Juristat | Trust Center
Juristat | Trust Center — Part 1

Security built for IP professionals.

Juristat is in compliance with security best practices, has implemented and is monitoring comprehensive controls, and maintains policies to outline its security procedures.

Juristat is SOC 2 Type II certified, hosted on AWS, and designed so your client data never enters our environment. Use this page to review our security posture, request documentation, and start your team's security review. Trusted by leading patent firms, Fortune 500 IP teams, and research universities worldwide.

For any questions, contact us at [email protected].

No client data transmitted
Only structured queries reach Juristat, not your questions, documents, or conversation history.
No AI model training
Your queries and data are never used to train any AI model. The MCP server is stateless.
Least-privilege access
Only vetted, onshore engineers have break-glass access, and only when required by your contract.

Certified, audited, and independently verified.

Juristat's compliance program is audited annually by independent third parties. Request documentation below to support your firm's security review.

Certifications

Juristat holds SOC 2 Type II certification and CSA STAR Level 1. Click either certification below to request the report or view our registry entry.

CSA STAR Level 1 Annual pentest Cyber insurance

Infrastructure

AWS US-East-1
All infrastructure and USPTO data hosted in the United States. No offshore data storage.
Encryption in transit & at rest
TLS for all data in motion. All stored data encrypted on enterprise-grade AWS infrastructure.
Customer data isolation
Your data is logically isolated from other customers. Independently audited annually.
SSO & MFA available
SSO available for a nominal infrastructure fee. MFA supported through your SSO provider.
Request SOC 2 Type II Report

Resources

SOC 2 Type 2

CSA Star Level One

Subprocessors

Auth0

Email addresses are used and stored for user authentication into the Juristat app; https://auth0.com/docs/secure/security-center

Data location: 10800 NE 8th St Suite 700, Bellevue, Washington, 98004, United States

Slack

Internal communication regarding user account creation and troubleshooting; https://slack.com/trust

Data location: 500 Howard Street San Francisco, CA 94105, United States

Intercom

Email addresses used for user identification/authentication, usage tracking, customer support, and customer notifications; https://trust.intercom.com/

Data location: 55 2nd Street, 4th Floor, San Francisco, CA 94105, United States

Pendo

Email addresses used for user identification/authentication, usage tracking, customer support, and customer notifications; https://trust.pendo.io/

Data location: 301 Hillsborough St., Suite 1900, Raleigh, NC 27603, United States

Mixpanel

Email addresses used for user identification/authentication, usage tracking, customer support, and error tracking; https://trust.mixpanel.com/

Data location: 1 Front St, 28th Floor, San Francisco, CA 94111, United States

Hex Technologies

Data warehouse for internal analysis and monitoring; https://trust.hex.tech/

Data location: 2261 Market Street #4233, San Francisco, CA 94114

LogRocket

Records and retains user sessions for up to 30 days to support customer service/support teams; https://logrocket.com/products/safety-security-performance

Data location: 87 Summer St Boston, MA, 87 Summer St Boston, MA 02110, United States

Amazon Web Services

Cloud storage of published and unpublished patent application data; https://aws.amazon.com/trust-center/

Data location: 410 Terry Avenue North, Seattle, Washington, 98109-5210, United States

Monitoring

Continuously monitored by Secureframe
View all
Juristat | Trust Center — Part 2

Data Security

No client data transmitted
Only structured queries reach Juristat, like an examiner ID or application number. Your question and context never leave your AI environment.
No AI model training
Juristat does not use customer queries, prompts, or data to train any AI model. The MCP server is stateless and retains no conversation data.
No privileged data exposure
Attorney-client privileged communications and work product are never transmitted to or stored by Juristat unless you explicitly upload them.
Read-only & stateless
Data Layer only reads patent data to answer your question. Prompts are cleared after each response. Nothing is retained between sessions.
Granular access control
MCP access can be enabled or disabled firm-wide or per user. No connection established unless a user explicitly initiates one.
SSO & MFA supported
Single sign-on is available for a nominal infrastructure fee. MFA is supported through your SSO provider.

FAQs


Does Juristat train AI models on my data?
No. Juristat does not use customer content, data, queries, or prompts to train any AI model. The MCP server is stateless — it processes each request independently and retains no conversation data.
When I access Juristat through Claude, Copilot, or ChatGPT, who processes my data?
Your chosen AI tool processes your conversation — not Juristat. The AI interprets your question locally and constructs a narrow, structured query (for example, an examiner ID lookup). Only that structured query is sent to Juristat's MCP server. Your original question, conversation history, and any other context never leave your AI environment.
What data does Juristat access through the Data Layer MCP?
The Data Layer MCP gives you access to the same Juristat patent data you can see when you log into the website. Your access is tied to your existing account permissions — nothing more, nothing less.
Could privileged communications or work product reach Juristat?
Only if you explicitly upload them. Juristat's MCP server does not pull in privileged materials, draft claims, or documents from your environment. Juristat isolates customer data and provides auditors with evidence of that isolation as part of its annual SOC 2 audit.
Is our organization's data kept separate from other customers?
Yes. Your data is logically isolated from all other customers. Insights or outputs derived from your data cannot affect another customer's experience. Customer isolation is independently audited as part of Juristat's SOC 2 Type II certification.
Where is data stored and processed — is anything offshore?
Juristat's infrastructure and all USPTO data are hosted in the United States on AWS US-East-1. Customer data processed by Juristat's MCP server — including tool call parameters and any logs — remain within US AWS regions.
What types of customer data does Juristat collect beyond patent data?
Juristat collects standard usage telemetry similar to most web platforms. We also maintain access audit logs as required by contract and applicable regulations. These logs may include user information (name and email), access timestamps, and records of specific activity.
Can we arrange a full security review?
Yes. Contact your Juristat account representative or reach out at [email protected] to arrange a security review tailored to your organization's requirements. Our security team typically responds within two business days.

Ready to start your security review?

Your account rep can walk through documentation and answer questions from your IT team.

Monitoring

Change Management

Baseline Configurations
Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.
Segregation of Environments
Development, staging, and production environments are segregated.
Configuration and Asset Management Policy
A Configuration and Asset Management Policy governs configurations for new sensitive systems
Secure Development Policy
A Secure Development Policy defines the requirements for secure software and system development and maintenance.
Change Management Policy
A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes.
Production Data Use is Restricted
Production data is not used in the development and testing environments, unless required for debugging customer issues.

Availability

Testing the Business Continuity and Disaster Recovery Plan
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Business Continuity and Disaster Recovery Plan based on the test results.
Business Continuity and Disaster Recovery Policy
Business Continuity and Disaster Recovery Policy governs required processes for restoring the service or supporting infrastructure after suffering a disaster or disruption.
High Availability Configuration
The system is configured for high availability to support continuous availability, when applicable.
Uptime and Availability Monitoring
System tools monitors for uptime and availability based on predetermined criteria.
Automated Backup Process
Full backups are performed and retained in accordance with the Business Continuity and Disaster Recovery Policy.

Organizational Management

Code of Conduct
A Code of Conduct outlines ethical expectations, behavior standards, and ramifications of noncompliance.
Internal Control Monitoring
A continuous monitoring solution monitors internal controls used in the achievement of service commitments and system requirements.
Acceptable Use Policy
An Acceptable Use Policy defines standards for appropriate and secure use of company hardware and electronic systems including storage media, communication tools and internet access.
Performance Reviews
Internal personnel are evaluated via a formal performance review at least annually
Information Security Program Review
Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually.
New Hire Screening
Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency to fulfill their responsibilities. New hires sign confidentiality agreements or equivalents upon hire.
Internal Control Policy
An Internal Control Policy identifies how a system of controls should be maintained to safeguard assets, promote operational efficiency, and encourage adherence to prescribed managerial policies.
Background Checks
Background checks or their equivalent are performed before or promptly after a new hires start date, as permitted by local laws.
Roles and Responsibilities
Information security roles and responsibilities are outlined for personnel responsible for the security, availability, and confidentiality of the system.
Disciplinary Action
Personnel who violate information security policies are subject to disciplinary action and such disciplinary action is clearly documented in one or more policies.
Information Security Policy
An Information Security Policy establishes the security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data.
Cybersecurity Insurance
Cybersecurity insurance has been procured to help minimize the financial impact of cybersecurity loss events.
Performance Review Policy
A Performance Review Policy provides personnel context and transparency into their performance and career development processes.
Organizational Chart
Management maintains a formal organizational chart to clearly identify positions of authority and the lines of communication, and publishes the organizational chart to internal personnel.

Confidentiality

Access to Customer Data is Restricted
Access to, erasure of, or destruction of customer data is restricted to personnel that need access based on the principle of least privilege.
Data Retention and Disposal Policy
A Data Retention and Disposal Policy specifies how customer data is to be retained and disposed of based on compliance requirements and contractual obligations.
Data Classification Policy
A Data Classification Policy details the security and handling protocols for sensitive data.

Vulnerability Management

Third-Party Penetration Test
A 3rd party is engaged to conduct a network and application penetration test of the production environment at least annually. Critical and high-risk findings are tracked through resolution.
Vulnerability and Patch Management Policy
A Vulnerability Management and Patch Management Policy outlines the processes to efficiently respond to identified vulnerabilities.

Incident Response

Incident Response Plan
An Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning and tracking confirmed incidents through to resolution.

Risk Assessment

Risk Register
A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy.
Vendor Risk Management Policy
A Vendor Risk Management Policy defines a framework for the onboarding and management of the vendor relationship lifecycle.
Risk Assessment and Treatment Policy
A Risk Assessment and Treatment Policy governs the process for conducting risk assessments to account for threats, vulnerabilities, likelihood, and impact with respect to assets, team members, customers, vendors, suppliers, and partners. Risk tolerance and strategies are also defined in the policy.

Network Security

Network Security Policy
A Network Security Policy identifies the requirements for protecting information and systems within and across networks.

Access Security

Encryption and Key Management Policy
An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls.
Asset Inventory
A list of system assets, components, and respective owners are maintained and reviewed at least annually
Administrative Access is Restricted
Administrative access to production infrastructure is restricted based on the principle of least privilege.
Access Control and Termination Policy
An Access Control and Termination Policy governs authentication and access to applicable systems, data, and networks.
User Access Reviews
System owners conduct scheduled user access reviews of production servers, databases, and applications to validate internal user access is commensurate with job responsibilities.
Least Privilege in Use
Users are provisioned access to systems based on principle of least privilege.
Removal of Access
Upon termination or when internal personnel no longer require access, system access is removed, as applicable.
Encryption-in-Transit
Service data transmitted over the internet is encrypted-in-transit.
Access to Product is Restricted
Non-console access to production infrastructure is restricted to users with a unique SSH key or access key
Unique Access IDs
Personnel are assigned unique IDs to access sensitive systems, networks, and information
Complex Passwords
Personnel are required to use strong, complex passwords and a second form of authentication to access sensitive systems, networks, and information

Physical Security

Physical Security Policy
A Physical Security Policy that details physical security requirements for the company facilities is in place.

Communications

Communication of Critical Information
Critical information is communicated to external parties, as applicable.
Privacy Policy
A Privacy Policy to both external users and internal personnel. This policy details the company's privacy commitments.
Confidential Reporting Channel
A confidential reporting channel is made available to internal personnel and external parties to report security and other identified concerns.
Communication of Security Commitments
Security commitments and expectations are communicated to both internal personnel and external users via the company's website.
Description of Services
Descriptions of the company's services and systems are available to both internal personnel and external users.