What Type II actually proves
A security questionnaire tests what a vendor says. A SOC 2 Type I report tests whether controls are properly designed at a single point in time. Type II goes further. It examines whether those controls actually operated, continuously, over a sustained period: access control, encryption, monitoring, incident response, and vendor risk management, each tested against operating evidence from the full audit window.
To be candid about what that means: a report doesn’t make software secure by itself. What it verifies is that the controls we describe are the controls we run, and that an independent examiner found them operating without exception for three months. Our customers evaluate evidence for a living. This is the kind they can act on.
Why it matters for patent data
The material our customers run through the engine includes invention disclosures, draft claims, and competitive analysis: some of the most sensitive data a company holds. That’s why the same discipline applies across everything we build. No training on customer data, zero data retention with our LLM providers, and now independent assurance that the controls behind those promises hold up in operation.
SOC 2 Type II sits alongside our ISO 27001:2022 certification: the same security program, examined two ways.
Getting the report
We use Vanta for continuous control monitoring, and Advantage Partners conducted the examination. The full report is available to customers and prospective customers under NDA. Ask your account team, or request it through our Trust Center.



.png)







.webp)



