When engineering teams move product data and collaboration workflows to the cloud, one question inevitably comes up:
How secure is our data?
For organizations managing intellectual property, engineering designs and other sensitive information, cloud security is about much more than preventing unauthorized access. It also involves privacy, regulatory requirements, service availability, software quality and the responsible use of artificial intelligence.
Dassault Systèmes addresses these concerns through six areas highlighted in its Trust Center: Security, Regulatory Compliance, Quality, Privacy, Availability and Trusted AI.
These six pillars work together to create a broader framework for customer trust. At the same time, security in the cloud follows a shared responsibility model: Dassault Systèmes protects the platform and its underlying infrastructure, while customers remain responsible for how they configure and use the environment.
This article summarizes the key concepts discussed during our webinar on artificial intelligence, cloud computing and security on the 3DEXPERIENCE platform.
At a Glance: How Does 3DEXPERIENCE Approach Security?
The 3DEXPERIENCE platform’s cloud security approach combines security-by-design practices, vulnerability testing, incident response, privacy controls, quality management, resilient infrastructure and Trusted AI principles.
However, moving to the cloud doesn’t mean an organization can stop thinking about security.
Customers still need to manage their users, permissions, devices and data appropriately. Understanding where the provider’s responsibilities end, and where the customer’s responsibilities begin, is one of the most important parts of evaluating any cloud platform.
The Shared Responsibility Model
Before looking at the six pillars, it’s important to understand one fundamental concept: cloud security is a shared responsibility.
Dassault Systèmes’ Shared Responsibility Model defines the respective responsibilities of Dassault Systèmes and its customers for operational security and compliance.
Customer responsibilities include:
-
Customer data
-
Devices and endpoints
-
Identity and access management
Dassault Systèmes responsibilities include:
-
Applications
-
Operating systems
-
Virtualization
-
Physical resources such as compute, network and storage
-
Physical datacenters
In practical terms, Dassault Systèmes is responsible for protecting the cloud service and the infrastructure that supports it. The customer remains responsible for deciding who should have access to its data, assigning appropriate permissions and securing the devices used to connect to the platform.
This distinction is critical.
A highly secure cloud platform cannot prevent an organization from giving a user more access than they need or failing to remove a former employee’s access.
The 6 Pillars of 3DEXPERIENCE Trust
1. Security
Security is the first layer that most organizations think about when evaluating a cloud platform—and for good reason.
Dassault Systèmes describes its approach as security by design, meaning security requirements are integrated into the software development and operational lifecycle rather than being added after the fact.
The security program includes measures such as:
-
Secure software development practices
-
Continuous threat monitoring
-
Vulnerability management
-
Static and dynamic application security testing (SAST and DAST)
-
Software composition analysis
-
Penetration testing
-
A private bug bounty program
-
Incident response through the Dassault Systèmes Computer Security Incident Response Team (CSIRT)
The 3DEXPERIENCE platform on the cloud also has security certifications and assessments, including ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certifications.
The goal isn’t to rely on a single security mechanism, but to use multiple layers of protection throughout the platform lifecycle.
2. Regulatory Compliance
Security and compliance are closely related, but they aren’t the same thing.
Organizations operating in industries such as aerospace, automotive, life sciences, medical devices or other regulated environments may have specific requirements for how information is stored, processed and managed.
The Dassault Systèmes Trust Center provides information about applicable certifications, regulatory requirements and compliance programs. Current resources include information related to regulations such as the EU Data Act, NIS2, the Cyber Resilience Act and DORA.
However, there’s an important distinction:
A vendor’s certification does not automatically make a customer compliant.
Organizations still need to determine which requirements apply to their own industry, jurisdiction and processes, and then configure and use the platform accordingly.
The Trust Center is therefore an important resource for IT, security, legal, quality and compliance teams evaluating 3DEXPERIENCE.
3. Quality
Security isn’t the only factor that determines whether a cloud platform can be trusted.
Software quality, development practices and continuous improvement also play an important role.
Dassault Systèmes maintains a Quality Management System (QMS) designed to embed quality throughout the software development lifecycle. The QMS governing the 3DEXPERIENCE platform is certified to ISO 9001:2015 for activities including design, development, deployment, cloud operations and support.
For organizations operating in regulated environments, quality management can also support requirements around validation, traceability and controlled processes.
In other words, trust isn’t simply about keeping unauthorized users out. It’s also about having structured processes designed to deliver reliable software and continuously improve it.
4. Privacy
Security protects information from unauthorized access, while privacy focuses on how personal information is collected, processed and managed.
Dassault Systèmes maintains a Data Privacy Program that includes dedicated governance, employee training and technical and organizational measures. The 3DEXPERIENCE platform on the cloud is also certified to ISO/IEC 27701:2019 for privacy information management and ISO/IEC 27018:2019 for controls related to personally identifiable information in public cloud services.
Privacy requirements can vary depending on the type of information involved and the jurisdictions in which an organization operates.
For that reason, companies should consider questions such as:
-
What personal information is being processed?
-
Why is it being collected?
-
Who has access to it?
-
Where is it processed?
-
Which privacy regulations apply?
Understanding these questions is particularly important when engineering organizations collaborate with customers, suppliers or other external stakeholders.
5. Availability
Security is only useful if your team can access the platform when it needs to.
3DEXPERIENCE cloud availability relies on cloud operations, monitoring, resilient infrastructure and redundancy mechanisms designed to support service continuity. Dassault Systèmes also provides customers with access to cloud status and maintenance information through the Health Console.
The platform’s infrastructure is distributed across multiple geographic regions, with 3DEXPERIENCE data centers listed across the Americas, Europe and Asia-Pacific.
Availability is also another example of shared responsibility.
A cloud provider can maintain resilient infrastructure, but customers still need to consider their own internet connectivity, endpoint devices, authentication processes and internal business continuity procedures.
6. Trusted AI
Artificial intelligence introduces another dimension to the question of trust.
As AI becomes increasingly integrated into engineering and collaboration workflows, organizations need to understand not only what AI can do, but also how it is governed.
Dassault Systèmes’ Trusted AI approach is based on six principles:
-
Human supervision and control
-
Robustness, security and privacy
-
Intellectual property and data protection
-
Transparency and explainability
-
Inclusivity and equity
-
Sustainability
The emphasis on human supervision is particularly relevant for engineering.
AI can assist with tasks such as finding information, summarizing content, automating selected activities and supporting decision-making. However, users remain responsible for reviewing and validating the results appropriate to their use case.
Dassault Systèmes also publishes documentation describing the intended purpose of individual AI-based functionalities, providing greater transparency about how AI is incorporated into its solutions.
What about customer data and AI?
This is one of the most important questions organizations should ask when evaluating AI features.
Rather than making a blanket assumption about how customer information is handled, organizations should review the specific AI functionality, applicable contractual terms, data governance documentation and hosting environment involved.
Dassault Systèmes states that its AI capabilities are governed through privacy-by-design and security-by-design principles, with controls intended to protect confidentiality, integrity and intellectual property.
Because AI functionality and terms can evolve, reviewing the current documentation for the specific capability being deployed is the best way to evaluate how your organization’s data will be handled.
Why Does This Matter to Small and Mid-Sized Businesses?
Security can be particularly challenging for small and mid-sized organizations.
Maintaining an on-premises infrastructure requires resources for servers, operating system updates, security patches, backups, monitoring, access management and incident response.
Moving to a cloud platform doesn’t eliminate those responsibilities entirely, but it changes where they sit.
A cloud provider can take responsibility for a significant portion of the underlying infrastructure and operational security. The customer can then focus its resources on the areas it directly controls, such as:
-
User identities and permissions
-
Data governance
-
Endpoint security
-
Employee awareness
-
Internal procedures
-
Business continuity
This division of responsibility can be an important consideration when comparing cloud and on-premises environments.
10 Questions to Ask Before Adopting 3DEXPERIENCE Cloud
Before moving engineering data to the cloud, organizations should consider:
-
What types of data will be stored on the platform?
-
Who should be able to view, modify or share that data?
-
How will user roles and permissions be managed?
-
How will access be reviewed and removed when employees leave?
-
Are appropriate security measures enabled on user devices?
-
Which regulatory or certification requirements apply to our organization?
-
Where will our data be hosted and processed?
-
Which AI capabilities do we plan to use?
-
What contractual and data governance terms apply to those AI capabilities?
-
Have our IT, security, legal and quality teams reviewed the relevant Trust Center documentation?
These questions can help turn a general discussion about “cloud security” into a practical evaluation of your organization’s actual requirements.
Building Trust in Cloud-Based Engineering
3DEXPERIENCE security isn’t based on a single feature or certification.
It is the result of multiple technical, organizational and governance practices working together, from secure software development and vulnerability testing to privacy, quality management, resilient infrastructure and responsible AI.
Just as importantly, security is a shared responsibility.
The better question isn’t simply:
“Is the cloud secure?”
Instead, organizations should ask:
“What protections does the provider implement, what responsibilities remain with us, and how will we manage our data and users every day?”
Understanding those responsibilities is the first step toward making an informed decision about cloud-based engineering.
Want to evaluate how 3DEXPERIENCE could fit into your organization’s security, collaboration and data management requirements? Contact the Solidxperts team to discuss your environment and requirements.
















