SECURITY WHAT IS PRIVATE · WHAT IS POOLED LOCAL · SINGLE_USER
Adesio · Intake

How we protect your BOM

What Intake does with the file you send it, what it keeps to itself, and what it shares — stated plainly, with each measure marked by whether it is in force today or lands with the hosted release.

Where we are today

Intake is currently an advanced prototype. The isolation principles below are built into its architecture today; the production enforcement — authentication, per-client isolation, encryption at rest, sovereign hosting, and audit logging — is being implemented for the hosted release.

01

Why this matters

A BOM is your product’s recipe and sourcing strategy — which parts, in what quantities, on which board, from which sources. Reconstructing it means reverse-engineering your design and cost structure. Protecting that is the whole point of Intake.

02

The core guarantee

What we pool to get smarter carries none of your composition. Even with full access to our shared knowledge, no one can reconstruct your BOM — the data that reveals a product lives only in your private space, isolated to you.

Private to you — never pooled Client A Your files Your part codes → parts quantities · placement Your reports Client B Your files Your part codes → parts quantities · placement Your reports Client C Your files Your part codes → parts quantities · placement Your reports Pooled — carries no client data Format knowledge how to read a file format — structure only, no part data Universal parts facts package · specs · lifecycle, keyed to the public part number
The join that would reveal a product — this part, used by you, this many times, on this board — exists only inside the dashed boundary, per client. What is pooled below it is structure and public manufacturer facts, which say nothing about who uses what.
03

What stays private, and what we share

Your private space

Your uploaded files, the link between your internal part codes and real parts, with quantities and placement, plus your reports. Isolated to you, never pooled. This is the crown-jewel data, and the only place the revealing join “part X, used by you, N times, on board Z” ever exists.

Format knowledge (shared)

How to read a file format — delimiters, where columns sit. Structure only, no part data, so sharing it reveals nothing about your parts.

Universal parts facts (shared)

Public manufacturer facts about a part — package, specs, lifecycle — keyed to the manufacturer’s own public part number. Universal reference knowledge; it never says who uses a part.

04

Reading your file protects youIN FORCE TODAY

Your file is read locally at the edge and turned into a clean, normalized form. Nothing is looked up in a third-party supplier database at import — your raw BOM is never shipped out to be matched. Only the normalized result travels onward.

05

Can’t share a full BOM? Import a part list insteadIN FORCE TODAY

If your security policy forbids exporting a full BOM — common in defense and aerospace — you can import a part list instead: the same parts with the structure (reference designators, placement, assembly topology) stripped out. A part list is inherently reverse-engineering-safe, so you get sourcing and qualification while never disclosing how the parts fit together.

Choose it when you upload: the intake page asks whether you are sending a BOM or a part list, and the choice travels with the analysis. In part-list mode the absent design fields are treated as expected rather than as gaps, and they are nulled in what we hand on rather than reconstructed.

06

Encryption and accessAT PRODUCTION

At production, your data is encrypted in transit and at rest (KMS envelope encryption as the baseline). For the most sensitivity-constrained clients we offer two stronger options: PGP encryption with your own key (so even we can’t read your stored file), or fully in-browser analysis (your raw BOM never leaves your machine — we receive only the normalized result). Access is least-privilege, and Tier-1 access is audit-logged.

07

Sovereign hosting for sensitive sectorsAT PRODUCTION

For clients with sovereignty requirements, Intake can be deployed on SecNumCloud-qualified sovereign infrastructure — S3NS (Thales × Google), operated in France by Thales — so your data stays under French jurisdiction. Intake’s import runs offline by design, which makes a zero-egress sovereign deployment a natural fit.

The SecNumCloud qualification is S3NS’s, not Adesio’s: Intake is not itself SecNumCloud-qualified. This deployment is available on request, and is not the current default hosting.

Adesio · Intake — the client-facing BOM front door.
Every measure on this page is marked with when it applies. Nothing here is a certification: Adesio holds no SOC 2, ISO 27001 or equivalent attestation today, and claims none. The SecNumCloud qualification referenced above is S3NS’s, not Adesio’s.