How Sibe Protects Your CAD Data: Security, US Data Residency, and ITAR Readiness
When engineering teams move CAD data to the cloud, features are only part of the decision. You also need clear answers to the questions your security review will ask:
- Where are our engineering files stored?
- How is the data encrypted?
- Who can access it?
- What happens during an outage?
- Can we use the platform for ITAR-controlled technical data?
Here is the current picture.
Sibe's standard commercial environment is hosted in the United States on Google Cloud. Customer data is encrypted at rest and in transit, access is controlled through workspace permissions and user roles, and the platform is backed by automatic backups, disaster recovery protocols, and continuous security monitoring.
Sibe's standard environment is not currently a dedicated ITAR-compliant or fully geo-fenced environment. We are working toward an enhanced deployment option for customers with stricter US data residency and ITAR-oriented requirements. You can also review our current controls on the Sibe Data Security page.
Where is Sibe customer data hosted?
Sibe's standard commercial environment runs in the Google Cloud us-central1 region, in Council Bluffs, Iowa. Customer engineering data stays within that United States cloud boundary, including:
- Customer files
- File metadata
- Logs
- Backups
- File previews and conversions
- Temporary file processing
Sibe may use third-party business tools for customer communication and operational support. Some of these tools may be operated by non-US vendors, but they are not used to store or process customer engineering files.
Google Cloud provides the underlying infrastructure: physical data center security, storage, networking, encryption capabilities, and platform-level controls. Sibe manages the application layer: authentication, workspace permissions, file-level workflows, sharing controls, and operational access procedures.
Security controls built around engineering workflows
Security is not only about where a file is stored. It is also about controlling how people access, change, review, release, and share that file.
Sibe uses role-based access control, so Workspace Owners decide who reaches engineering data and what each person can do. These controls include:
- Workspace and folder-level permissions
- Separate user roles for different levels of access
- Public and private folders
- Version history
- Check-in and check-out controls
- Review and release workflows
- Controlled file-sharing options
Keeping this activity inside one managed CAD document management workspace reduces uncontrolled file duplication, overwritten versions, unmanaged local copies, and engineering files leaking through disconnected tools.
How is data encrypted?
Customer data stored in Sibe is protected using Google Cloud server-side encryption with Google-managed encryption keys. Google Cloud encrypts stored content using AES-256 at the storage layer. You can read more in Google's documentation on default encryption at rest.
Data moving between users, Sibe, and the underlying cloud services is protected using Transport Layer Security. Sibe supports TLS 1.2 and TLS 1.3; the older TLS 1.0 and TLS 1.1 standards are disabled. Google provides more detail in its documentation on encryption in transit.
Public SSL configuration reports are available for sibe.io and app.sibe.io.
Backups, monitoring, and disaster recovery
Sibe maintains continuous system monitoring, automatic backups every 24 hours, and disaster recovery protocols designed to minimize downtime and data loss after a service disruption.
For engineering teams, this removes much of the operational burden that comes with maintaining:
- Local CAD vault servers
- Manual backup jobs
- VPN access
- Server updates
- Local disaster recovery procedures
The goal is a reliable place to manage engineering data without running your own file server infrastructure.
How does Sibe control employee access?
Access to Sibe's production systems is restricted to personnel with an essential business need, and that access is monitored and audited.
Development and testing run in isolated staging environments, separate from production. Customer production data is not used in Sibe's development and testing workflows.
Sibe maintains an incident response plan and runs employee security training and awareness programs to reinforce the secure handling of customer information and internal systems.
Continuous security monitoring through Drata
Sibe uses Drata's security automation platform to continuously monitor internal security controls. Drata supports automated alerts and evidence collection, which helps our team keep visibility into security controls throughout the year rather than treating security as a one-time review.
Customers and prospects can review our real-time Drata security report for added visibility into Sibe's security program and monitored controls.
Is Sibe ITAR compliant today?
Sibe's standard commercial environment should not currently be represented as a dedicated ITAR-compliant environment. Although it is hosted in the United States, US hosting alone does not automatically satisfy every requirement associated with ITAR-controlled technical data.
An ITAR-oriented deployment may require additional controls covering areas such as:
- Data location
- Support personnel access
- Personnel nationality and location
- System configuration
- Permitted cloud services and endpoints
- Monitoring for configuration changes
Customers handling ITAR-controlled or other export-controlled technical data should not upload that material into Sibe's standard commercial environment unless the use case has been reviewed and approved by their own legal, security, or compliance teams.
Our roadmap for enhanced ITAR-oriented controls
Sibe is working toward an enhanced data residency option using Google Cloud Assured Workloads. Assured Workloads lets organizations apply predefined packages of technical controls to regulated cloud environments. Google publishes a list of its available Assured Workloads control packages.
The dedicated Google Cloud ITAR control package is designed to support controls including:
- US-only data location restrictions
- Technical support routed to US Persons located in the United States
- Restrictions on the Google Cloud products and API endpoints that can be used
- Monitoring for configuration violations
Once enabled for a customer environment, this enhanced option is intended to support teams with stricter requirements around US data residency, support personnel access, and ITAR-oriented cloud deployment controls.
It would be a separate deployment option, not a default feature of Sibe's standard commercial environment. Availability, scope, pricing, technical requirements, and implementation details must be reviewed with Sibe before regulated workloads are onboarded.
Security is a shared responsibility
Sibe provides the collaboration-first CAD document management application, workspace access model, file permissions, monitoring, backups, and operational safeguards. Google Cloud provides the underlying infrastructure and platform-level security controls.
Google also publishes information about its approach to customer data, government requests, insider access, advertising, and data protection on its Transparency and Data Protection page.
Customers remain responsible for determining whether a particular system, deployment model, configuration, and workflow satisfies their:
- Internal information security policies
- Customer and supplier contracts
- Export-control obligations
- Regulatory requirements
No cloud platform can make this determination on a customer's behalf.
Evaluating Sibe for a security-conscious engineering team?
Sibe can support your vendor security review with structured questionnaires, architecture discussions, data residency information, and deeper reviews of regulated deployment requirements.
For teams working with ITAR-controlled or export-controlled technical data, please book a conversation with our team before uploading controlled material. We can review your requirements and determine whether an appropriate deployment option is available.
For teams working with standard commercial engineering data, Sibe gives you a secure, US-hosted way to manage SolidWorks files, versions, reviews, releases, and collaboration without maintaining your own servers or VPN infrastructure.
You can review our current controls on the Sibe Data Security page, view our real-time security report, or book a demo.
This article is provided for informational purposes only. It is not legal advice, an export-control determination, a certification, or a customer-specific compliance attestation.
Book a free Demo with Ken to see Sibe in action


Ken Maren
Chief Solutions Architect
SolidWorks Expert with 30+ Years Experience
Redirecting...



.avif)
