Security
goCAD is designed to protect your design data first. Design data (STEP files) is processed only on your PC and is never sent to Kotogoo or any external server.
Last updated: July 2026
Local-First by Design
goCAD is a local, self-contained desktop application. The 3D STEP models you load and the drawings you generate are all processed and stored within your PC. There is no upload to the cloud and no transmission to our servers (except when you choose to use the optional AI assistant — see "Network Communication" below).
- Works in offline environments with no internet connection.
- Because design data never leaves your internal network, even highly confidential drawings and part data can be handled with confidence.
- Input (STEP files) and output (DXF / PDF) stay entirely on your local file system.
Data Handling
- Where design data is stored
- Your local PC (no external transmission)
- Cloud integration
- None (no upload to the cloud)
- Usage data (telemetry)
- Not collected (the application has no usage-reporting feature)
- Personal information
- Not collected by the application itself
Network Communication
goCAD’s core features (STEP import, geometry analysis, dimensioning, and DXF / PDF export) all run on your PC and do not communicate externally. Your design data (STEP files) is never transmitted.
- License activation: no online license activation is performed.
- Automatic updates: no automatic update check is performed.
- Optional AI assistant: goCAD includes an optional AI assistant that helps with tasks such as dimensioning. It is disabled by default and requires you to configure your own API key. Only when you enable it is geometry information sent to the LLM provider you choose (default: OpenRouter). Unless you use this feature, goCAD does not communicate externally. In any case, the STEP file itself is never uploaded.
Installer Authenticity (Code Signing)
Our distributed installer will be digitally signed with a code signing certificate to prevent spoofing and tampering, and we will publish the SHA-256 hash of each release.
After downloading, you can verify that the file has not been tampered with by comparing it against the published SHA-256 hash.
Software Transparency (OSS / SBOM)
We publish the open-source software (OSS) components used by goCAD and their licenses. Based on METI’s "Guide to Introducing SBOM for Software Management," we also provide a Software Bill of Materials (SBOM).
Vulnerability Handling
If you discover a security issue, please contact us at contact@kotogoo.com. We will review your report, assess the impact, and make the necessary fixes.
On Third-Party Certification
We do not currently hold third-party certifications such as ISMS (ISO/IEC 27001), and will consider obtaining them as our business grows. Note that goCAD uses a local, self-contained architecture that does not transmit design data externally, structurally reducing the risk of information leakage.
For Procurement / IT Teams
We can respond to security assessment checklists and provide additional materials required for your review. See the procurement page for details.