How we protect your data
Patent intelligence is sensitive work. This page documents our security practices, infrastructure, data handling, and compliance roadmap so you can make an informed decision about using ClaimHit.
Infrastructure
ClaimHit runs on managed cloud infrastructure. We do not operate our own servers; every provider maintains its own security certifications.
| Provider | Role | Assurance |
|---|---|---|
| Vercel | Application hosting and global CDN | SOC 2 Type II, ISO 27001 |
| Supabase | Database, authentication and storage | SOC 2 Type II, GDPR DPA |
| Inference providers | Several frontier-model providers, run in parallel | SOC 2 Type II; zero data retention or no training on API calls. Names available on request. |
| Web search providers | Retrieval of public product pages | Receive only claim-derived queries; zero retention where offered. Names available on request. |
| Stripe and PayU India | Payment processing | PCI DSS Level 1 |
| Resend | Transactional email | SOC 2 Type II |
Data security
- Encryption in transit. All data between your browser and ClaimHit is encrypted using TLS 1.2 or higher. HTTPS is enforced on every endpoint.
- Encryption at rest. All data stored in our database is encrypted at rest using AES-256. Backups are also encrypted. Passwords are hashed with bcrypt.
- Row-level security. Every database table uses row-level security policies. Users can only access their own data, and team members only their team’s data.
- Authentication. Handled by Supabase Auth with short-lived tokens, email and password sign-in, and a secure password reset flow.
- Environment isolation. Production and preview environments use separate keys, database credentials and secrets. Nothing is shared between them.
- Access control. Production database access is limited to authorised personnel, all access is logged, and every system follows the principle of least privilege.
How patent data is handled
Patent numbers are public information. When you enter a patent number, ClaimHit fetches the patent data from public patent office APIs and sends the claims to inference providers for analysis. Patent numbers and their published claim text are not confidential; they sit in public registries.
Inference providers do not retain your data. Every provider we use operates a zero-data-retention or no-training policy on API calls by default; the list is available to clients on request. We never send your account identity (name, email, company) to these providers. Searches are anonymous at the API level.
Your search history and results are stored in our database, accessible only to your account (or your team, if you are in a team workspace). We retain them for the life of your account to provide history and re-run features. When you delete your account, all search history is deleted within 30 days.
Your proposal requests, run-for-you lists and expert review requests contain more sensitive information: target names, case notes, budgets. This data is stored securely and accessible only to you and the ClaimHit team. It is retained for 7 years for legal and accounting purposes, consistent with standard professional services records requirements.
Documents you upload for a Hit Chart, such as a teardown or an internal specification, are permanently deleted within 24 hours, and we confirm the deletion by email. Only the extracted evidence stays in your chart.
Incident response
In the event of a data breach or security incident that affects your personal data:
- We assess the incident within 24 hours of discovery.
- We notify affected users by email within 72 hours if the breach poses a risk to their rights, in line with GDPR Article 33.
- We notify the relevant supervisory authority within 72 hours where required.
- We document every incident and our response in our internal security log.
To report a security vulnerability, email security@claimhit.com. We aim to acknowledge all reports within 48 hours.
Compliance roadmap
We are committed to meeting the security standards required by law firms, enterprise IP teams, and technology transfer offices.
Security contact
- Security: security@claimhit.com
- Privacy and data protection: privacy@claimhit.com
- General: contact page