Trust Center
For Procurement Teams
For procurement and IT teams evaluating goCAD, we have gathered the information needed for your review. We can also respond to security assessment checklists and provide additional materials.
Last updated: July 2026
Quick Facts
- Product
- goCAD (CAD automation tool)
- Provider
- Kotogoo (Nagoya, Aichi, Japan)
- Delivery
- Windows desktop application (local install)
- Design data processing
- Self-contained on your PC. No external transmission
- Upload to cloud
- None
- Personal information (app itself)
- None collected
- Installer signing
- Code signing planned at release
- OSS / SBOM
- Published (provided in SPDX / CycloneDX format)
- Offline operation
- Supported
- Contact
- contact@kotogoo.com
Responses to Common Security Checklist Items
- External transmission of design data: none. Everything is processed locally.
- Data storage location: your local PC. Not stored on our servers or the cloud.
- Communication: core features run offline and do not transmit design data (STEP files). Only when the optional AI assistant (opt-in, disabled by default) is enabled is geometry information sent to the LLM provider you configure.
- Software authenticity: verifiable via the signed installer and SHA-256 checksum.
- Third-party components: disclosed in the OSS license list and SBOM.
- Incident response: reports accepted at contact@kotogoo.com; we assess impact and provide fixes.
- Third-party certification: not currently held (under consideration). The local, self-contained architecture reduces risk.
Materials We Can Provide
- Company information (company profile / documents verifying the existence of the business).
- Security overview document (a PDF version of this page).
- Software Bill of Materials (SBOM).
- End User License Agreement (EULA).
- We can also enter into a non-disclosure agreement (NDA).
Contact
To send us a security checklist, request additional materials, or discuss adoption, please contact us at contact@kotogoo.com.