This Security Exhibit outlines the technical and organizational measures maintained by PatentFile, LLC for the PatentDash.ai platform (the “Service”). These standards are designed to protect Client Data and ensure the integrity, availability, and confidentiality of all intellectual property processed within the Service.
1. Enterprise Infrastructure
The Service is deployed within a high-security production environment that maintains SOC 2 Type II and ISO 27001 certifications. By leveraging a sovereign architectural design, PatentDash ensures the following:
Physical Security
Data is housed in Tier-III (or higher) data centers featuring 24/7 onsite security personnel, biometric access controls, and full-spectrum environmental redundancies (power, cooling, and fire suppression).
High Availability
The architecture utilizes multi-zone geographic redundancy, ensuring that the Service remains resilient and available even in the event of localized infrastructure failures.
2. Advanced Data Encryption
PatentDash enforces rigorous encryption standards to safeguard sensitive legal work-product at every stage:
In-Transit
All communications between the Client and PatentDash are secured using TLS 1.3 or higher. We utilize strong cipher suites to prevent interception or “man-in-the-middle” attacks.
At-Rest
All Client Data, including patent drafts, claims, and associated metadata, is encrypted at rest using AES-256 (Advanced Encryption Standard).
Cryptographic Isolation
Encryption keys are managed through a centralized, hardware-backed security module with strict access rotation policies to ensure data remains siloed and protected.
3. Identity and Access Management (IAM)
Access to PatentDash is governed by a “Zero Trust” framework and the principle of Least Privilege:
Enhanced Authentication
The Service supports enterprise-grade Single Sign-On (SSO) and Multi-Factor Authentication (MFA), ensuring that only verified users can access sensitive Client environments.
Granular Authorization
PatentDash utilizes Role-Based Access Control (RBAC) to strictly define user permissions, preventing unauthorized internal lateral movement.
Administrative Oversight
Personnel access to production environments is strictly limited to authorized senior engineers, requires justified business intent, and is subject to full audit logging.
4. Continuous Threat Mitigation
PatentDash employs a proactive security posture to identify and neutralize threats before they impact the Service:
24/7 Monitoring
We maintain continuous visibility into infrastructure and application-level logs to detect and respond to anomalous activity in real-time.
Automated Security Scanning
Our development pipeline includes regular automated vulnerability assessments to identify and remediate potential security gaps in the application logic.
Incident Response
PatentFile, LLC maintains a formal incident response plan designed to ensure rapid containment and transparent communication in the event of a suspected security threshold breach.
5. Legal Compliance and Auditability
Designed for the specific needs of intellectual property professionals, PatentDash aligns with high-stakes confidentiality requirements:
Comprehensive Audit Trails
The Service maintains immutable logs of user activity and system changes, retained for a minimum of 90 days to support internal compliance reviews.
Professional Responsibility Alignment
Our security controls are specifically engineered to support the preservation of attorney-client privilege and the work-product doctrine as required by global patent offices and professional responsibility standards.