Critical Windchill and FlexPLM Security Notice

Critical new security patches are now available. Customers are urged to apply the patches immediately.

Learn More

PTC Trust Center

Overview Cybersecurity Advisory Center Compliance Privacy
Contact Us

Trust, transparency, and PTC


Stemming from PTC’s commitment to sharing the information our customers and partners need to be confident in doing business with us, our Trust Center exists as a hub for information on our compliance with all laws and regulations that apply to our business as well as a resource to learn more about how we protect data entrusted to us. Whether you’re a longstanding customer or brand new to PTC, we aim to balance transparency with the security of our operations and strive to disclose any information your organization needs for due diligence activities. Let's work together to create a safer, more secure, and resilient digital environment for everyone.

Responsible AI at PTC

We pride ourselves on leveraging technological innovations to help us work smarter and give our customers more Power To Create, but we also recognize that there is a careful balance to be maintained between the risks and benefits of adopting new technology.

With the rapid advancement of Artificial Intelligence (AI), finding this balance has never been more critical.

PTC’s AI Governance Council, AI@PTC, was formed to assess the risks and benefits that AI presents to PTC and to create processes that enable the responsible use of AI@PTC.

AI@PTC has identified transparency as a core principle to guide PTC’s responsible use of AI. This means that PTC knows:

  • How AI is used in our business operations and development processes
  • What data is made available to AI and how is it processed
  • Where AI is used in our products, for which we will follow the 4 NIST Principles of Explainable AI

Equipped with this information, PTC can ensure that all supporting business processes account for the impact of AI, including Vendor Risk Management, IT Security, Data Privacy, Secure Software Development, and Compliance. PTC will continuously adapt its operations to the AI technology and regulatory landscape as it evolves to maintain this commitment to Responsible AI.

AI features in PTC products

Learn more about how PTC’s AI Features protect your data, comply with applicable laws, and interact with third-party models.

What are AI Features in PTC products?

AI Features in PTC's licensed products and services include engineered or machine-based systems that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments. AI Features are designed to help to:

  • Advise – e.g., provide instant access to knowledge;
  • Assist – e.g., support users by completing steps within workflows; and
  • Automate – e.g., execute entire workflows.

Does PTC comply with applicable laws and regulations governing AI?

Yes. PTC has implemented measures reasonably designed to support compliance with applicable laws and regulations relevant to its AI features. PTC maintains a documented AI governance and risk management program informed by the NIST AI Risk Management Framework (RMF) key principles for trustworthy AI, including principles relating to fairness, bias, security, and safety.

Does PTC use customer data to train AI models?

No. PTC does not use customer data to train any AI models without the customer's express prior written consent. PTC's large language model providers also do not use customer data to train their AI models.

Does PTC commingle customer data with other customers’ or PTC's data?

No. PTC's AI Features do not commingle customer data with data from other customers or with PTC's internal data. Customer Data is logically isolated in per-tenant environments.

Is customer data exposed to publicly available or “open” AI models?

AI Features in PTC’s products do not expose customer data to publicly available or "open" third-party AI models. Where PTC integrates third-party foundational models (e.g., Azure OpenAI), these are accessed through secure, enterprise-grade API connections within PTC's controlled environment.

May PTC use anonymized/aggregated usage data to improve services?

Yes. PTC may collect and use anonymized, aggregated or de-identified technical usage data, telemetry, logs, metrics and metadata to operate, maintain, secure and improve services and AI features. Such usage data does not identify any customer or individual and does not expose customer data.

What third-party AI models are integrated into PTC products?

Certain PTC AI Features are powered by pre-trained large language models (LLMs) hosted on Microsoft Azure OpenAI. PTC integrates these models into its products through secure, enterprise-grade API connections within PTC's controlled environment.

PTC retains the right to add, remove, or substitute third-party AI models, including in response to changes in law, regulatory guidance, contractual obligations, or technical feasibility.

Does PTC modify or host the underlying GPAI model?

No. PTC does not develop, train, fine-tune, modify, or host the underlying GPAI model. In the cases where an AI Feature is powered by a third-party LLM, PTC integrates the model via API and acts as a deployer of the GPAI model.

How are PTC's AI Features classified under the EU AI Act?

To the extent PTC products fall within the broad definition of "AI system," they qualify as "certain AI systems" (limited risk). PTC's AI Features do not fall within the scope of high-risk AI systems as defined in the EU AI Act (Regulation (EU) 2024/1689).

Customers' own downstream applications (i.e., what they build or deploy using PTC's tools) may independently fall under high-risk categories under the AI Act. Such classification obligations are the customer's responsibility.

What is PTC's role under the EU AI Act: provider or deployer?

PTC operates in a dual role depending on the nature of the AI Feature:

Role When it applies
Provider of certain AI systems (limited risk) When PTC develops proprietary AI features using its own algorithms
Deployer of General-Purpose AI (GPAI) models When PTC integrates third-party large language models (e.g., Azure OpenAI) into its products via API

As a deployer, PTC does not develop, fine-tune, or modify the underlying foundational model beyond the threshold that would trigger reclassification as a GPAI model provider under the European Commission's Guidelines.

PTC’s proactive approach to cybersecurity

Want to learn more? PTC’s Cybersecurity Whitepaper is a comprehensive resource that covers topics such as PTC’s corporate security approach, our commitment to training and awareness, our processes and incident response policy, and our shared responsibility with customers and partners to develop and maintain secure, defensible, and resilient systems.

Read the White Paper

Cybersecurity

Taking a holistic, multi-layered approach to cybersecurity and privacy, PTC is committed to securing every entry point under its control against attack. In today’s globally interconnected world, cybersecurity is a team effort, and we work together to empower our suppliers and customers who are making sure updates are applied, devices are protected, and credentials are kept secure.

Below you’ll find more information on how PTC ensures the security of your data along with information on best practices for implementing the local security that will ensure every potential attack surface is considered and secured.

PTC cloud security

PTC cloud security

Learn how PTC Cloud handles hosted data for our core products. Learn More
Onshape security

Onshape security

Learn how Onshape handles CAD and related data through our global design service. Learn More
Arena security

Arena security

Learn how Arena handles PLM and QMS data through our SaaS services. Learn More
ServiceMax security

ServiceMax security

Learn how ServiceMax, a PTC Technology, securely handles service data. Learn More

Certificates and accreditations

To efficiently demonstrate our security posture and the quality of our operations, PTC focuses on achieving industry-standard certifications and attestation reports. Please review the options below to find the assessment frameworks most relevant to your business and your relationship with PTC.

Advisory center

PTC is committed to promptly providing the information you need to keep your PTC product installations secure.

Visit this page to learn about remediations for vulnerabilities that have impacted PTC products.

Learn More

Coordinated vulnerability disclosure program

PTC values the work of the global cybersecurity community in discovering software vulnerabilities before they can be exploited by malicious actors. Visit this page to learn more about how to securely report a potential vulnerability identified in a PTC product.

Learn More

Code of Business Conduct and Ethics

A cornerstone of the PTC ethics and compliance program is the PTC Code of Business Conduct and Ethics. Leading in all we do means that how we accomplish our goals matters. Read our code to learn more about PTC’s commitment to conducting business ethically and inclusively.

Compliance

PTC believes a fundamental ingredient of business success is that PTC and all personnel consistently conduct themselves with integrity and in accordance with the law.  To promote these principles, PTC maintains an extensive compliance program built on governance and awareness.

Anti-corruption

PTC does not permit or condone bribes, kickbacks or any other illegal or improper payments, transfers or receipts. Review our policy to understand how PTC ensures compliance.

Controlled data handling

PTC carefully protects the sensitive information it receives. Review this policy to understand PTC’s ITAR and export-controlled data handling procedures.

Export control classification

This document lists the Export Control Classification Numbers ("ECCN") under the U.S. Export Administration Regulations (the "EAR") relating to PTC products.

Corporate social responsibility

Visit PTC’s Corporate Social Responsibility (CSR) page to read our annual report and learn more about PTC’s values and programs.

Section 508 Accessibility

Review the available Voluntary Product Accessibility Templates (VPATs) detailing Section 508 compliance for individual PTC products.

Privacy

PTC considers the protection of personal information as a fundamental human right. That’s why we’ve developed and implemented a global privacy program to safeguard personal information through sound policies and procedures that place appropriate controls on personal information processing. Review our privacy policy to learn everything you need to know about how we securely handle your personal information.

You can also visit the Onshape, Arena, and codebeamer privacy pages for more information.

Privacy Policy