AI & Data Policy
1. Purpose
Cableteque Corp uses Optical Character Recognition (OCR) and Generative AI, including Large Language Models, within its Licensed Software to reduce manual data entry and enhance the user experience. These technologies extract Bills of Materials and technical data from engineering drawings and generate intelligent recommendations within the platform.
This policy describes how AI technologies process data, what protections apply to your data, and Cableteque's commitments regarding the responsible use of AI.
This policy operates in conjunction with the Cableteque End User License Agreement (EULA), Privacy Notice, and the Mutual Non-Disclosure Agreement (MNDA). In the event of a conflict, the order-of-precedence provisions of the EULA and any applicable executed addendum shall govern.
2. AI Features
AI features are opt-in and disabled by default. Enablement requires an authorized administrator to accept the AI Feature Addendum. Licensee is responsible for review of AI outputs by a qualified person before those outputs are relied upon for quoting, engineering, design validation, or other decisions. AI outputs are decision-support material and are not a substitute for qualified professional judgment.
2.1 BOM, F2L, and Technical Data Extraction
Uses OCR and Generative AI to read engineering drawings and automatically populate a Bill of Materials (BOM), Wires From-to-List (F2L), and associated technical data, reducing manual data-entry effort.
Inputs: Licensee-uploaded engineering drawings and technical documents.
Processing: OCR-based text recognition followed by LLM-based structured data extraction.
Outputs: Extracted BOM, F2L, and technical data; part numbers, manufacturers, descriptions, quantities, measurements.
2.2 Intelligent Recommendations
Generative AI provides suggestions and recommendations within the platform, for example, component matching and quote optimization. All such outputs are for reference only. See Section 8 for accuracy limitations.
2.3 Future AI Features
Any new AI feature or use case not described above will be reviewed and approved by Cableteque's Security Officer before release. This policy will be updated accordingly, and Licensees will be notified of material changes in accordance with Section 14.
3. Data Framework: Definitions and Protections
Cableteque's data commitments are organized around three distinct categories. Understanding these categories is the foundation of this policy.
3.1 Licensee Data
All electronic data or information submitted by Licensee to the Licensed Software, including BOMs, engineering drawings, specifications, proprietary part data, Commercial Data (defined in Section 6.2), and any AI-generated outputs derived from that data. Licensee Data is fully protected under the commitments in this policy and the EULA.
3.2 Usage Data
Data about how Licensee and its authorized users interact with the platform; clickstream data, features used, session telemetry, browser type, and performance metrics. Usage Data does not include Licensee Data or any AI-generated outputs derived from Licensee Data.
Identifiable Usage Data may be used to operate, secure, administer, support, and troubleshoot the applicable Licensee account. Cross-customer usage analytics and trend analysis use aggregated or de-identified Usage Data. Permitted uses of Licensee Data for generalized product improvement are described in Section 4; Licensee-specific enhancement is described in Section 5.
3.3 Prohibitions
The following uses of data are prohibited:
• Using Licensee Data from one account as customer-specific data, patterns, recommendations, or intelligence to inform another Licensee's experience, except for generalized product improvements permitted under Section 4 that do not disclose, reproduce, or permit reconstruction of Licensee Data.
• Using Licensee Data to train or fine-tune the weights or parameters of any artificial intelligence or machine-learning model, or as a cross-customer model-training dataset.
• Using Licensee Data or Commercial Data for cross-customer benchmarking, market-pricing analytics, supplier intelligence, or competitive insights.
Providers that process Licensee Data are governed by written service, confidentiality, security, and data-use terms appropriate to their role. AI providers are prohibited from using Licensee Data to train, fine-tune, benchmark, or improve models for the benefit of any third party.
4. No-Training Commitment
Cableteque does not use Licensee Data, Commercial Data, or AI-generated outputs to train or fine-tune the weights or parameters of an artificial intelligence or machine-learning model, whether Cableteque's or a third party's, or as a cross-customer model-training dataset. This restriction does not prevent Cableteque from using Licensee Data as reasonably necessary to provide, maintain, secure, administer, support, troubleshoot, validate, or improve the Licensed Software, including reproducing reported issues, validating corrections, and developing generalized bug fixes, rules, algorithms, heuristics, prompts, workflows, code changes, and other product improvements, subject to the restrictions in this Policy.
This prohibition applies to:
• All Licensee Data and documents uploaded to the Licensed Software.
• All AI-generated outputs derived from Licensee Data (e.g., extracted BOMs, F2L, technical data, or recommendations).
• All Commercial Data as defined in Section 6.2.
• Usage Data when attributed to an individual Licensee account, for model training purposes.
Permitted uses of data in the context of AI operations are limited to:
• Providing, maintaining, securing, administering and supporting the Licensed Software, including session-specific troubleshooting of the applicable Licensee account.
• Identifying trends and usage patterns using aggregated or de-identified Usage Data.
• Improving the Licensed Software and Cableteque's internal analytical capabilities using aggregated or de-identified Usage Data. Cross-customer usage analytics and trend analysis use aggregated or de-identified Usage Data only. Licensee Data may be used for troubleshooting, validation, error correction, and generalized product improvement only as expressly permitted in this Section.
• Creating aggregated, anonymized data for lawful business purposes.
Cableteque does not use Licensee Data or Commercial Data for cross-customer benchmarking, market-pricing analytics, supplier intelligence, or competitive insights. Requirements applicable to third-party AI providers are described in Section 9.
5. Within-Account Enhancement
Cableteque may use a Licensee's own Licensee Data to improve that Licensee's experience within their own account, for example, by recognizing components, suppliers, or configurations the Licensee commonly specifies or enriches, and applying those patterns to pre-populate or suggest data within that same account.
This use is strictly within-account. Licensee Data from one account is never used as customer-specific data, patterns, recommendations, or intelligence for another Licensee. This restriction does not prohibit generalized product improvements made in accordance with Section 4. Within-account enhancement does not constitute training or fine-tuning of an AI or machine-learning model.
6. Proprietary Data Protections
6.1 Component Library
The rules governing Cableteque's shared component library, including what may be added to the library, how commercially available component specifications are handled, and the auto-designation of all Licensee Data as proprietary, are set out in the Data Use provision of the EULA, which is the binding contractual commitment on this topic.
Licensee-proprietary data, custom components, Licensee-specific assembly configurations, internal or non-public part numbers, and Commercial Data are never added to the shared component library. Shared component-library records do not expose Licensee identity and do not permit any reconstruction of a Licensee's bill-of-materials composition, assembly relationships, or design context. Library enrichment is limited to publicly available specifications for commercially available components.
See the EULA for the complete and governing terms.
6.2 Commercial Data
“Commercial Data” means any Licensee-specific pricing, supplier relationships, payment terms, MOQ, lead times, costs and margins, obtained in a non-public way. This includes:
• Negotiated supplier pricing, discounts, and rebates.
• Supplier identities and proprietary supplier relationships.
• Payment terms, Licensee-specific minimum order quantities, and lead-time agreements.
• Quote pricing, Licensee-specific cost structures, and margin data.
Commercial Data is treated as Confidential, logically segregated by Licensee identifier, and accessible only to authorized Cableteque personnel for service delivery. Cableteque does not use Commercial Data to train AI models, to generate cross-Licensee recommendations, or to produce benchmarking, market-pricing, supplier-intelligence, or competitive-insight analytics derived from Licensee pricing or supplier data.
7. Regulated Content
Cableteque operates two separate environments. The Commercial environment supports ordinary commercial workloads. CabletequeGov supports CUI, CDI, and approved export-controlled workloads under applicable customer terms. CabletequeGov is hosted on AWS GovCloud (U.S.), with defined processing functions performed in U.S.-only regions of Azure Government and Google Cloud Assured Workloads. All CabletequeGov processing occurs within U.S. regions.
All Licensee Data is treated as confidential and proprietary by default, regardless of labeling. Licensee remains responsible for determining whether its data is subject to CUI, CDI, ITAR, EAR, or other regulatory restrictions, for identifying such data before submission, and for ensuring that its users are appropriately authorized.
7.1 Commercial Instance
The Commercial environment is not authorized to process Controlled Unclassified Information (CUI), Covered Defense Information (CDI), ITAR-restricted data, or other export-controlled content. Licensees must not submit such content to the Commercial environment.
7.2 CabletequeGov
CabletequeGov is purpose-built to process CUI, CDI, and approved export-controlled technical data. CabletequeGov customers are subject to additional controls and terms described in their governing agreement, including the CabletequeGov Compliance Addendum.
Access to unencrypted Licensee Data, including export-controlled technical data, and to the means of decryption, is restricted to U.S. persons or other persons authorized under applicable U.S. export-control law. Personnel without such authorization may perform infrastructure or platform-support activities only where technical and organizational controls prevent access to such data or to the means of decryption.
Cloud-provider certifications and authorizations apply only to the provider services and authorization boundaries identified in the applicable provider package. Cableteque's use of an authorized cloud service does not, by itself, certify or authorize CabletequeGov.
|
Control |
Description |
|
Access Restriction |
Access limited to authorized personnel; role-based access controls enforced consistent with the FedRAMP® Moderate baseline. Export-controlled access is restricted as described above in this Section 7.2. |
|
Encryption |
Encryption in transit and at rest as described in Section 11, including FIPS 140-3 validated cryptographic modules for CabletequeGov. |
|
No AI Training |
CabletequeGov data is not used to train, fine-tune, benchmark, or improve any model. See Section 4. |
|
Audit Logging |
All access and processing events are logged and available for compliance review. |
|
Data Residency |
All CabletequeGov processing occurs within U.S. regions, as described above in this Section 7.2. |
|
Hosting and Assessment Status |
Hosting is described above in this Section 7.2; assessment and certification status is described in Section 12. |
8. AI Output Accuracy
AI-generated output, including BOM and technical data extraction results, component recommendations, and any other AI-assisted data, is for reference only. It does not constitute engineering certification, professional advice, or a guarantee of accuracy. All outputs must be reviewed and validated by a qualified person before use in any engineering, manufacturing, quoting, or procurement process. Licensee's review responsibility is stated in Section 2.
Cableteque acknowledges the following known limitations of its AI features:
• AI processing does not guarantee 100% accuracy. Output may be incomplete, incorrect, or have missing items.
• Large or highly complex drawings (approximately over 4,000 square inches) may yield lower accuracy.
• Processing times vary. Complex files may take 30 minutes or longer.
• AI features are in active development. Capabilities, supported file types, and behavior may change over time.
• AI features do not perform engineering design validation, quality inspection, or manufacturing certification.
Licensees are solely responsible for any decisions, actions, or outcomes based on AI-generated output. These limitations are described in further detail in the AI Feature Addendum, which Licensees must execute before accessing AI features.
9. Third-Party AI Providers
Providers that process Licensee Data are governed by written service, confidentiality, security, and data-use terms appropriate to their role. AI providers are prohibited from using Licensee Data to train, fine-tune, or improve models.
AI processing for CabletequeGov is performed by approved providers operating within U.S.-region environments.
The following additional requirements apply:
• Written data-protection terms are in place before any Licensee Data is transmitted to a third-party AI provider.
• Providers are subject to security due diligence and must demonstrate compliance with applicable data protection standards.
• Licensee Data transmitted to third-party providers is encrypted in transit and subject to the same classification controls as all other production data. See Section 11.
• The Security Officer maintains an approved provider registry. No unapproved provider may receive Licensee Data.
• Provider terms are reviewed annually or upon any material change to the provider's services.
CabletequeGov. Additional provider, processing-region, data-residency, and authorization requirements applicable to CabletequeGov are governed by the CabletequeGov Compliance Addendum, including its Schedule A.
10. Data Retention
AI-processed data, including inputs and outputs, is subject to the same retention practices as all Licensee Data, as described in Cableteque's Privacy Notice.
11. Security Controls
AI pipelines and components are treated as production systems and are subject to the same security controls applied across the Cableteque platform.
Licensee Data is encrypted in transit using TLS 1.2 or higher, or other approved cryptographic protocols appropriate to the applicable service, and at rest using cloud-native key-management services governed by Cableteque-controlled access policies. CabletequeGov uses cryptographic modules validated to FIPS 140-3 and listed in the NIST Cryptographic Module Validation Program.
Routine direct administrative access to production Licensee Data is disabled. Time-bound, least-privilege access may be granted to authorized personnel for approved support, security, legal, or incident-response purposes, and such access is logged and reviewed.
Additional controls include:
• Logical segregation of Licensee Data at the database and API layer using a unique Licensee identifier. AI output from one account is not exposed to another.
• Access to AI production systems is disabled by default and requires approval.
• Continuous logging and security monitoring across all AI pipeline infrastructure.
• Industry-standard security inspection, including anti-virus and vulnerability scanning of AI software components prior to deployment.
Any suspected security incident involving AI-processed data should be reported immediately to support@cableteque.com.
12. Compliance Posture
CabletequeGov was approved as FedRAMP® Ready on July 27, 2026, and is listed on the FedRAMP® Marketplace (Package ID FR2620331565). Following the FedRAMP® program's 2026 transition, the Marketplace designates Rev 5 Ready listings as “Legacy FedRAMP® Ready” (Class C/Moderate, Agency path, effective July 28, 2026). The Readiness Assessment was performed by Ignyte Assurance Platform, an accredited Third-Party Assessment Organization, against the FedRAMP® Moderate baseline covering the full CabletequeGov system boundary: infrastructure, platform, and application. The FedRAMP® Program Management Office reviewed the results and identified no concerns.
An independent FedRAMP® Moderate Equivalency assessment is being conducted by Ignyte Assurance Platform. Cableteque expects the full audit to occur in November 2026, with full 3PAO-validated Body of Evidence and other documentation required under applicable DoD FedRAMP® Moderate Equivalency guidance, targeted for completion in December 2026. Target dates are planning objectives.
ISO/IEC 27001 certification across all Cableteque environments is in progress, with completion targeted by the end of 2026, and Ignyte Assurance Platform engaged for ISMS implementation support and the certification audit.
13. Privacy and Contact
This AI & Data Policy operates in conjunction with Cableteque's Privacy Notice, which governs the collection, use, and sharing of information when you use the Licensed Software. Key data uses in connection with AI workflows are summarized below.
|
Data Type |
Description |
Purpose |
|
Session & Interaction Data |
Clickstream data, features used, time on pages, session telemetry |
Operating, securing, administering, supporting, and troubleshooting the applicable Licensee account; product improvement; within-account enhancement |
|
Device & Log Data |
IP address, browser type, OS, crash reports |
Security monitoring and performance analysis |
Consistent with the Privacy Notice, data collected in AI workflows is used only as permitted by the Policy, including within-account enhancement and generalized product improvement under §4. Cableteque does not sell Licensee Data.
14. Changes to This Policy
Cableteque will provide at least thirty (30) days' prior written notice of any material amendment to an incorporated policy that materially diminishes Licensee's rights or materially alters the handling or security of Licensee Data. Non-material changes, including clarifications, formatting and editorial corrections, do not require notice. No policy amendment will modify a mutually executed agreement without a writing signed by both parties.