Trust Center
Security & Trust
Polar Cloud powers secure 3D printing workflows for manufacturers, engineering firms, universities, libraries, and thousands of schools worldwide. This Trust Center explains how we protect your data, operate our infrastructure, and respond to security events.
Compliance posture
Polar Cloud is FERPA and COPPA compliant, GDPR ready, and iKeepSafe certified. Polar Cloud is hosted on AWS infrastructure that is independently certified to standards including SOC 2 Type II and ISO 27001. Polar3D applies comparable operational security controls to the services we manage.
Polar3D has not yet completed an independent SOC 2 audit and therefore does not claim SOC 2 certification. If your security review requires additional information, we’re happy to provide our Security Overview and respond to vendor security questionnaires.
Security
How we protect accounts, files, and printer connections. For the full architecture — including our outbound-only printer networking model — see the security overview.
Encryption in transit
All communication with Polar Cloud is protected using TLS 1.2 or higher. Customer data is encrypted at rest using industry-standard encryption provided by our cloud infrastructure.
Authentication
Credentials are salted and hashed — never stored in plain text. Sessions expire on inactivity, and password resets are single-use and time-limited.
MFA
Multi-factor authentication is available on all accounts and can be required organization-wide by an administrator. Sensitive actions trigger an additional step-up challenge.
SSO
Polar Cloud supports authentication through Google, Microsoft, Clever, ClassLink, and other supported identity providers. Contact us if you require enterprise identity integration using a specific provider or protocol.
Monitoring
Infrastructure, application, and authentication events are logged centrally and retained for investigation. Anomalous sign-in activity raises an alert to our on-call rotation.
Incident response
Polar Cloud follows a documented incident response process. If a confirmed security incident affects customer data, impacted customers are notified without undue delay in accordance with applicable laws and contractual obligations.
Reliability
Polar Cloud runs print queues that classrooms and production floors depend on. Our platform health, uptime history, and incident reports are publicly available in real time. We believe transparency is an important part of operational reliability.
Public status page
Live component-level status for the web app, API, and printer WebSocket service. Subscribe there to get incident notifications by email as they are posted.
Historical uptime
The status page publishes our uptime history alongside a full archive of past incidents and their post-incident notes — including the ones that did not go well.
Planned maintenance policy
Routine maintenance is scheduled outside North American school hours and announced on the status page in advance. Maintenance that could interrupt active print jobs is announced at least five business days ahead.
Data
We only collect what running the platform requires. We do not sell, rent, or trade customer or student data — including to advertisers.
Data ownership
Your models, G-code, and print history remain yours. Customer models, CAD files, and engineering data remain the property of the customer and are never used to train AI models. Self-service data export is in development.
Data retention
Account and print data is retained for as long as the account is active. When a subscription ends, data is retained for 90 days so it can be recovered, then scheduled for deletion.
Data deletion
Administrators can delete individual records or request full deletion of an organization’s data. Verified deletion requests are processed according to our documented data retention policy. Customer data is removed from production systems, and backup copies expire automatically through our backup retention schedule. Written confirmation of deletion is available upon request.
Backups
Databases are backed up automatically with point-in-time recovery, stored encrypted in a separate location, and restore procedures are tested on a regular schedule.
Enterprise
Documentation for procurement, legal, and security review.
Security overview (PDF)
Our security whitepaper: architecture, encryption, access control, and the answers most vendor assessments ask for.
Enterprise SLA (PDF)
Contractual uptime commitments, support response targets, and remedies. Available on request for enterprise and district agreements.
Data Processing Addendum
Coming soonA GDPR-aligned DPA covering processing terms, subprocessors, and international transfers. In preparation — contact us if you need one to complete a purchase.
Questions, or reporting something?
Our security team answers vendor assessments, sends the enterprise SLA, and triages vulnerability reports. We aim to acknowledge every report within one business day.
security@polar3d.com