ClaimHit
Security

How we protect your data

Patent intelligence is sensitive work. This page documents our security practices, infrastructure, data handling, and compliance roadmap so you can make an informed decision about using ClaimHit.

GDPR compliantTLS 1.2+ in transitAES-256 at restSOC 2 Type II, in preparationISO 27001, planned

Infrastructure

ClaimHit runs on managed cloud infrastructure. We do not operate our own servers; every provider maintains its own security certifications.

ProviderRoleAssurance
VercelApplication hosting and global CDNSOC 2 Type II, ISO 27001
SupabaseDatabase, authentication and storageSOC 2 Type II, GDPR DPA
Inference providersSeveral frontier-model providers, run in parallelSOC 2 Type II; zero data retention or no training on API calls. Names available on request.
Web search providersRetrieval of public product pagesReceive only claim-derived queries; zero retention where offered. Names available on request.
Stripe and PayU IndiaPayment processingPCI DSS Level 1
ResendTransactional emailSOC 2 Type II

Data security

How patent data is handled

Patent numbers are public information. When you enter a patent number, ClaimHit fetches the patent data from public patent office APIs and sends the claims to inference providers for analysis. Patent numbers and their published claim text are not confidential; they sit in public registries.

Inference providers do not retain your data. Every provider we use operates a zero-data-retention or no-training policy on API calls by default; the list is available to clients on request. We never send your account identity (name, email, company) to these providers. Searches are anonymous at the API level.

Your search history and results are stored in our database, accessible only to your account (or your team, if you are in a team workspace). We retain them for the life of your account to provide history and re-run features. When you delete your account, all search history is deleted within 30 days.

Your proposal requests, run-for-you lists and expert review requests contain more sensitive information: target names, case notes, budgets. This data is stored securely and accessible only to you and the ClaimHit team. It is retained for 7 years for legal and accounting purposes, consistent with standard professional services records requirements.

Documents you upload for a Hit Chart, such as a teardown or an internal specification, are permanently deleted within 24 hours, and we confirm the deletion by email. Only the extracted evidence stays in your chart.

Incident response

In the event of a data breach or security incident that affects your personal data:

To report a security vulnerability, email security@claimhit.com. We aim to acknowledge all reports within 48 hours.

Compliance roadmap

We are committed to meeting the security standards required by law firms, enterprise IP teams, and technology transfer offices.

Complete
GDPR compliance
Privacy policy, cookie consent, data subject rights, DPA with Supabase, data deletion capability. Completed April 2026.
Complete
TLS and encryption
All data encrypted in transit and at rest. Implemented at launch.
Complete
Row-level security
All database tables protected by RLS policies. Users can only access their own data.
In progress
SOC 2 Type II
Readiness and audit preparation in progress, covering the security, availability and confidentiality criteria. Target completion Q1 2027.
Planned
ISO 27001
Planned for European enterprise clients who prefer ISO 27001 over SOC 2. Target: 2027.
Planned
Penetration testing
Annual third-party penetration test planned for Q4 2026.

Security contact