Your patent data is protected by the strictest security standards
How Patenty protects your data
Neither Patenty nor third-party AI providers use your patent data for model training. Data is only used to deliver the requested services.
Row-Level Security (RLS) ensures complete data separation between users. No user can access another user's data.
All data is encrypted with TLS 1.3 during transmission and AES-256 at rest.
When a customer deletes data, it is immediately removed from the live database, including related files and metadata. Backup copies expire and are purged on their retention cycle.
We have achieved Cloud Security Alliance's Security, Trust, Assurance and Risk (STAR) program Level 1 certification.
All infrastructure partners including Vercel, Supabase, and Google Cloud hold global security certifications such as SOC 2 Type II and ISO 27001.
Trusted global security standards compliance
Vercel
SOC 2 Type II, GDPR, ISO 27001 Aligned
Supabase
SOC 2 Type II, HIPAA Eligible, GDPR
Google Vertex AI
ISO 27001, SOC 2, GDPR, FedRAMP
Mistral AI
SOC 2 Type II, GDPR
Customer data protection policies when using AI services
LLM providers use customer data only for providing Patenty services and do not use it for AI model training.
Sensitive customer patent data is processed primarily by Google Vertex AI and is not used to train models. Under Google's policy, prompts detected for potential abuse—and prompts and responses for features designated Advanced AI—may be retained for security review for up to 30 days. When value-tier economy AI generation is enabled, its OpenRouter route enforces Zero Data Retention per request. We describe the Google route as zero-retention only when a project-specific exception has been verified. Current subprocessors and retention terms are listed at /privacy/subprocessors.
Customer data is never used to train models. Our primary model, Google Vertex AI, does not use customer prompts or outputs to train its foundation models, per its public data governance policy.
Only email addresses are collected for authentication. No other personally identifiable information (PII) is collected.
Data is hosted on secure cloud infrastructure (Supabase - AWS-based).
Data is retained only while there is a business need or regulatory requirement, then securely deleted.
Actual security features based on CSA STAR Level 1 certification
Review Patenty's detailed security policy. For firms and enterprise customers evaluating adoption, we provide due-diligence documents — including a Data Processing Agreement (DPA) and security questionnaire (CAIQ) responses — upon NDA execution.