Skip to main content

Security and data

Start your Resin security review with what is actually published.

See the public statements that apply today, the questions that still need a direct answer, and the policy clauses your reviewer can cite.

Do not send confidential project files with an initial inquiry.

Primary public sources

Privacy Policy Terms of Service Security contact

What the public policies say happens to service data.

This summary follows the Privacy Policy. It does not fill in infrastructure or provider details that Resin has not published.

01

You provide data

Account details, project and workspace content, prompts, comments, imports, and support messages enter Resin when you choose to submit or create them.

02

Resin runs the service

The service processes that information to provide design tools, collaboration, support, security, billing, and AI-assisted features.

03

Approved collaborators can see workspace data

Members, owners, and administrators may see content and activity according to their permissions and organization settings.

04

Service providers support delivery

Provider categories include hosting, authentication, billing, analytics, support, email, and AI infrastructure. The public policy does not name each provider here.

Separate a published statement from an open question.

“Published” means a statement is available on Resin's public site. It does not mean the control was independently tested.

Published

A public product or policy statement is available.

Available on request

A contact path is published; confirm which answers or evidence Resin can provide.

Confirm with Resin

The public material is not detailed enough for a review decision.

Not claimed

Resin makes no public claim for this item on this page.

Identity

Account access, roles, and authentication controls

TopicWhat is known publiclyStatus
Account access

Email-and-password sign-in is visible, but public material does not document the availability and configuration of recovery, two-factor authentication, and organization roles together.

Confirm with Resin
Workspace permissions

The Privacy Policy says workspace visibility and administrative actions depend on permissions and role.

Privacy Policy
Published
SSO, provisioning, and session controls

Plan availability, configuration options, and session behavior are not documented publicly.

Confirm with Resin
Authentication and admin event logs

The public site does not provide an event catalog, access method, or retention schedule.

Confirm with Resin

Data

Ownership, data categories, retention, and portability

TopicWhat is known publiclyStatus
Customer content ownership

The Terms state that customers retain ownership of their schematics, PCB files, libraries, BOMs, outputs, comments, and other project content.

Terms of Service
Published
Data collected and processed

The Privacy Policy lists account, workspace, project, usage, device, diagnostic, support, and security-event information.

Privacy Policy
Published
Access, correction, deletion, and export requests

The Privacy Policy describes these request paths and notes that availability can depend on plan, role, ownership, legal requirements, and technical feasibility.

Privacy Policy
Published
Retention and deletion timelines

A purpose-based retention statement is published, but schedules for active data, deleted data, backups, logs, and AI records are not.

Confirm with Resin

Infrastructure

Providers, locations, encryption, backups, and assurance

TopicWhat is known publiclyStatus
Service-provider categories

The Privacy Policy names categories including cloud infrastructure, authentication, billing, analytics, support, email, and AI infrastructure.

Privacy Policy
Published
Provider register and processing regions

Provider names, purposes by data class, storage regions, and remote-access locations are not listed publicly.

Confirm with Resin
Encryption, keys, secrets, and backups

Implementation details and restore-test evidence are not documented publicly.

Confirm with Resin
Certifications and independent audits

This page does not claim SOC 2, ISO 27001, a penetration test, or another independent attestation.

Not claimed

Operations

Safeguards, incident handling, recovery, and service commitments

TopicWhat is known publiclyStatus
General safeguards

The Privacy Policy says Resin uses administrative, technical, and organizational safeguards, without publishing the underlying control design here.

Privacy Policy
Published
Security and privacy review route

Resin provides a contact path for a redacted question list. Confirm the specific answers and evidence available for your review before relying on them.

Security contact
Available on request
Vulnerability and incident response

Processes, response targets, notification triggers, exercise records, and test summaries are not documented publicly.

Confirm with Resin
Business continuity and recovery

Recovery objectives, dependency assumptions, and dated recovery-test results are not published.

Confirm with Resin
Availability and support commitments

No public uptime SLA or security escalation commitment is claimed on this page.

Not claimed

AI

Project context, model providers, retention, and organization controls

TopicWhat is known publiclyStatus
AI feature inputs

The Privacy Policy says relevant prompts, project context, files, outputs, and feedback may be processed when AI-assisted features are used.

Privacy Policy
Published
AI providers and model endpoints

The current provider list, model endpoints, data fields sent, and transfer paths are not published.

Confirm with Resin
Training, provider retention, and human review

Provider-specific training use, retention, abuse monitoring, and human-review terms are not stated publicly.

Confirm with Resin
Organization-level AI controls

The ability to disable AI or limit its users, actions, project context, and data classes is not documented publicly.

Confirm with Resin

Bring these questions to your review.

These topics are not answered in enough detail by the public site. Ask for written, dated answers that match your plan, data classes, and intended use.

  1. 01

    The current subprocessor list and the data each provider receives

  2. 02

    Storage, processing, backup, and support-access regions

  3. 03

    Encryption protocols, key management, and privileged-access controls

  4. 04

    AI provider training, retention, abuse-monitoring, and human-review terms

  5. 05

    Incident response, vulnerability management, and customer-notification targets

  6. 06

    Backup testing, recovery objectives, uptime commitments, and independent audit results

Ask for the information your organization needs.

Send a redacted list of questions, the product scope being evaluated, and the evidence your reviewer expects. Confirm an approved transfer method before sharing sensitive material.