News: Lightbringer raises $10 million in Series A funding
Data Security

Your inventions,

protected.

Lightbringer is SOC 2 Type II certified, GDPR compliant, and never uses customer invention data to train AI models. All data is encrypted in transit and at rest, and access is role-based by design.

Security certifications

SOC 2 Type II certification badge

Certified since Jan 2025, audited annually by Insight Assurance

ISO 27001 in progress badge

In progress, targeting 2026

Regulatory compliance

Assessed as limited-risk; transparency obligations met

GDPR compliant badge

GDPR compliant, continuously monitored via Vanta

Our commitments

‍Confidentiality by contract, not just policy

The moment you sign up, Lightbringer is contractually bound to protect what you submit: we treat your Confidential Information with the same care as our own, and we won't disclose it to third parties or use it for anything beyond providing and improving the Service, except where required by law. You retain all IP rights in what you submit and in any Patent Documents generated.

Encrypted everywhere

TLS 1.2–1.3 in transit, AES-256 at rest, encrypted company devices, MFA where available.

We do not train AI models on your data

Lightbringer uses pre-trained models only — OpenAI's GPT, used with EU data residency and Zero Data Retention (OpenAI does not store your data once a request completes), and Google's Gemini via Google Cloud Platform (hosted in Finland). Neither provider uses data passed through these services to train their models.

‍Access is yours to control

Role-based access lets you decide who inside your organisation sees what, on top of Lightbringer's own least-privilege internal access model.

How we protect your data

Zero trust architecture

Built on a Zero Trust model: micro-service segmentation (limits blast radius of any single breach), defense-in-depth (auth/authz checked continuously as data moves through the system), least-privilege access, continuous monitoring.

All third-party infrastructure vendors must themselves carry SOC 2 or ISO 27001, plus GDPR compliance, before Lightbringer will use them.

Your data is stored on Microsoft Azure and PlanetScale (hosted on AWS, Frankfurt), with backups replicated to Google Cloud Platform, also in Frankfurt — all within the EU.

Encryption and penetration testing

TLS 1.2–1.3 for data in transit; AES-256 for data at rest.

Independent penetration testing annualy, and vulnerability scanning (external assessment, e.g. Syneptic) continously, plus a periodical public HTTP Observatory scan of app.lightbringer.com .

Access control and authentication

Sign-in via Auth0/Okta (email + password), Google SSO, or Microsoft SSO.

Four-tier role model: Inventor (invention prep only), Attorney (invention prep + drafting), Moderator (full org/document access), Primary Contact (receives case/org notifications).

Internally, Lightbringer staff follow least-privilege access — people only see what their role requires.

AI & model confidentiality

No customer data is ever used to train OpenAI's or Google's models.

Uses only pre-trained third-party models (OpenAI GPT, with EU residency and Zero Data Retention; Google Gemini via GCP) — never fine-tuned or trained on your submissions.

Data sent to these models is not shared back for their training. Read more in Open AI Data Policy and/or Google Gemini Data Policy.

Development & training

Mandatory security training for all personnel.

Documented development guidelines; automated vulnerability scanning in CI; required automated tests and code review before any production deploy; database migration verification; deployments scheduled outside core European office hours.

Backup and disaster recovery

Documented incident response policy.

Customer data backed up every 12 hours, retained a minimum of 7 days.

Rollback or full service redeployment within 48 hours of a disaster event; disaster-recovery drills run annually.

Offices use fob-controlled entry, logged visitor access, no equipment left overnight, and lock automatically when unstaffed — though the Service itself keeps running with no dependency on physical office access.

Availability & continuity

Infrastructure is designed with redundancy and resilience: failover mechanisms and scalable resources keep performance steady under varying load.

Proactive monitoring and incident management identify and resolve disruptions quickly, minimizing downtime.

Backed by the concrete recovery commitments in panel (f) above — backup frequency, rollback window, and annual DR drills.

Accuracy & data integrity

Validation checks, quality assurance processes, and error detection/correction run throughout the data lifecycle.

Automated monitoring tracks and reports on processing activity, so discrepancies are caught and corrected promptly.

Transparent logging and audit trails allow a full review of data processing activity, confirming operations are carried out accurately — this is the "Processing Integrity" principle under SOC 2.

Compliance & certifications

  • SOC 2 Type II: Security, Availability, and Confidentiality — certified since January 2025, audited annually by Insight Assurance.
  • ISO 27001 — actively in progress, targeted for 2026.
  • GDPR — compliant. Read more: EU & UKData Processing Addendum (DPA)Privacy Policy
  • Continuous compliance monitoring via Vanta.
Last updated: 30/6 2026

How your data flows through the platform

01
Invention Preparation
You describe your idea; only your org's authorized users (per your role settings) can see it.
02
Patent Creation
AI drafts from your recorded idea. A Lightbringer patent attorney is connected to your case to produce and finalize the draft. They're identifiable within the platform and bound by our confidentiality terms.
03
Patent Management
The Lightbringer platform, together with a Lightbringer Product Specialist tracks filings and office actions; visibility again follows your organisation role settings.

Legal foundation

The moment you sign up, Lightbringer is contractually bound to protect what you submit: we treat what you share with the same care as our own confidential information, and we don't disclose it to third parties or use it for anything beyond providing and improving the Service — except where required by law.

You keep all intellectual property rights in what you submit and in every patent document the platform helps produce. Lightbringer doesn't claim ownership over your Confidential Information or your Patent Documents (Terms of Service, Section 6).

Lightbringer AB is registered in Malmö, Sweden, and is therefore bound by the GDPR and Swedish data protection legislation directly.

Frequently asked questions about data security

Do you use our data to train AI models?

No. Lightbringer uses only pre-trained models — OpenAI's GPT, used with EU data residency and Zero Data Retention, and Google's Gemini via Google Cloud Platform (hosted in Finland). Your data is never used to train these models, and it isn't shared back to OpenAI or Google for their own training purposes.

Who inside Lightbringer can see our inventions?

Access follows the principle of least privilege — Lightbringer staff can only see what's necessary to provide the Service. Within your own organization, you control visibility through four roles: Inventor, Attorney, Moderator, and Primary Contact.

Is Lightbringer SOC2 compliant? Can we see the report?

Yes — Lightbringer has been SOC 2 Type II certified since January 2025, audited annually by Insight Assurance. Contact us and we'll share the current report.

What happens to our data if there's a security incident?

We follow a documented Incident Response Policy. Customer data is backed up every 12 hours and retained for a minimum of 7 days, and we can roll back or fully redeploy the service within 48 hours of a disaster event. We run disaster recovery drills annually to confirm this works.

Where is our data physically stored?

Your core application data is stored on Microsoft Azure and PlanetScale (hosted on AWS, Frankfurt), with backups replicated to Google Cloud Platform, also in Frankfurt. When your data is processed by our AI providers, that happens via OpenAI (EU residency, Zero Data Retention) and Google Gemini via Google Cloud in Finland. Everything stays within the EU, and every infrastructure vendor we use must itself hold SOC 2 or ISO 27001 certification, plus GDPR compliance.

Can we control who on our team sees what?

Yes. Lightbringer's role-based access lets you assign each team member as Inventor, Attorney, Moderator, or Primary Contact, so visibility into your inventions and documents matches their actual role.

Does Lightbringer share our data with OpenAI or Google?

No. Data sent to OpenAI is processed under a Zero Data Retention configuration with EU residency — it isn't stored once the request completes, and it's never used to train OpenAI's models. Data sent to Google's Gemini is likewise never used by Google to train its models. Both providers' own data-processing terms confirm this.

How is Lightbringer compliant with the EU AI Act?

We've assessed that Lightbringer's use of AI doesn't fall into the Act's high-risk categories, so our core obligation is transparency: making clear when content is AI-generated. Beyond that, the safeguards the Act is built around (data governance, access control, audit logging, risk management) are the same ones already verified through our SOC 2 Type II certification, reinforced by the fact that we never train AI models on your data.

.1

Have a security questionnaire from your legal or procurement team? Send it over.