Security

Built for material you can’t afford to leak.

Patent material is the most sensitive data in a technical company. The platform is designed end-to-end so a leak isn’t one incident away — engagement-scoped access controls, encryption, no training, full audit trail.

Practices

Five things, in order of how often they get asked about.

Engagement-scoped at the database layer

Every customer's source documents, parsed chunks, candidates, and IVAP outputs live in a workspace scoped to one engagement. Pipeline runs query their own engagement only. Postgres row-level security is enforced server-side on engagement-scoped tables. Company reference data — such as company names, sectors, funding stage, and the CPC codes captured at intake — is held in a shared corpus. Your engagement's confidential company profile is not: it sits on a separate, engagement-scoped table that no other customer can read.

Encryption at rest and in transit

All ingress is TLS 1.2+. Object storage (Supabase Storage) and the Postgres database are encrypted at rest with AES-256 keys managed by the cloud provider's KMS. We do not transmit customer documents over unencrypted channels at any point in the pipeline.

No model training on your material

Customer content is never used to train AI models — ours, our providers', or anyone downstream. Production agents call Anthropic under zero-data-retention agreements where available, with opt-out from any training corpus regardless. This commitment is in our customer agreement, not just a marketing promise.

Audit trail on every artifact

Every pipeline stage emits a structured event recording which engagement it ran for, when, and what it produced. Every prior-art reference carries a verification timestamp from a live USPTO or EPO call within the last 24 hours. The audit trail is exportable to your counsel on request.

Access controls

Application-level administrative access to production data is standing, not ticket-gated: a named, small set of operators can read production data at any time. That access is confidentiality-bounded and fully audited. Production runs on managed platforms (Railway, Supabase, Vercel) with dashboard access limited to named operators, scoped API tokens, and no shared accounts. All admin actions are logged and reviewed.

Compliance status

Where we are. Where we’re going.

SOC 2 Type II
Planned

Planned. We intend to begin a SOC 2 examination with an independent auditor after our Series A; the report timeline and availability will be published once the engagement is scheduled.

GDPR / CCPA
Honored

Customer rights described in the Privacy Policy apply globally; we honor data-subject requests from any jurisdiction within the law's response window or 30 days, whichever is shorter.

PII minimization
By design

We do not collect customer PII beyond what's needed to run the engagement (name, email, billing). We do not collect inventor PII for the inventorship attestation beyond what already appears in your documents.

Reporting a vulnerability

Found something?

We take vulnerability reports seriously and respond within one business day. Critical issues are triaged the same day. Please include reproduction steps, affected endpoints, and any relevant context. Good-faith research is welcome and protected from legal action.

Email hello@slingip.ai

For full data-handling specifics, see the Privacy Policy. For the legal terms covering security obligations, see Terms of Service.