Skip to content
IP Craft

Security

Built for privileged client work product

Patent work means privileged client information and deadlines you cannot miss. A law practice depends on three controls: each client's data kept apart, a record you can audit, and a human in charge of the AI. All three are built into how IP Craft works. None of them are left to policy.

Per-client data isolation

Each client organization is walled off from every other one. The wall sits in the database itself, not just in the app (row-level security, forced on every table). So one firm's matters cannot be seen by another. No query can reach across that line, even a buggy one.

Your data is not training data

We never train our models on your data. Your inventions and matters are used to do your work, and nothing else. You can export all of it at any time.

Append-only legal-truth record

Prosecution events and AI work products go into a record that can be added to but never rewritten (append-only). Who decided what, and when, is always preserved. That is what makes a record you can defend later.

Human approval on AI

AI never files, abandons, moves a statutory deadline, or changes what a claim covers — in either direction — on its own. Every AI work product is a proposal you, or your own counsel, review and approve. The judgment stays with the human who signs.

Encryption & transport security

Your data is encrypted both in transit (TLS) and at rest. Our email is signed and checked against spoofing (DKIM and DMARC). Secrets are held centrally and never written into code.

Least-privilege access

A dedicated identity provider handles sign-in. Everyone gets the least access their job needs. Live client data and our test systems run in separate AWS accounts, on separate clusters, so the two cannot mix.

Isolated, US-region infrastructure

IP Craft runs on its own isolated AWS infrastructure, in the United States. Automated guardrails keep the workloads inside approved accounts and regions.

A note on maturity. IP Craft is live and under active development. The protections above describe how the platform is architected today. Formal third-party attestations (e.g. SOC 2) are identified as roadmap items — we're glad to discuss our current posture in detail. Questions: hello@ipcraft.co.

Ready when you are

Start on your own — docketing and AI assistance are free, no card. Or talk to us about your security review.