Your patent data is protected by the strictest security standards
How Patenty protects your data
Neither Patenty nor third-party AI providers use your patent data for model training. Data is only used to deliver the requested services.
Each account is isolated so one user cannot access another user's data.
All data is encrypted with TLS 1.3 during transmission and AES-256 at rest.
When a customer deletes data, it is immediately removed from the live database, including related files and metadata. Backup copies expire and are purged on their retention cycle.
We have achieved Cloud Security Alliance's Security, Trust, Assurance and Risk (STAR) program Level 1 certification.
Hosting, database, and AI-inference subprocessors hold third-party certifications such as SOC 2 Type II and ISO 27001. Vendor names are listed at /privacy/subprocessors.
Trusted global security standards compliance
Application hosting
SOC 2 Type II, GDPR, ISO 27001 Aligned
Database and authentication
SOC 2 Type II, HIPAA Eligible, GDPR
Managed AI inference
ISO 27001, SOC 2, GDPR, FedRAMP
Document extraction
SOC 2 Type II, GDPR
Customer data protection policies when using AI services
LLM providers use customer data only for providing Patenty services and do not use it for AI model training.
Sensitive customer patent data is processed through managed AI inference and is not used to train models. Inputs flagged for possible abuse may be retained for security review for up to 30 days. Some plans use a per-request no-retention path. We describe a path as zero-retention only when that path is confirmed. Current subprocessors and retention terms are listed at /privacy/subprocessors.
Customer data is never used to train models. The AI inference paths we use follow their published data-governance policies and do not use customer prompts or outputs to train foundation models.
Only email addresses are collected for authentication. No other personally identifiable information (PII) is collected.
Data is hosted on secure cloud infrastructure in the Seoul, South Korea region.
Data is retained only while there is a business need or regulatory requirement, then securely deleted.
Actual security features based on CSA STAR Level 1 certification
Review Patenty's detailed security policy. For firms and enterprise customers evaluating adoption, we provide due-diligence documents — including a Data Processing Agreement (DPA) and security questionnaire (CAIQ) responses — upon NDA execution.