · FULL POLICY AND DPA PROVIDED DURING PILOT CONTRACTING