Trust Center
Security you can verify,
stated honestly.
IPELINT handles confidential patent application content and attorney work product. This page describes the controls we operate today, the testing behind them, and exactly where we are on the path to formal attestation. We separate what is implemented and verifiable from what is in progress — we would rather under-claim than overstate.
Compliance posture
Updated July 2026. Statuses below are exact — nothing is claimed ahead of evidence.
SOC 2 Type 1
In preparation
Full audit package prepared (system description, 29-control matrix mapped to CC1–CC9, signed policy set, evidence program). Auditor engagement is the next step; remaining infrastructure hardening items are tracked to closure before assertion.
SOC 2 Type II
Roadmap
Planned to follow the Type 1 report after an observation period. An independent penetration test is scheduled ahead of the Type II window.
Independent penetration test
Scheduled — not yet performed
A third-party penetration test with remediation tracking is planned before the SOC 2 Type II period. Today, penetration-style testing is performed by our internal security suite on every release (see Security testing below).
NIST 800-53 Rev 5 alignment
Internal mapping maintained
Internal mapping of 264 controls at the FedRAMP Moderate baseline, with implementation status tracked per control. A 3PAO has not been engaged.
Data residency
United States only
All processing and storage in US regions: AWS us-east-1 / us-east-2, MongoDB Atlas (US), Google BigQuery (US — public patent corpus only, no customer data).
Privacy program
Operating
GDPR-aligned data handling: data classification, retention schedule, PII redaction in logs, account deletion procedure, and a maintained public privacy policy.
Security testing
Every production release passes an internal security gate. An independent third-party penetration test is scheduled ahead of our SOC 2 Type II period — until that report exists, we don't describe our testing as externally validated.
Internal penetration test suite
Automated attack-simulation tests run against the application: authentication bypass, tenant-isolation escape, injection, privilege escalation, and rate-limit abuse scenarios. Part of the pre-production release gate.
Security regression suite
Dedicated security test suite covering authorization middleware chains, multi-tenant query scoping, API-key permission enforcement, and encryption round-trips, run before every production deployment.
Secret scanning
Repository-wide secret scanning (gitleaks) with a triaged baseline; findings block until reviewed.
Tenant-scope static analysis
Custom lint pass that verifies database queries are organization-scoped — fail-closed multi-tenant isolation checked at the code level, not just at runtime.
Dependency & supply chain
Locked dependency installs in CI (npm ci) with vulnerability audit gates; container images built from pinned bases and run as non-root.
Encryption verification
Scripted production verification that sensitive fields (including 2FA secrets) are encrypted at rest and that storage buckets deny public access.
Resilience drills
Documented disaster-recovery plan with RTO/RPO targets; database point-in-time-restore drills and incident-response tabletop exercises are part of the evidence program.
Platform controls
Encryption at rest
Application-level field encryption (AES-256-GCM) across ~30 sensitive data models under an AWS KMS customer-managed key, plus S3 server-side encryption and encrypted managed databases.
Encryption in transit
HTTPS-only with HSTS (1-year, preload) and TLS 1.2+ (TLS 1.3 supported).
Authentication
Clerk-managed identity with mandatory app-enforced two-factor authentication (TOTP or email) and per-request JWT verification.
Multi-tenant isolation
Organization-scoped data model with fail-closed query scoping and server-side ownership verification on every request.
API access
Partner API and MCP connector use per-workspace revocable API keys with granular permissions, optional IP allowlists, and per-key rate limits and quotas.
Audit logging
All state-changing requests and 70+ security event types logged to AWS CloudWatch with PII redaction and 365-day retention.
Least privilege
AWS access via SSO and instance roles — no static cloud credentials in the runtime path; separated development and production environments.
Incident response
Documented incident-response plan with defined roles, severity tiers, and customer notification commitments.
Subprocessors
Third parties that process or store data on IPELINT's behalf. All processing occurs in the United States. Customers are notified in advance before any new subprocessor begins processing customer data.
| Provider | Purpose | Customer data exposure |
|---|---|---|
| Amazon Web Services | Hosting, storage, key management, secrets, logging, AI inference (Bedrock) | Yes — application data, documents, audit logs (US regions) |
| MongoDB Atlas | Managed primary database and backups | Yes — application data and metadata (US) |
| Clerk | Identity and authentication | Yes — user names, emails, auth factors (US) |
| Stripe | Payment processing | Limited — billing contacts and tokenized payment data only; no work product |
| Google Cloud (BigQuery) | Analytics over the public patent corpus | No customer data — public corpus queries only |
| Pinecone decommissioning | Legacy vector search, superseded by AWS-native storage | Retained for rollback only; scheduled for closure |
Documentation for evaluators
The following are available to prospective customers' security and IT teams under NDA. Email security@ipelint.com — we typically respond within one business day.
- IPELINT Trust & Security Package (controls, implementation detail, and honest gap disclosure)
- System description and SOC 2 control matrix (29 controls mapped to CC1–CC9)
- Security testing summaries (internal penetration suite and security regression gates)
- Information-security policy set, incident-response plan, and business-continuity/disaster-recovery plans
- Subprocessor inventory with attestation status
- Service-level agreement (SLA) with uptime targets and support tiers
Public policies: Privacy Policy · Terms of Service · Security Overview