Skip to main content

Trust Center

Security you can verify, stated honestly.

IPELINT handles confidential patent application content and attorney work product. This page describes the controls we operate today, the testing behind them, and exactly where we are on the path to formal attestation. We separate what is implemented and verifiable from what is in progress — we would rather under-claim than overstate.

Compliance posture

Updated July 2026. Statuses below are exact — nothing is claimed ahead of evidence.

SOC 2 Type 1

In preparation

Full audit package prepared (system description, 29-control matrix mapped to CC1–CC9, signed policy set, evidence program). Auditor engagement is the next step; remaining infrastructure hardening items are tracked to closure before assertion.

SOC 2 Type II

Roadmap

Planned to follow the Type 1 report after an observation period. An independent penetration test is scheduled ahead of the Type II window.

Independent penetration test

Scheduled — not yet performed

A third-party penetration test with remediation tracking is planned before the SOC 2 Type II period. Today, penetration-style testing is performed by our internal security suite on every release (see Security testing below).

NIST 800-53 Rev 5 alignment

Internal mapping maintained

Internal mapping of 264 controls at the FedRAMP Moderate baseline, with implementation status tracked per control. A 3PAO has not been engaged.

Data residency

United States only

All processing and storage in US regions: AWS us-east-1 / us-east-2, MongoDB Atlas (US), Google BigQuery (US — public patent corpus only, no customer data).

Privacy program

Operating

GDPR-aligned data handling: data classification, retention schedule, PII redaction in logs, account deletion procedure, and a maintained public privacy policy.

Security testing

Every production release passes an internal security gate. An independent third-party penetration test is scheduled ahead of our SOC 2 Type II period — until that report exists, we don't describe our testing as externally validated.

Internal penetration test suite

Automated attack-simulation tests run against the application: authentication bypass, tenant-isolation escape, injection, privilege escalation, and rate-limit abuse scenarios. Part of the pre-production release gate.

Security regression suite

Dedicated security test suite covering authorization middleware chains, multi-tenant query scoping, API-key permission enforcement, and encryption round-trips, run before every production deployment.

Secret scanning

Repository-wide secret scanning (gitleaks) with a triaged baseline; findings block until reviewed.

Tenant-scope static analysis

Custom lint pass that verifies database queries are organization-scoped — fail-closed multi-tenant isolation checked at the code level, not just at runtime.

Dependency & supply chain

Locked dependency installs in CI (npm ci) with vulnerability audit gates; container images built from pinned bases and run as non-root.

Encryption verification

Scripted production verification that sensitive fields (including 2FA secrets) are encrypted at rest and that storage buckets deny public access.

Resilience drills

Documented disaster-recovery plan with RTO/RPO targets; database point-in-time-restore drills and incident-response tabletop exercises are part of the evidence program.

Platform controls

Encryption at rest

Application-level field encryption (AES-256-GCM) across ~30 sensitive data models under an AWS KMS customer-managed key, plus S3 server-side encryption and encrypted managed databases.

Encryption in transit

HTTPS-only with HSTS (1-year, preload) and TLS 1.2+ (TLS 1.3 supported).

Authentication

Clerk-managed identity with mandatory app-enforced two-factor authentication (TOTP or email) and per-request JWT verification.

Multi-tenant isolation

Organization-scoped data model with fail-closed query scoping and server-side ownership verification on every request.

API access

Partner API and MCP connector use per-workspace revocable API keys with granular permissions, optional IP allowlists, and per-key rate limits and quotas.

Audit logging

All state-changing requests and 70+ security event types logged to AWS CloudWatch with PII redaction and 365-day retention.

Least privilege

AWS access via SSO and instance roles — no static cloud credentials in the runtime path; separated development and production environments.

Incident response

Documented incident-response plan with defined roles, severity tiers, and customer notification commitments.

Subprocessors

Third parties that process or store data on IPELINT's behalf. All processing occurs in the United States. Customers are notified in advance before any new subprocessor begins processing customer data.

ProviderPurposeCustomer data exposure
Amazon Web Services Hosting, storage, key management, secrets, logging, AI inference (Bedrock)Yes — application data, documents, audit logs (US regions)
MongoDB Atlas Managed primary database and backupsYes — application data and metadata (US)
Clerk Identity and authenticationYes — user names, emails, auth factors (US)
Stripe Payment processingLimited — billing contacts and tokenized payment data only; no work product
Google Cloud (BigQuery) Analytics over the public patent corpusNo customer data — public corpus queries only
Pinecone decommissioningLegacy vector search, superseded by AWS-native storageRetained for rollback only; scheduled for closure

Documentation for evaluators

The following are available to prospective customers' security and IT teams under NDA. Email security@ipelint.com — we typically respond within one business day.

  • IPELINT Trust & Security Package (controls, implementation detail, and honest gap disclosure)
  • System description and SOC 2 control matrix (29 controls mapped to CC1–CC9)
  • Security testing summaries (internal penetration suite and security regression gates)
  • Information-security policy set, incident-response plan, and business-continuity/disaster-recovery plans
  • Subprocessor inventory with attestation status
  • Service-level agreement (SLA) with uptime targets and support tiers

Public policies: Privacy Policy · Terms of Service · Security Overview