What Intake does with the file you send it, what it keeps to itself, and what it shares — stated plainly, with each measure marked by whether it is in force today or lands with the hosted release.
Intake is currently an advanced prototype. The isolation principles below are built into its architecture today; the production enforcement — authentication, per-client isolation, encryption at rest, sovereign hosting, and audit logging — is being implemented for the hosted release.
A BOM is your product’s recipe and sourcing strategy — which parts, in what quantities, on which board, from which sources. Reconstructing it means reverse-engineering your design and cost structure. Protecting that is the whole point of Intake.
What we pool to get smarter carries none of your composition. Even with full access to our shared knowledge, no one can reconstruct your BOM — the data that reveals a product lives only in your private space, isolated to you.
Your uploaded files, the link between your internal part codes and real parts, with quantities and placement, plus your reports. Isolated to you, never pooled. This is the crown-jewel data, and the only place the revealing join “part X, used by you, N times, on board Z” ever exists.
How to read a file format — delimiters, where columns sit. Structure only, no part data, so sharing it reveals nothing about your parts.
Public manufacturer facts about a part — package, specs, lifecycle — keyed to the manufacturer’s own public part number. Universal reference knowledge; it never says who uses a part.
Your file is read locally at the edge and turned into a clean, normalized form. Nothing is looked up in a third-party supplier database at import — your raw BOM is never shipped out to be matched. Only the normalized result travels onward.
If your security policy forbids exporting a full BOM — common in defense and aerospace — you can import a part list instead: the same parts with the structure (reference designators, placement, assembly topology) stripped out. A part list is inherently reverse-engineering-safe, so you get sourcing and qualification while never disclosing how the parts fit together.
Choose it when you upload: the intake page asks whether you are sending a BOM or a part list, and the choice travels with the analysis. In part-list mode the absent design fields are treated as expected rather than as gaps, and they are nulled in what we hand on rather than reconstructed.
At production, your data is encrypted in transit and at rest (KMS envelope encryption as the baseline). For the most sensitivity-constrained clients we offer two stronger options: PGP encryption with your own key (so even we can’t read your stored file), or fully in-browser analysis (your raw BOM never leaves your machine — we receive only the normalized result). Access is least-privilege, and Tier-1 access is audit-logged.
For clients with sovereignty requirements, Intake can be deployed on SecNumCloud-qualified sovereign infrastructure — S3NS (Thales × Google), operated in France by Thales — so your data stays under French jurisdiction. Intake’s import runs offline by design, which makes a zero-egress sovereign deployment a natural fit.
The SecNumCloud qualification is S3NS’s, not Adesio’s: Intake is not itself SecNumCloud-qualified. This deployment is available on request, and is not the current default hosting.