Patentext, Inc.

Patentext, Inc.

Trust Center

Patentext is the IP platform for startups backed by Alchemist Accelerator.

We provide an AI-powered platform for IP workflows and patent prosecution.

None of the disclosure materials, documents generated, or documents exported are stored by third-party providers, outside of our cloud providers, or used in AI model training.

All data is stored and encrypted at-rest and in-transit using Google Cloud Platform infrastructure.

Patentext has zero data retention policies in place with its LLM providers.

Controls

Comprehensive overview of the security control frameworks we run — grouped by category so you can jump straight to the domain you care about.

Control Environment

  • Employee background checks performed

    The company conducts background screenings for all new hires.

Communication and Information

  • Data integrity maintained

    The company has implemented policies and procedures to safeguard electronic Protected Health Information (ePHI) against unauthorized alteration or destruction.

Risk Assessment

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

Control Activities

  • Documentation change control

    System documentation shall be subject to revision and change control procedures that maintain an audit trail documenting time-sequenced development and modifications.

  • Operational system checks

    Operational system checks shall be used, as appropriate, to enforce permitted sequencing of steps and events.

Logical and Physical Access Controls

  • Data transmission encrypted

    The company uses secure transmission protocols to encrypt confidential and sensitive data when it is transmitted over public networks.

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • System access limitation

    System access shall be restricted to authorized individuals.

  • Authority checks

    Authority checks shall restrict system use, electronic signing, access to operations or system input/output devices, record alteration, and performance of the operation at hand to authorized individuals.

  • Firewall access restricted

    The company limits privileged access to the firewall to authorized users who have a valid business need.

  • Data encryption utilized

    The company encrypts datastores containing sensitive customer data at rest.

  • Security patches installed within one month

    The company installs critical security patches within one month of their release, as determined by the risk ranking process defined in VPM-4.

  • Securely dispose of data

    The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.

  • Remote access encrypted enforced

    The company restricts remote access to production systems to authorized employees using an approved encrypted connection.

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Malicious software protection implemented

    The company has implemented procedures to guard against, detect, and report malicious software.

System Operations

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Vulnerability and system monitoring procedures established

    The company’s formal policies define requirements for the following IT and engineering functions: 1. Vulnerability management 2. System monitoring

  • Security vulnerabilities identification process exists

    The company maintains a process for identifying security vulnerabilities that includes: 1. Using reputable external sources to obtain current vulnerability information 2. Assigning risk rankings to identified vulnerabilities, clearly highlighting all high-risk and critical issues Risk rankings follow industry best practices and consider factors such as CVSS base scores, vendor classifications, and the affected system types. The risk assessment strategy ensures that all high-risk vulnerabilities are identified and that critical vulnerabilities, including those impacting public-facing systems, security infrastructure, or systems processing cardholder data, are addressed promptly.

  • Incident management procedures followed

    The company’s security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management in accordance with its security incident response policy and procedures.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

Change Management

  • Documentation change control

    System documentation shall be subject to revision and change control procedures that maintain an audit trail documenting time-sequenced development and modifications.

Risk Mitigation

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

Additional Criteria for Availability

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Production multi-availability zones established

    The company employs a multi-location strategy for production environments to enable operations to resume at alternate data centers if a facility becomes unavailable.

  • Database replication utilized

    The company’s databases are replicated in real time to a secondary data center, with alerts set up to notify administrators of any replication failures.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Environmental monitoring devices implemented

    The company uses environmental monitoring devices configured to automatically alert management in the event of environmental incidents.

Additional Criteria for Confidentiality

  • Data encryption utilized

    The company encrypts datastores containing sensitive customer data at rest.

  • Securely dispose of data

    The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.

Additional Criteria for Processing integrity

  • Establish and maintain a data management process

    The organization establishes and maintains a documented data management process that addresses, at a minimum: 1. Data sensitivity 2. Data owner 3. Data handling 4. Data retention limits 5. Data disposal requirements The organization aligns these elements with enterprise sensitivity and retention standards and reviews and updates the documentation annually or upon significant changes that could impact this control.

  • Operational system checks

    Operational system checks shall be used, as appropriate, to enforce permitted sequencing of steps and events.

  • Data integrity maintained

    The company has implemented policies and procedures to safeguard electronic Protected Health Information (ePHI) against unauthorized alteration or destruction.

  • Processing data inputs validated

    The company’s system evaluates data inputs for compliance with input requirements and generates on-screen alerts when issues with transaction inputs or processing are detected.

  • System validation

    Persons who use closed systems to create, modify, maintain, or transmit electronic records shall validate those systems for accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.

  • Customer data retained

    The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.

General Provisions of GDPR

  • Personal information policies and procedures established

    The company reviews and updates its policies and procedures as needed or when changes occur to ensure that personal information collected is: 1. Identified as either essential or optional 2. Collected with consent (implicit or explicit) in accordance with legal and regulatory requirements 3. Used in alignment with and limited to the purposes stated in the privacy notice

  • Legal personal information tracked

    The company logs, tracks, and maintains records of personal information disclosed for legal purposes in its designated tracking system for historical reference and audit purposes.

Rights of the Data Subject

  • Privacy information purpose communicated

    The company documents new purposes for previously collected information, notifies individuals of these new uses, obtains and records their consent or withdrawal, and ensures the information is used in line with the newly documented purpose.

  • Legal personal information tracked

    The company logs, tracks, and maintains records of personal information disclosed for legal purposes in its designated tracking system for historical reference and audit purposes.

  • PII controllers' obligations to inform third parties

    The company establishes a process, along with supporting policies and procedures, to notify sub-processors of any corrections, deletions, or withdrawals of personally identifiable information (PII).

  • Automated decision making

    The company identifies and fulfills its obligations to data subjects arising from decisions made through automated processing, where applicable, in accordance with relevant privacy and data protection requirements.

  • Data subject request handling is managed

    Mandatory: - Requests from data subjects are handled without undue delay - Procedures are established to support the controller in responding to data subject requests - Employees are trained to immediately notify the responsible contact upon receipt of a data subject request and to coordinate subsequent actions accordingly

  • Determining information for PII principals

    The organization identifies and documents the information that must be provided to individuals regarding the processing of their personally identifiable information, including when such information is to be provided.

  • Providing information to PII principals

    The organization provides individuals with clear and easily accessible information identifying the controller responsible for processing and explaining how their personally identifiable information is processed.

  • Providing mechanism to object to PII processing

    The organization establishes a mechanism that enables individuals to object to the processing of their personally identifiable information.

  • Providing copy of PII processed

    The organization is able to provide individuals, upon request, with a copy of the personally identifiable information that is processed.

Controller and Processor

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • Personal information policies and procedures established

    The company reviews and updates its policies and procedures as needed or when changes occur to ensure that personal information collected is: 1. Identified as either essential or optional 2. Collected with consent (implicit or explicit) in accordance with legal and regulatory requirements 3. Used in alignment with and limited to the purposes stated in the privacy notice

  • Additional breach information

    A business associate provides the company, acting as a covered entity, with any additional information required for individual notifications, either at the time of notification or as soon as the information becomes available.

  • Notification of breach

    The company, in its role as a covered entity, requires all business associates to notify it upon the discovery of any breach involving unsecured protected health information. A breach is considered discovered by the business associate on the first day it becomes known or should have been known through the exercise of reasonable diligence. The business associate is regarded as having knowledge of the breach if any individual, other than the one responsible for the breach, who is an employee, officer, or agent of the business associate, is aware of it, as defined under the Federal common law of agency.

  • Timeliness of breach notification

    Unless a delay is requested for law enforcement purposes, a business associate must provide the breach notification required under the company’s Breach Notification Policy, as specified in IRO-15, without unreasonable delay and no later than 60 calendar days from the date the breach is discovered.

  • Breach notice identification of individuals

    A business associate’s breach notification includes, to the extent possible, the identification of each individual whose unsecured protected health information was, or is reasonably believed to have been, accessed, acquired, used, or disclosed in connection with the breach.

  • PII minimization

    The company ensures that data collection and processing are limited to what is required to fulfill the purposes explicitly defined in its documented data processing activities, supporting compliance with data minimization requirements.

  • Records related to processing PII

    The company maintains all necessary privacy records to evidence compliance with applicable data protection laws and regulatory requirements.

  • Breach policy and procedure

    The company establishes documented policies and procedures for responding to data breaches, which include defined notification processes to ensure timely communication to relevant stakeholders.

  • Appoint Data Protection Officer

    A Data Protection Officer must be appointed if any of the following conditions apply: 1. The organization is a public authority or body 2. The core activities of the controller or processor involve processing operations that, due to their nature, scope, or purposes, require regular and systematic monitoring of data subjects on a large scale 3. The core activities of the controller or processor consist of large-scale processing of special categories of data or personal data relating to criminal convictions and offenses

  • Privacy and Impact Assessment

    To establish a privacy impact assessment process and to perform a privacy impact assessment as necessary.

  • Privacy Monitoring and Auditing

    To monitor and audit PII protection controls and the effectiveness of internal PII protection policy.

  • Regulatory and contractual protections for personal data

    Mandatory: - Legal and contractual information security requirements for processing personally identifiable data are identified - Requirements for complying with legal and contractual obligations for the protection of personally identifiable data are defined and communicated to responsible persons - Processes and procedures for protecting personally identifiable data are integrated into the information security management system

  • Data Protection Officer is appointed

    Mandatory: - A data protection officer is appointed where required under GOV-56 in GDPR - It is determined whether appointment of a data protection officer is mandatory or voluntary - Where no data protection officer is required, a data protection function or equivalent role is defined - Contact details of the data protection function are published - The data protection function is integrated into the organizational structure - The data protection status is documented and reported to top management - The data protection function is provided with sufficient capacity and resources - It is determined whether the data protection role is performed on a full-time or part-time basis - Adequate professional qualifications are ensured - Regular professional training is conducted - Access to relevant specialist literature is ensured - Data protection coordinators support the data protection function within organizational units, taking company size into account

  • Register of processing activities is created and maintained

    Mandatory: - Where legally required, a register of processing activities is maintained and kept up to date - Required technical and organizational measures for processing activities are implemented in accordance with information security requirements - Process or sequence descriptions with clearly defined responsibilities are established

  • Data subject request handling is managed

    Mandatory: - Requests from data subjects are handled without undue delay - Procedures are established to support the controller in responding to data subject requests - Employees are trained to immediately notify the responsible contact upon receipt of a data subject request and to coordinate subsequent actions accordingly

  • AI Compliance Integration

    Where a product incorporates an AI system and is subject both to the requirements of this Regulation and to the requirements of applicable Union harmonisation legislation, the provider shall be responsible for ensuring that the product complies in full with all applicable requirements under that Union harmonisation legislation. When ensuring that high-risk AI systems comply with the requirements set out in this Section, providers may, for the purpose of ensuring consistency, avoiding duplication, and minimising additional burdens, choose to integrate the relevant testing and reporting activities, as well as the information and documentation relating to the AI system, into existing documentation and procedures required under the applicable Union harmonisation legislation.

Transfers of personal data to third countries or international organisations

  • Identify basis for PII transfer between jurisdictions

    The company identifies and formally documents the legal basis for transferring personally identifiable information (PII) across jurisdictions in compliance with applicable data protection laws and regulations.

  • Contractual obligations are communicated to subcontractors and cooperation partners

    Mandatory: - Applicable contractual obligations to clients are passed on to subcontractors and cooperation partners - Compliance with contractual agreements is reviewed - Contact details for subcontractor contact persons are available and kept up to date

  • International data transfer process is defined

    Mandatory: - Transfers of data to third countries are identified and systematically documented - Documentation of third-country transfers is maintained, for example within the register of processing activities - Appropriate safeguards for international data transfers are in place in accordance with Chapter 5 of GDPR, including consideration of relevant court decisions and transfer impact assessments where applicable - It is determined whether consent from the responsible party is required for each transfer to a third country

Support

  • Customer data retained

    The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.

Performance evaluation

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • AI Compliance Integration

    Where a product incorporates an AI system and is subject both to the requirements of this Regulation and to the requirements of applicable Union harmonisation legislation, the provider shall be responsible for ensuring that the product complies in full with all applicable requirements under that Union harmonisation legislation. When ensuring that high-risk AI systems comply with the requirements set out in this Section, providers may, for the purpose of ensuring consistency, avoiding duplication, and minimising additional burdens, choose to integrate the relevant testing and reporting activities, as well as the information and documentation relating to the AI system, into existing documentation and procedures required under the applicable Union harmonisation legislation.

Organisational Controls

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Access requests required

    The company ensures that access to in-scope system components is based on job role and function or requires a documented access request and manager approval before access is granted.

  • Vulnerability and system monitoring procedures established

    The company’s formal policies define requirements for the following IT and engineering functions: 1. Vulnerability management 2. System monitoring

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Customer data retained

    The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.

  • Legal personal information tracked

    The company logs, tracks, and maintains records of personal information disclosed for legal purposes in its designated tracking system for historical reference and audit purposes.

  • Sanction policy applied

    The company enforces appropriate sanctions against workforce members who fail to comply with its security policies and procedures.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Contingency operations established

    The company has established procedures, to be implemented when needed, that allow facility access during emergencies in order to support data restoration as outlined in the disaster recovery and emergency mode operations plans.

  • PII minimization

    The company ensures that data collection and processing are limited to what is required to fulfill the purposes explicitly defined in its documented data processing activities, supporting compliance with data minimization requirements.

  • Retention of PII

    The company retains personally identifiable information (PII) only for the duration necessary to fulfill the purposes for which it was collected, in alignment with applicable data retention policies.

  • Breach policy and procedure

    The company establishes documented policies and procedures for responding to data breaches, which include defined notification processes to ensure timely communication to relevant stakeholders.

  • Intellectual property rights

    The organization implements appropriate procedures to safeguard intellectual property rights.

  • Identity management

    The organization manages identities throughout their entire lifecycle, from creation and use to modification and deactivation.

  • System access restricted to authorized access only

    The organization shall limit system access exclusively to authorized users, processes operating on behalf of authorized users, and approved devices, including interconnected systems.

  • Unique accounts, services, and processes are in use

    The organization shall identify system users, processes operating on behalf of users, and devices.

  • Including Information Security in the Business Continuity Management Process

    A managed program and process shall be developed and maintained for business continuity throughout the organization that addresses the information security requirements needed for the organization's business continuity.

  • AI Compliance Integration

    Where a product incorporates an AI system and is subject both to the requirements of this Regulation and to the requirements of applicable Union harmonisation legislation, the provider shall be responsible for ensuring that the product complies in full with all applicable requirements under that Union harmonisation legislation. When ensuring that high-risk AI systems comply with the requirements set out in this Section, providers may, for the purpose of ensuring consistency, avoiding duplication, and minimising additional burdens, choose to integrate the relevant testing and reporting activities, as well as the information and documentation relating to the AI system, into existing documentation and procedures required under the applicable Union harmonisation legislation.

  • System validation

    Persons who use closed systems to create, modify, maintain, or transmit electronic records shall validate those systems for accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.

People Controls

  • Employee background checks performed

    The company conducts background screenings for all new hires.

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • MDM system utilized

    The company uses a mobile device management (MDM) system to centrally manage mobile devices that support the service.

  • Sanction policy applied

    The company enforces appropriate sanctions against workforce members who fail to comply with its security policies and procedures.

Physical Controls

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • MDM system utilized

    The company uses a mobile device management (MDM) system to centrally manage mobile devices that support the service.

  • Environmental monitoring devices implemented

    The company uses environmental monitoring devices configured to automatically alert management in the event of environmental incidents.

  • Environmental security inspected

    The company conducts maintenance inspections of environmental security measures at its data centers at least once a year.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Application and data criticality analyzed

    The company assesses the relative criticality of specific applications and data to support the development and execution of other contingency plan components.

  • Maintenance records maintained

    The company has established policies and procedures to document all repairs and modifications to the physical components of its facilities that relate to security, including items such as hardware, walls, doors, and locks.

  • Equipment maintenance

    The organization ensures that equipment is properly maintained to support the availability, integrity, and confidentiality of information.

Technological Controls

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • MDM system utilized

    The company uses a mobile device management (MDM) system to centrally manage mobile devices that support the service.

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Database replication utilized

    The company’s databases are replicated in real time to a secondary data center, with alerts set up to notify administrators of any replication failures.

  • Production multi-availability zones established

    The company employs a multi-location strategy for production environments to enable operations to resume at alternate data centers if a facility becomes unavailable.

  • Customer transaction modifications restricted

    The company ensures that customer transaction data cannot be modified by either customers or administrators within the production application.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • System access restricted to authorized access only

    The organization shall limit system access exclusively to authorized users, processes operating on behalf of authorized users, and approved devices, including interconnected systems.

  • Multi-factor authentication (MFA) used for all admin access

    The organization shall require multi-factor authentication for both local and network access to privileged accounts, and for network access to non-privileged accounts.

  • AI Compliance Integration

    Where a product incorporates an AI system and is subject both to the requirements of this Regulation and to the requirements of applicable Union harmonisation legislation, the provider shall be responsible for ensuring that the product complies in full with all applicable requirements under that Union harmonisation legislation. When ensuring that high-risk AI systems comply with the requirements set out in this Section, providers may, for the purpose of ensuring consistency, avoiding duplication, and minimising additional burdens, choose to integrate the relevant testing and reporting activities, as well as the information and documentation relating to the AI system, into existing documentation and procedures required under the applicable Union harmonisation legislation.

  • System validation

    Persons who use closed systems to create, modify, maintain, or transmit electronic records shall validate those systems for accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.