Section 5: Information Sharing & Data Management

This policy defines MetalCore Manufacturing’s standards for secure information exchange, document control, and data classification across internal teams, suppliers, and clients. Compliance ensures operational integrity, IP protection, and alignment with ISO 9001:2015 & AS9100D requirements.

Effective Date: January 15, 2025
Version: 4.2.1
Owner: Quality & Compliance Dept.
Classification: Internal / Confidential
📄
5.1 Document Control & Versioning

All technical documents, drawings, BOMs, and quality records must follow MetalCore’s standardized version control protocol. Uncontrolled copies are strictly prohibited on the shop floor.

  • Naming Convention: [ProjectID]_[DocType]_[Rev]_[Date].ext (e.g., AE-2045_Drawings_RevB_20250312.dwg)
  • Revision Tracking: Minor updates use alphabetical suffixes (A1, A2); major changes increment letters (A → B → C).
  • Approval Workflow: All external-facing documents require digital sign-off from Engineering & Quality Assurance before distribution.
  • Retention: Active projects: 5 years. Closed projects: 10 years. Archived in AWS S3-Compliant storage.
📌 Note: CAD files must be submitted in native format + PDF/STEP backup. IPT, SLDPRT, and STEP 214 are accepted.
🔒
5.2 Secure Transfer Protocols

MetalCore enforces encrypted, auditable data transfer channels. Standard email is not permitted for sensitive manufacturing data.

  • MetalCore Secure Portal: Primary channel for partners. Supports files up to 2GB. TLS 1.3 encryption.
  • SFTP Access: Available for high-volume/automated integrations. Credentials issued by IT Security after NDA execution.
  • Encrypted Email: Use for urgent < 10MB transfers. Attachments must be password-protected; passwords sent via separate channel (SMS/Signal).
  • Physical Media: USB/Hard drives require IT sanitization & logging. Must be tracked via Asset ID and signed chain-of-custody form.
⚠️ Compliance Notice: ITAR/EAR-controlled data must be routed through the Restricted Data Gateway. Unauthorized export attempts are monitored and reported.
🏷️
5.3 Data Classification & Access Control

All information is classified upon ingestion. Access rights are granted based on role, project assignment, and clearance level.

Public Internal Use Confidential Restricted / ITAR Quality Record
  • Role-Based Access (RBAC): Engineering, Quality, Production, and Management tiers with strict separation of duties.
  • Third-Party Access: Suppliers require signed NDA/MUA. Temporary portal links expire after 14 days or 3 downloads.
  • Audit Trails: All document views, edits, and downloads are logged with timestamp, user ID, and IP address.
🤝
5.4 Client & Supplier Communication Standards

Clear communication channels prevent manufacturing delays and ensure specification alignment.

  • Design Reviews: Conducted via Microsoft Teams (recorded) or secure webinars. Minutes distributed within 24 hours.
  • ECN/ECO Process: Engineering Change Orders require formal submission, impact analysis, and mutual approval before implementation.
  • Quality Feedback: NCRs, PPAPs, and FAIRs shared through the Supplier Portal within agreed SLAs.
  • Escalation Path: Program Manager → Quality Director → VP Operations. Response time: < 2 business hours for critical issues.
💡 Best Practice: Always reference the latest approved drawing revision in all correspondence. Unmarked emails will be flagged for clarification.
5.5 Partner Compliance Checklist

Before initiating information exchange, ensure the following requirements are met:

  • ☐ Executed MetalCore NDA / Mutual Non-Disclosure Agreement
  • ☐ Portal access request submitted via procurement portal
  • ☐ Document classification tags applied per Section 5.3
  • ☐ File naming convention validated
  • ☐ ITAR/EAR status declared (if applicable)
  • ☐ Primary & secondary points of contact registered

Incomplete submissions will be returned to the sender for correction. Turnaround for access provisioning: 1–2 business days.