DATA ISOLATION & MODEL INTEGRITY
At EXO-0, we recognize that your architectural Revit families, corporate templates, and active project files represent highly sensitive proprietary assets. Our governance system is architected from the ground up to respect absolute data boundaries.
The EXO-0 Revit Desktop Add-in runs and executes QA checks completely within your workstation memory space or local network parameters. No design geometry, coordinates, family file bytes, custom schedules, or parameter definitions are transmitted to, parsed by, or cached on our cloud servers.
Your models never leave your workstations.
INFORMATION WE COLLECT
We limit data collection to the minimum technical telemetry and billing details required to run the service:
- Account Metadata: When you register, we collect authentication metadata (email addresses, passwords hashed securely via cryptographic algorithms, full names, usernames, and organization associations).
- Administrative Billing Logs: Standard commercial parameters required to coordinate subscription tiers, processed securely through Stripe (such as credit card last-4 digits, billing address, and transaction status logs).
- Auditing Telemetry summaries: The PROBE QA Agent uploads high-level compliance summaries to display in your Org Centre. This summary metadata is limited to parameters like: run timestamp, corporate member ID, model file name (excluding local directory paths), and numerical compliance scores (e.g., family parameter error count, bad line style counts).
HOW DATA IS UTILISED
We use the gathered telemetry and account parameters for the following operational workflows:
- Validating floating license access, concurrent workstation logins, and seat allocation limits.
- Displaying administrative audit histories in your Org Centre dashboard so managers can trace compliance over time.
- Identifying workstation error traces to isolate add-in crashes and distribute software updates.
- Securing user environments from unauthorized API attempts or license key sharing.
THIRD-PARTY INTEGRATIONS
To provide enterprise B2B workflows, we securely interface with select cloud service providers:
Hosts account metadata, permission states, and telemetry logs. Guarded with Row Level Security (RLS) policies.
Processes payments, invoices, subscription changes, and payment renewals. Financial data complies with PCI-DSS specifications.
SECURITY MATRIX & COMPLIANCE
Our infrastructure matches modern enterprise security standards to defend database records:
- Encryption at Rest & In-Transit: All database storage volumes utilize AES-256 encryption. Network data is encrypted using TLS 1.3 parameters.
- Isolation Controls: Organization tenants are strictly separated. Profiles and logs are restricted using server-enforced Postgres rules matching unique organization identifiers.
- Vulnerability Scans: Continuous automated tracking verifies dependencies and prevents API vulnerability exploits.
RETENTION & PURGING
We keep operational information active for the duration of your service subscription. Upon corporate account cancellation, administrators can request a complete profile delete:
- All user profiles, names, and team invites associated with the Org are permanently deleted from database tables.
- Uploaded QA audit histories and license activation keys are purged.
- Secure database backups are cleared recursively in accordance with standard data cycle retention policies within 30 days.
SYSTEM SUPPORT & DATA COORDINATOR
If your compliance officers require detailed data charts, data export sheets, or signed security agreements, contact our Data Protection Officer directly: