How we protect your data, API keys, and uploaded files — and how to report a vulnerability.
File type is validated by magic bytes (not file extension) before processing. Files that do not match a supported CAD format are rejected immediately and never written to persistent storage.
We take security vulnerabilities seriously and appreciate the security community's efforts to responsibly disclose findings.
If you discover a security vulnerability in CADLens, please report it to us at [email protected] with a clear description of the vulnerability, steps to reproduce it, and your assessment of its impact. Please do not disclose the issue publicly until we have had a reasonable opportunity to address it.
api.cadlens.co), dashboard, and public websiteWe do not currently offer a bug bounty programme, but we will publicly credit researchers who responsibly disclose valid vulnerabilities (with their permission).
For security disclosures: [email protected]
For general enquiries: [email protected]