Rights and contracts
Customer drawings and specs in manufacturing records: what to exclude
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Customer drawings, specifications, models and records that reproduce them should come out of a licensed manufacturing dataset, because build-to-print customers usually own that design information and bind suppliers through NDAs and purchase order terms. What often remains licensable is the shop's own operating history: machine logs, maintenance work orders, scheduling decisions and cycle times aggregated by part family.
Key takeaways
- In build-to-print work the customer typically owns drawings, specs and models, and PO terms usually limit their use to filling the order.
- Tooling paid for by the customer is often customer property along with its drawings; shop-designed fixtures may be the shop's.
- Blanking a title block does not make a drawing safe, because the geometry and tolerances are the protected information.
- CAM programs, inspection plans and CMM programs reproduce the design and are excluded; machine logs and maintenance records usually stay.
- Export-controlled and defense work is removed entirely rather than redacted.
Who owns the drawings and specs in a build-to-print shop?#
In a build-to-print shop, the customer typically owns the drawings, specifications and 3D models it sends, and the shop holds them only to make the parts ordered. Purchase order terms and conditions, NDAs and supply agreements usually say so directly and add a duty to keep the material confidential and use it for no other purpose.
Ownership gets less clear at the edges. Molds, dies and fixtures the customer paid for are often customer property along with their drawings, while fixtures the shop designed for its own efficiency may belong to the shop. In design-and-build or build-to-spec work, the contract decides whether the shop or the customer owns the design the shop developed.
Removing a customer's name changes none of this. The geometry, tolerances, material callouts and notes are the protected information, so a drawing with its title block blanked out is still the customer's drawing.
Exclusion checklist by system and record type#
The exclusion checklist works system by system, because each system stores customer design information in a different form. Default is the starting position before counsel reviews contracts; a record moves from review to keep only after identifiers are replaced and its free text has been checked.
| System | Record type | Default | Notes |
|---|---|---|---|
| ERP | Drawing, STEP and PDF attachments on parts and jobs | Exclude | Filter by attachment type and storage folder |
| ERP | Item master with customer part numbers and revisions | Replace | Swap for surrogate keys and part families |
| ERP | Routings and operation sequences | Review | Keep generic operations; strip notes quoting drawing callouts |
| ERP | Quotes and RFQ packages | Review | RFQ attachments out; estimator reasoning may stay after a scrub |
| CAM and DNC | CAM files and machine programs | Exclude | Programs encode the customer's geometry |
| QMS | First article and inspection reports | Exclude | Ballooned drawings and measured values reproduce the design |
| QMS | NCR and CAPA narratives | Review | Apply the customer and part identifier rule |
| Metrology | CMM programs and raw results | Exclude | Coordinates and tolerances map the part |
| Machine monitoring | Run time, alarms, downtime reasons | Usually keep | Remove job references that identify the customer |
| CMMS | Maintenance work orders and PM history | Usually keep | Describes your equipment, not the customer's design |
| Email and shared drives | Customer engineering correspondence | Exclude attachments; review text | Engineering change threads often quote specs |
Which contract terms should the survey cover?#
The contract survey starts with the documents that travel with every order, above all the customer's purchase order terms and conditions, which many shops accept without reading. These terms frequently claim ownership of all drawings, specifications, tooling and information the buyer furnishes, and restrict their use to performing the order.
Record the outcome per customer, not per document. One customer may have a narrow NDA and broad PO terms, and the stricter restriction is the one to plan around.
- NDAs signed at RFQ stage, including ones with prospects that never placed an order.
- Purchase order terms and conditions, including versions incorporated by a link printed on the PO.
- Supply agreements and long-term agreements with flow-down clauses.
- Tooling agreements that state who owns molds, dies and fixtures and their drawings.
- Quality agreements and supplier requirements manuals incorporated by reference.
- Prime contractor and government flow-downs, including export control and data rights legends.
Derived data: how much of the drawing does a record carry?#
Derived data is anything produced by working from the customer's drawing, and the test is how much of the design it carries. A CAM program or an inspection plan reproduces geometry and tolerances almost exactly, so it is treated as customer information. A spindle alarm log or a maintenance ticket on a lathe describes the shop's own equipment and carries almost none.
Some NDAs define confidential information to include anything derived from it. Where that language appears, even aggregated cycle times for that customer's parts deserve counsel's review before they go into scope.
| Data | How much of the design it carries | Typical treatment |
|---|---|---|
| CAM programs, CMM programs, inspection plans | High: geometry and tolerances | Exclude |
| Setup sheets and work instructions | Medium: dimensions, fixturing, critical features | Exclude, or rewrite as generic steps |
| Cycle times by part number | Low, but traceable to a part | Aggregate by part family or material |
| Scrap reasons and downtime codes | Low | Keep with part identity replaced |
| Machine sensor logs and alarms | Very low | Usually keep |
| Maintenance and calibration records | None | Usually keep |
Which shop records usually stay in scope?#
Shop records that describe your own equipment, people and decisions usually stay in scope once part identity is replaced. Machine alarm histories, downtime reasons, maintenance and calibration work orders, scheduling changes, material shortages and expedite decisions show how the plant actually runs, and they reveal little about any customer's design.
Aggregation widens that safe ground. Cycle times, scrap rates and setup durations grouped by part family, material or machine class keep their operational meaning while dropping the link to a specific drawing. Keep the grouping coarse enough that no group contains a single customer's part.
Export-controlled and defense work comes out entirely#
Export-controlled and defense work should leave the scope entirely rather than be redacted. Under the ITAR, technical data includes information required for the design, production, manufacture, repair or modification of defense articles, including blueprints, drawings, photographs, plans and instructions, which covers most of the job file for a defense part. SourceX excludes this work as a matter of policy.
Redaction does not solve the problem, because control turns on what the information is, not on whether it carries a customer name or a marking. Releasing ITAR technical data to a foreign person, even inside the United States, counts as an export, and a model developer's staff and contractors may include foreign persons. Markings, classification fields and flow-down clauses help find the work; they are not the test.
The practical step is segregation by program. If the ERP can filter jobs by customer, contract or an export classification field, use that filter to remove every related record, including NCRs, emails and machine logs tied to those jobs, before anyone reviews the rest.
Illustrative: an injection molder separates its record from its customers'#
Illustrative: a fictional custom injection molder runs an ERP for orders and scheduling, a QMS for inspections and complaints, and a press-monitoring system that logs cycles, alarms and downtime. Customers own most product designs and many of the molds in the building.
The general counsel's survey found that most customers' PO terms limited drawings and furnished information to use on the order, and one appliance maker's NDA covered anything derived from its information. The molder excluded all drawing attachments, mold drawings, first article reports and process sheets listing critical dimensions, and removed every record tied to the appliance maker.
What stayed was the plant's own operating history: press alarms and downtime reasons, mold maintenance work orders with mold numbers replaced, material changeover notes and scrap reasons by resin family. The package was narrower, but it described problems the molder solved itself.
How SourceX screens customer design information#
SourceX applies the customer IP screen inside the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery. Rights covers the contract survey customer by customer; Preparation removes attachments, programs and identifiers according to the exclusion list the supplier approved.
The SourceX Evidence Packet documents provenance for each record family, the licensing rights relied on, permitted use, the privacy record and the release authorization, so a later question from a customer can be answered from the file rather than from memory.
Frequently asked questions
Can we license designs for tooling and fixtures we built ourselves?
Possibly, if the shop designed and paid for them and no customer agreement assigns them to the customer. Tooling designed around a customer part still reflects that part's geometry, so counsel should check whether its drawings reveal the customer's design before including them.
What about parts we designed for a customer under a design services contract?
Ownership depends on the contract. Many design services agreements assign the resulting design to the customer on payment, while others let the shop keep rights in its general methods and know-how. Read the assignment and license-back clauses before treating any design as yours.
Can we include photos of parts taken on the shop floor?
Usually not by default. Photos show part geometry, markings and sometimes customer logos, and they are hard to screen at scale. Keep them out of the first package and revisit them only for parts that are clearly the shop's own products.
Do NDAs signed with prospects that never ordered still matter?
Yes. RFQ-stage NDAs often cover every drawing and specification the prospect sent, whether or not an order followed. Quote packages from those prospects should stay out unless counsel concludes the NDA has lapsed and nothing in it survives.
Do industry standards cited on a customer drawing make it public?
No. A drawing that cites public material or finish standards still combines them with the customer's own geometry, tolerances and notes, and that combination is the confidential part. Standards themselves are often licensed documents too, so copies stored on shared drives stay out of scope.
Sources
- 22 CFR 120.33(a)(1) defines ITAR technical data to include information, other than software, required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles, including information in the form of blueprints, drawings, photographs, plans, instructions or documentation. Source
- Under 22 CFR 120.50(a)(2), an export includes releasing or otherwise transferring technical data to a foreign person in the United States (a deemed export). Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.