Security & confidentiality

Built so your clients' inventions stay your clients' inventions.

We handle pre-filing invention material every day. This page is an overview of what data we touch and how we protect it. A more detailed document is available upon request.

Security overview · June 2026Subject to change as the product evolvessupport@patentdrawingai.com

The life of one drawing.

What happens to a file between upload and export, step by step.

01

Upload, privately

Your image goes straight into private storage. No public link is ever created for it.

02

Ownership checked

Every request is signed in and checked against who owns the project before any work runs.

03

Generation

An enterprise cloud AI provider generates the drawing under enterprise terms. The request carries only the image and the prompt. Your name, client, matter, and account never go with it.

04

Post-processing in-house

Cleanup and vectorization run on our own servers. Nothing else leaves our systems after generation.

05

Signed retrieval

The finished drawing stays in private storage, served only through short-lived signed links, checked on every request.

How your data stays protected.

What we send the AI provider, who can reach your data, and how it's encrypted.

AI handling

Your files never train AI

Uploads, prompts, and drawings are not used to train any model.

Nothing is kept after the request

The provider does not hold your image or prompt once the drawing is made.

Only the image and prompt are sent

No name, client, matter, account, or project goes with it.

Access

Signed-in requests only

Every request carries a signed token we check on our servers before anything runs.

Accounts stay separate

We isolate data in two places, the database and the application, so one account can't reach another's.

Encryption

In transit

All traffic uses TLS, from your browser to our servers and across our providers.

At rest

Your files and data are encrypted at rest, in both file storage and our database.

Download links

Files are served through signed links that expire and are checked on our servers. Raw storage links are never exposed.

A short vendor list, all attested.

Built on vetted, certified providers.

Everything that touches your data (AI, storage, database, and hosting) runs on providers with SOC 2 Type II, plus ISO certifications where they apply. We keep the vendor list short on purpose, and the full list is available on request.

Every provider in the path is independently attested.
Attestations in the path
SOC 2 TYPE IIISO 27001 (where applicable)

Your data leaves when you say so.

Retention is short, and deletion is real.

Drawings and uploads
Kept while your account is active, plus 30 days. Deleted within 30 days of a request.
Account data (projects, prompts, ledger)
Kept while your account is active, plus 30 days. Deleted within 30 days of a request.

Deletion starts with one email to support@patentdrawingai.com, and runs end to end, including our subprocessors.

For your security team

Doing a formal review? Just ask.

We can share a fuller security overview and the full subprocessor list on request. Email us and tell us what your review needs.