How to Protect Customer Drawings When You Quote: NDAs, AI, CUI and GDPR

People ask me a version of the same question almost every week. Sometimes it's about a customer's NDA. Sometimes it's whether they can drop a drawing into ChatGPT, whether a print counts as CUI, or where a European customer's data will live.

They're all really one question: when you quote a customer's drawing, where does it go, who can see it, and can you prove it?

Here's how I'd think about each version of that question, and what you should be able to show a customer when they ask.

"Our NDA says our drawings can't go in the cloud"

This is the one I hear most from commercial shops. Most NDAs in this industry exist to stop one thing: a customer's design ending up with someone who shouldn't have it, usually a competitor. They aren't written to stop you from using business software to do the work you were hired to do.

Think about where that drawing already lives. Your estimators open it on their laptops. It sits on a shared drive, gets emailed around internally, and the BOM ends up in your ERP. The real question was never whether the data touches software. It's whether that software is secure, and whether you can prove it.

Read the confidentiality and data handling terms in your agreement. If they're unclear, ask your customer in writing and keep the answer. That one email settles most of these conversations before they become a problem.

"Can we just run this through an AI tool?"

The most common version of this is dropping a print into ChatGPT to pull the BOM. You can. I wouldn't.

A generic model wasn't built on your parts library and can hand you two different BOMs from the same drawing. Even when it's right, there's no NDA behind that upload and no audit trail. Switching off the training toggle makes it a little more private. It doesn't make it appropriate for a customer's proprietary design. If your own customers are starting to ask you these same questions, here's what you should be able to show them.

Use AI. Just ask any AI vendor four things first. Does it train on your data, and is that promise in the contract or just a policy? Is your data isolated from other customers? Are the AI features off until you choose to turn them on? And if you handle CUI, is there a separate environment actually built for it?

"Is this drawing CUI, and does CMMC apply to us?"

This is where people get most confused, and the confusion costs time.

CMMC certifies your company, tied to your CAGE code. It doesn't certify the software you buy. For a cloud vendor handling CUI, the question is whether it meets the FedRAMP Moderate bar. The July CMMC pause didn't change the rules underneath either. DFARS 252.204-7012 and NIST 800-171 still apply.

Deciding whether a drawing is CUI is harder than it should be, because most of what reaches shop floors isn't labeled. When I sold my last wire harness company, I assumed most of our defense work was ITAR controlled. It turned out only two small programs were. Everything else was CUI. I found that out at the worst possible time.

So start with the contract and which DFARS clauses are in it. Ask your customer in writing which category applies. Then write down what you decided and why.  CUI is only one of the questions customers now ask about their drawings. For NDAs, AI tools and data residency too, see how to protect customer drawings when you quote. Assessors aren't looking for perfection. They're looking for a process you can defend. Max Aulakh of Ignyte and I covered all of this in CMMC, CUI and FedRAMP: The Questions You Actually Asked Us.

"Our customer is in Europe. Where does the data live?"

European customers tend to ask about data residency first. They want to know their data is hosted in the EU and handled in a way that supports GDPR. More and more, they also expect a supply chain partner to be working toward ISO 27001.

If you quote for European customers, or run a plant there, ask any software vendor which region your data is hosted in, not just which country the company is in. I covered the rest of what European shops should check in What Is the Best Wire Harness Quoting Solution for European Manufacturers?

What you should be able to show a customer

Whichever version of the question you get, the answer comes down to the same short list. You should be able to show:

  • Where the data is stored, including the hosting region.

  • Who can access it, and whether that access is limited and logged.

  • Whether AI touches it, and a contract term saying it isn't used for training.

  • Which environment handles regulated data, and that it's separate from everything else.

  • Independent evidence, meaning someone outside the vendor has checked the claims.

  • Your own written record of how you classified the data and why.

If you can hand a customer all six, the compliance email stops being a scramble and becomes a reply.

Where Cableteque fits

We built Cableteque so our customers can answer those questions without a scramble. Drawings, BOMs, and quote data stay inside your account, isolated from every other customer. Everything is encrypted in transit and at rest. Production access is role based, time limited, and logged.

Your pricing, suppliers, costs, and margins are never used across customers. Generative AI is off by default. We don't train or fine tune any model on your data, and that commitment is contractual and binds our AI providers too.

Regulated work runs in CabletequeGov, a separate environment on AWS GovCloud (U.S.). CabletequeGov was approved as FedRAMP Ready on July 27. It's listed on the FedRAMP Marketplace as Legacy FedRAMP Ready, Class C (Moderate), and we expect to finish our full FedRAMP Moderate Equivalency audit in November. That is not FedRAMP certification, and we don't claim it is.

European customers can keep their data in AWS Europe Central starting September 30, and we're targeting ISO 27001 certification in December 2026. Our governing documents, including the EULA, MNDA, and AI and Data Policy, are all published with version numbers.

We'll also talk directly with your customer's compliance team, your legal team, or your assessor. Reach us at legal@cableteque.com.

The questions aren't going away. The shops that can answer them quickly are the ones that keep winning the work.

FAQ

Can I use cloud quoting software if I've signed an NDA with my customer?

In most cases, yes. Most NDAs are written to keep a customer's design away from competitors, not to stop you from using secure business software. Check the confidentiality and data handling terms, and if they're unclear, ask your customer in writing and keep the answer.

Is it safe to upload a customer's wire harness drawing to ChatGPT?

It isn't a good idea for a customer's proprietary drawing. A generic model can return inconsistent BOMs. Even with the training toggle off, there's no NDA or audit trail behind the upload.

Does CMMC apply to my quoting software?

No. CMMC certifies your company, not the software you buy. For a cloud vendor handling CUI, the relevant question is whether it meets the FedRAMP Moderate bar.

How do I know if a customer drawing is CUI?

Start with your contract and any DFARS clauses in it, then ask your customer in writing which category applies. Write down what you decided and why, since assessors look for a consistent, documented process.

What should European manufacturers ask about data hosting?

Ask which region the data is hosted in, whether that hosting supports GDPR, and whether the vendor is working toward ISO 27001.

Recommended articles