Juristat Trust Center
Juristat is in compliance with security best practices, has implemented and is monitoring comprehensive controls, and maintains policies to outline its security procedures.
For any questions, contact us at [email protected].
Learn More
Compliance

SOC 2 Type 2

CSA Star Level One
Monitoring
Continuously monitored by Secureframe
FAQs
Is Juristat SOC 2 certified?
Yes. Juristat holds SOC 2 Type II certification, which is the more rigorous, ongoing
certification (as opposed to a one-time assessment). Upon signing an NDA, Juristat's
security team will share the full audit report and any other reasonable supporting
evidence upon request.
Has Juristat undergone third-party penetration testing?
Yes. Juristat conducts at least one external penetration test per year. Relevant findings
and outcomes are documented in our SOC 2 Type II report.
Does Juristat support single sign-on (SSO) or multi-factor authentication (MFA)?
Yes. SSO is available to customers for a nominal fee to cover infrastructure and
maintenance costs. MFA is supported through your SSO provider.
What data does Juristat access, and what is included in the Data Layer MCP?
The Data Layer MCP gives you access to the same Juristat patent data you can already
see when you log into the website. Your access is tied to your existing account
permissions.
What types of customer data does Juristat collect beyond patent and prosecution data
(e.g., usage logs, search queries, user behavior)?
Juristat collects standard usage telemetry (similar to most web platforms). We also
maintain access audit logs as required by contract and applicable regulations. These logs
may include user information (name and email address), access timestamps, and records
of specific activity
Is my organization’s data kept separate from other customers' data?
Yes. Any non-publicly available data obtained from your organization is logically isolated
from all other customers. Insights or outputs derived from your data cannot affect
another customer's experience, and vice versa.
Where is customer data stored and processed in Juristat’s MCP service, and are any
subprocessors located outside of the United States?
Juristat’s infrastructure and all of its USPTO data are hosted in the United States on AWS,
US-East-1. Customer data processed by Juristat’s MCP server including tool call
parameters and any logs thereof, remain within US AWS regions.
Do you use customer data to train models?
Juristat does not use customer content, data, queries, or prompts to train AI models.
When I access Juristat’s data through my LLM (CoPilot, Claude, ChatGPT, Harvey, etc.),
who is processing my data?
Your LLM’s AI processes your data: not Juristat. When you query Juristat’s data through
one of your AI tools, the AI tool (e.g. CoPilot) processes your query to determine what
data is needed to respond. It then calls Juristat’s MCP tools to obtain that data, which is
then incorporated into your conversation with your LLM. The data you upload into a
conversation is governed by your agreement with your AI provider.
Who within Juristat can access user data on the Juristat platform, and how is access
controlled?
Access to customer data is tightly restricted. Only a limited number of vetted, onshore
engineers have "break-glass" emergency access, meaning they can only access customer
data when necessary for emergencies or to respond to a specific customer inquiry, as
outlined in your contract.
