# Resin EDA Security and Data Review

Schema: `security-data-review-v1`

Template version: `2026-07-13`

Record status: `Blank template`

This is a buyer-side question set, not a statement of Resin controls. `Policy-stated` identifies controlling public policy language; `Publicly described` identifies product material that still requires direct evaluation. Obtain written, dated, attributable answers and inspect the required evidence before relying on any response. Blank fields, `Awaiting answer`, and `Pending review` do not imply acceptance, availability, or a negative answer.

Use the same evaluation ID and project alias in the technical evaluation, procurement review, and team handoff records so the files form one review dossier.

To request written owner answers, use [Resin's security and privacy contact route](https://previewresineda.up.railway.app/new/contact#security-privacy). Keep the applicable response, evidence, owner, date, disposition, and approval fields blank or `Pending` until attributable answers and the required evidence are received and reviewed.

## Policy source register

Register checked: 2026-07-13

The public Terms of Service and Privacy Policy were each updated 2026-07-01. Each reference below is the exact public route and clause anchor used by this worksheet. Re-check the controlling text and effective version before relying on it.

| Document | Policy date | Exact public route and anchor | Used for |
|---|---|---|---|
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-information-collected-account`](https://previewresineda.up.railway.app/privacy#privacy-information-collected-account) | Account and organization data inventory |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-information-collected-project-content`](https://previewresineda.up.railway.app/privacy#privacy-information-collected-project-content) | Project and workspace data inventory |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-usage-device-telemetry`](https://previewresineda.up.railway.app/privacy#privacy-usage-device-telemetry) | Usage, device, diagnostic, and security-event data |
| Terms of Service | 2026-07-01 | [`/terms#terms-accounts-access-credentials`](https://previewresineda.up.railway.app/terms#terms-accounts-access-credentials) | Credential responsibility and account activity |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-workspace-collaboration-visibility`](https://previewresineda.up.railway.app/privacy#privacy-workspace-collaboration-visibility) | Workspace visibility according to permissions |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-workspace-collaboration-admin`](https://previewresineda.up.railway.app/privacy#privacy-workspace-collaboration-admin) | Owner and administrator workspace controls |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-ai-features-processing`](https://previewresineda.up.railway.app/privacy#privacy-ai-features-processing) | AI-assisted feature processing |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-ai-features-submission`](https://previewresineda.up.railway.app/privacy#privacy-ai-features-submission) | AI submission limits and authorization warning |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-sharing-providers-categories`](https://previewresineda.up.railway.app/privacy#privacy-sharing-providers-categories) | Service-provider categories |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-international-use-locations`](https://previewresineda.up.railway.app/privacy#privacy-international-use-locations) | Processing locations |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-security-retention-duration`](https://previewresineda.up.railway.app/privacy#privacy-security-retention-duration) | Purpose-based retention statement |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-choices-requests`](https://previewresineda.up.railway.app/privacy#privacy-choices-requests) | Access, correction, deletion, and export requests |
| Terms of Service | 2026-07-01 | [`/terms#terms-design-data-ownership`](https://previewresineda.up.railway.app/terms#terms-design-data-ownership) | Design-data ownership |
| Terms of Service | 2026-07-01 | [`/terms#terms-design-data-operating-rights`](https://previewresineda.up.railway.app/terms#terms-design-data-operating-rights) | Limited rights to operate the service |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-choices-product`](https://previewresineda.up.railway.app/privacy#privacy-choices-product) | Plan- and role-dependent product choices and export |
| Privacy Policy | 2026-07-01 | [`/privacy#privacy-security-retention-safeguards`](https://previewresineda.up.railway.app/privacy#privacy-security-retention-safeguards) | General safeguards statement |

## Shared evaluation dossier

- Organization:
- Evaluation ID:
- Project alias:
- Evaluator:
- Security or privacy reviewer:
- Review date:
- Owner answer version or date:
- Build or release reviewed:
- Data classification:
- Evidence custodian:
- Decision owner:
- Supersedes record ID:

Do not enter confidential project names or restricted data in a file that will leave the approved review group.

## Intended evaluation data inventory

Record one row per materially different data class before reviewing controls. Keep a class out of the pilot while its allowed use, owner, or required protection remains unresolved. Use the continuation fields when more than six rows are required.

| ID | Data class and example | Source | Purpose | Recipients or processors | Sensitivity / regulatory constraints | Allowed and prohibited use | Internal owner | Disposition |
|---|---|---|---|---|---|---|---|---|
| DATA-01 | | | | | | | | Pending |
| DATA-02 | | | | | | | | Pending |
| DATA-03 | | | | | | | | Pending |
| DATA-04 | | | | | | | | Pending |
| DATA-05 | | | | | | | | Pending |
| DATA-06 | | | | | | | | Pending |

- Total intended data-class rows:
- Continuation record reference:
- Continuation revision or SHA-256:

| ID | Area | Evaluator question | Required evidence | Response progress | Written answer / source version | Evidence inspected / result | Owner | Date | Review disposition |
|---|---|---|---|---|---|---|---|---|---|
| ACC-01 | Access | How are organizations, projects, files, search results, and collaboration channels isolated? | Current authorization and tenancy design, including server-side enforcement boundaries. | Awaiting answer | | | | | Pending review |
| ACC-02 | Access | Which password, MFA, SSO, provisioning, recovery, and session controls are available for the proposed plan? | Dated identity-control matrix with plan and role availability. | Awaiting answer | | | | | Pending review |
| ACC-03 | Access | Which roles exist, what can each role view or change, and who can elevate access? | Permission matrix covering project, organization, billing, export, AI, and administrative actions. | Awaiting answer | | | | | Pending review |
| ACC-04 | Access | Which user, administrator, authentication, export, and security events are recorded and reviewable? | Event catalog, access path, integrity controls, export method, and retention schedule. | Awaiting answer | | | | | Pending review |
| AI-01 | AI | Which AI providers and model endpoints receive prompts, design context, files, outputs, metadata, or feedback? | Current AI data-flow diagram, provider register, field inventory, purpose, and transfer mechanism. | Awaiting answer | | | | | Pending review |
| AI-02 | AI | Is customer content used to train, fine-tune, evaluate, or improve Resin or third-party models and services? | Approved contractual or policy statement covering Resin and every AI provider. | Awaiting answer | | | | | Pending review |
| AI-03 | AI | What provider retention, abuse-monitoring, human-review, and deletion terms apply? | Provider-specific terms and Resin configuration or agreement evidence. | Awaiting answer | | | | | Pending review |
| AI-04 | AI | Can an organization disable AI or constrain the project context, users, actions, and data classes available to it? | Plan-specific control matrix and product demonstration. | Awaiting answer | | | | | Pending review |
| SUB-01 | Providers and regions | Which legal entities process account, project, telemetry, support, billing, authentication, and AI data? | Current subprocessor register with purpose and data categories. | Awaiting answer | | | | | Pending review |
| SUB-02 | Providers and regions | Where is each data class stored, processed, backed up, supported, and accessed from? | Architecture and regional-processing record, including remote support access. | Awaiting answer | | | | | Pending review |
| SUB-03 | Providers and regions | Which transfer mechanisms and data-protection terms apply to cross-border processing? | Applicable DPA, transfer mechanism, and supplementary-measures record. | Awaiting answer | | | | | Pending review |
| SUB-04 | Providers and regions | How are customers notified before a provider or processing-location change? | Subprocessor-change process, notice channel, timing, and objection path. | Awaiting answer | | | | | Pending review |
| RET-01 | Lifecycle | How long is each active, deleted, backup, log, support, billing, telemetry, and AI record retained? | Approved retention schedule with trigger, duration, system, owner, and exception. | Awaiting answer | | | | | Pending review |
| RET-02 | Lifecycle | How is project, organization, account, and privacy-request deletion initiated, authorized, verified, completed, and evidenced? | Deletion procedure, completion targets, backup handling, legal-hold rules, and confirmation record. | Awaiting answer | | | | | Pending review |
| RET-03 | Lifecycle | What is backed up, how is it protected, and how often are restores tested? | Backup architecture, schedule, immutability and access controls, plus a dated restore-test result. | Awaiting answer | | | | | Pending review |
| RET-04 | Lifecycle | Which recovery objectives and continuity procedures apply to customer data and service operation? | Approved RTO/RPO, dependency assumptions, continuity plan, and dated exercise result. | Awaiting answer | | | | | Pending review |
| EXP-01 | Exit and portability | Which design, library, BOM, comment, history, attachment, account, membership, audit, and configuration records can be exported? | Plan-and-role export matrix with format, fidelity, dependencies, and known losses. | Awaiting answer | | | | | Pending review |
| EXP-02 | Exit and portability | Can an administrator export an entire organization in a repeatable machine-readable package? | Product demonstration using representative data plus package schema and checksum record. | Awaiting answer | | | | | Pending review |
| EXP-03 | Exit and portability | What access and export window applies after cancellation, suspension, or termination? | Approved contractual terms and operational offboarding procedure. | Awaiting answer | | | | | Pending review |
| EXP-04 | Exit and portability | How should an independent tool validate the exported engineering and manufacturing artifacts? | Receiver acceptance procedure, supported format/version boundaries, and representative result. | Awaiting answer | | | | | Pending review |
| SEC-01 | Security and incidents | How are customer data and credentials protected in transit, at rest, in backups, and during support access? | Protocol, encryption, key-management, secrets-management, and privileged-access description. | Awaiting answer | | | | | Pending review |
| SEC-02 | Security and incidents | How are dependencies, infrastructure, application findings, penetration-test results, and external reports prioritized and remediated? | Vulnerability-management process, severity targets, disclosure route, and dated test summary. | Awaiting answer | | | | | Pending review |
| SEC-03 | Security and incidents | How are relevant incidents detected, investigated, contained, communicated, and closed? | Incident-response plan, customer-notification triggers and timing, contact route, and exercise record. | Awaiting answer | | | | | Pending review |
| SEC-04 | Security and incidents | Which certifications, audits, assessments, or attestations are current and applicable to this service? | Dated scope statement and approved report, certificate, or independent summary. | Awaiting answer | | | | | Pending review |
| SEC-05 | Security and incidents | Which availability, support, escalation, and recovery commitments apply to the proposed plan? | Executed service terms or approved service-level schedule. | Awaiting answer | | | | | Pending review |

## Decision record

- Overall decision: Pending
- Decision rationale:
- Approved data classes and workflows:
- Prohibited data classes and workflows:
- Required controls or conditions before use:
- Accepted gaps, rationale, and expiry or re-review trigger:
- Unresolved risks and question IDs:
- Evidence references, versions, dates, and custodians:
- Next required review date:

Re-review triggers to select when applicable: material product, provider, architecture, region, policy, contract, control, incident, data-use, retention, export, or ownership change; scheduled review date; or newly discovered evidence.

## Required approvals

| Role | Approver | Disposition | Date | Approval record reference |
|---|---|---|---|---|
| Engineering owner | | Pending | | |
| Security owner | | Pending | | |
| Privacy or legal owner | | Pending | | |
| Procurement owner | | Pending | | |
