You provide data
Account details, project and workspace content, prompts, comments, imports, and support messages enter Resin when you choose to submit or create them.
Security and data
See the public statements that apply today, the questions that still need a direct answer, and the policy clauses your reviewer can cite.
Do not send confidential project files with an initial inquiry.
Primary public sources
Data flow summary
This summary follows the Privacy Policy. It does not fill in infrastructure or provider details that Resin has not published.
Account details, project and workspace content, prompts, comments, imports, and support messages enter Resin when you choose to submit or create them.
The service processes that information to provide design tools, collaboration, support, security, billing, and AI-assisted features.
Members, owners, and administrators may see content and activity according to their permissions and organization settings.
Provider categories include hosting, authentication, billing, analytics, support, email, and AI infrastructure. The public policy does not name each provider here.
Public control matrix
“Published” means a statement is available on Resin's public site. It does not mean the control was independently tested.
A public product or policy statement is available.
A contact path is published; confirm which answers or evidence Resin can provide.
The public material is not detailed enough for a review decision.
Resin makes no public claim for this item on this page.
Account access, roles, and authentication controls
| Topic | What is known publicly | Status |
|---|---|---|
| Account access | Email-and-password sign-in is visible, but public material does not document the availability and configuration of recovery, two-factor authentication, and organization roles together. | Confirm with Resin |
| Workspace permissions | The Privacy Policy says workspace visibility and administrative actions depend on permissions and role. Privacy Policy | Published |
| SSO, provisioning, and session controls | Plan availability, configuration options, and session behavior are not documented publicly. | Confirm with Resin |
| Authentication and admin event logs | The public site does not provide an event catalog, access method, or retention schedule. | Confirm with Resin |
Ownership, data categories, retention, and portability
| Topic | What is known publicly | Status |
|---|---|---|
| Customer content ownership | The Terms state that customers retain ownership of their schematics, PCB files, libraries, BOMs, outputs, comments, and other project content. Terms of Service | Published |
| Data collected and processed | The Privacy Policy lists account, workspace, project, usage, device, diagnostic, support, and security-event information. Privacy Policy | Published |
| Access, correction, deletion, and export requests | The Privacy Policy describes these request paths and notes that availability can depend on plan, role, ownership, legal requirements, and technical feasibility. Privacy Policy | Published |
| Retention and deletion timelines | A purpose-based retention statement is published, but schedules for active data, deleted data, backups, logs, and AI records are not. | Confirm with Resin |
Providers, locations, encryption, backups, and assurance
| Topic | What is known publicly | Status |
|---|---|---|
| Service-provider categories | The Privacy Policy names categories including cloud infrastructure, authentication, billing, analytics, support, email, and AI infrastructure. Privacy Policy | Published |
| Provider register and processing regions | Provider names, purposes by data class, storage regions, and remote-access locations are not listed publicly. | Confirm with Resin |
| Encryption, keys, secrets, and backups | Implementation details and restore-test evidence are not documented publicly. | Confirm with Resin |
| Certifications and independent audits | This page does not claim SOC 2, ISO 27001, a penetration test, or another independent attestation. | Not claimed |
Safeguards, incident handling, recovery, and service commitments
| Topic | What is known publicly | Status |
|---|---|---|
| General safeguards | The Privacy Policy says Resin uses administrative, technical, and organizational safeguards, without publishing the underlying control design here. Privacy Policy | Published |
| Security and privacy review route | Resin provides a contact path for a redacted question list. Confirm the specific answers and evidence available for your review before relying on them. Security contact | Available on request |
| Vulnerability and incident response | Processes, response targets, notification triggers, exercise records, and test summaries are not documented publicly. | Confirm with Resin |
| Business continuity and recovery | Recovery objectives, dependency assumptions, and dated recovery-test results are not published. | Confirm with Resin |
| Availability and support commitments | No public uptime SLA or security escalation commitment is claimed on this page. | Not claimed |
Project context, model providers, retention, and organization controls
| Topic | What is known publicly | Status |
|---|---|---|
| AI feature inputs | The Privacy Policy says relevant prompts, project context, files, outputs, and feedback may be processed when AI-assisted features are used. Privacy Policy | Published |
| AI providers and model endpoints | The current provider list, model endpoints, data fields sent, and transfer paths are not published. | Confirm with Resin |
| Training, provider retention, and human review | Provider-specific training use, retention, abuse monitoring, and human-review terms are not stated publicly. | Confirm with Resin |
| Organization-level AI controls | The ability to disable AI or limit its users, actions, project context, and data classes is not documented publicly. | Confirm with Resin |
Known unknowns
These topics are not answered in enough detail by the public site. Ask for written, dated answers that match your plan, data classes, and intended use.
The current subprocessor list and the data each provider receives
Storage, processing, backup, and support-access regions
Encryption protocols, key management, and privileged-access controls
AI provider training, retention, abuse-monitoring, and human-review terms
Incident response, vulnerability management, and customer-notification targets
Backup testing, recovery objectives, uptime commitments, and independent audit results
Security and procurement
Send a redacted list of questions, the product scope being evaluated, and the evidence your reviewer expects. Confirm an approved transfer method before sharing sensitive material.