Your inventions,
protected.
Lightbringer is SOC 2 Type II certified, GDPR compliant, and never uses customer invention data to train AI models. All data is encrypted in transit and at rest, and access is role-based by design.
Security certifications

Certified since Jan 2025, audited annually by Insight Assurance

In progress, targeting 2026
Regulatory compliance

Assessed as limited-risk; transparency obligations met

GDPR compliant, continuously monitored via Vanta
Our commitments
Confidentiality by contract, not just policy
The moment you sign up, Lightbringer is contractually bound to protect what you submit: we treat your Confidential Information with the same care as our own, and we won't disclose it to third parties or use it for anything beyond providing and improving the Service, except where required by law. You retain all IP rights in what you submit and in any Patent Documents generated.
Encrypted everywhere
TLS 1.2–1.3 in transit, AES-256 at rest, encrypted company devices, MFA where available.
We do not train AI models on your data
Lightbringer uses pre-trained models only — OpenAI's GPT, used with EU data residency and Zero Data Retention (OpenAI does not store your data once a request completes), and Google's Gemini via Google Cloud Platform (hosted in Finland). Neither provider uses data passed through these services to train their models.
Access is yours to control
Role-based access lets you decide who inside your organisation sees what, on top of Lightbringer's own least-privilege internal access model.
How we protect your data
Built on a Zero Trust model: micro-service segmentation (limits blast radius of any single breach), defense-in-depth (auth/authz checked continuously as data moves through the system), least-privilege access, continuous monitoring.
All third-party infrastructure vendors must themselves carry SOC 2 or ISO 27001, plus GDPR compliance, before Lightbringer will use them.
Your data is stored on Microsoft Azure and PlanetScale (hosted on AWS, Frankfurt), with backups replicated to Google Cloud Platform, also in Frankfurt — all within the EU.
TLS 1.2–1.3 for data in transit; AES-256 for data at rest.
Independent penetration testing annualy, and vulnerability scanning (external assessment, e.g. Syneptic) continously, plus a periodical public HTTP Observatory scan of app.lightbringer.com .
Sign-in via Auth0/Okta (email + password), Google SSO, or Microsoft SSO.
Four-tier role model: Inventor (invention prep only), Attorney (invention prep + drafting), Moderator (full org/document access), Primary Contact (receives case/org notifications).
Internally, Lightbringer staff follow least-privilege access — people only see what their role requires.
No customer data is ever used to train OpenAI's or Google's models.
Uses only pre-trained third-party models (OpenAI GPT, with EU residency and Zero Data Retention; Google Gemini via GCP) — never fine-tuned or trained on your submissions.
Data sent to these models is not shared back for their training. Read more in Open AI Data Policy and/or Google Gemini Data Policy.
Mandatory security training for all personnel.
Documented development guidelines; automated vulnerability scanning in CI; required automated tests and code review before any production deploy; database migration verification; deployments scheduled outside core European office hours.
Documented incident response policy.
Customer data backed up every 12 hours, retained a minimum of 7 days.
Rollback or full service redeployment within 48 hours of a disaster event; disaster-recovery drills run annually.
Offices use fob-controlled entry, logged visitor access, no equipment left overnight, and lock automatically when unstaffed — though the Service itself keeps running with no dependency on physical office access.
Infrastructure is designed with redundancy and resilience: failover mechanisms and scalable resources keep performance steady under varying load.
Proactive monitoring and incident management identify and resolve disruptions quickly, minimizing downtime.
Backed by the concrete recovery commitments in panel (f) above — backup frequency, rollback window, and annual DR drills.
Validation checks, quality assurance processes, and error detection/correction run throughout the data lifecycle.
Automated monitoring tracks and reports on processing activity, so discrepancies are caught and corrected promptly.
Transparent logging and audit trails allow a full review of data processing activity, confirming operations are carried out accurately — this is the "Processing Integrity" principle under SOC 2.
Compliance & certifications
- SOC 2 Type II: Security, Availability, and Confidentiality — certified since January 2025, audited annually by Insight Assurance.
- ISO 27001 — actively in progress, targeted for 2026.
- GDPR — compliant. Read more: EU & UKData Processing Addendum (DPA), Privacy Policy
- Continuous compliance monitoring via Vanta.
How your data flows through the platform
Invention Preparation
Patent Creation
Patent Management
Legal foundation
You keep all intellectual property rights in what you submit and in every patent document the platform helps produce. Lightbringer doesn't claim ownership over your Confidential Information or your Patent Documents (Terms of Service, Section 6).
Lightbringer AB is registered in Malmö, Sweden, and is therefore bound by the GDPR and Swedish data protection legislation directly.
Frequently asked questions about data security
No. Lightbringer uses only pre-trained models — OpenAI's GPT, used with EU data residency and Zero Data Retention, and Google's Gemini via Google Cloud Platform (hosted in Finland). Your data is never used to train these models, and it isn't shared back to OpenAI or Google for their own training purposes.
Access follows the principle of least privilege — Lightbringer staff can only see what's necessary to provide the Service. Within your own organization, you control visibility through four roles: Inventor, Attorney, Moderator, and Primary Contact.
Yes — Lightbringer has been SOC 2 Type II certified since January 2025, audited annually by Insight Assurance. Contact us and we'll share the current report.
We follow a documented Incident Response Policy. Customer data is backed up every 12 hours and retained for a minimum of 7 days, and we can roll back or fully redeploy the service within 48 hours of a disaster event. We run disaster recovery drills annually to confirm this works.
Your core application data is stored on Microsoft Azure and PlanetScale (hosted on AWS, Frankfurt), with backups replicated to Google Cloud Platform, also in Frankfurt. When your data is processed by our AI providers, that happens via OpenAI (EU residency, Zero Data Retention) and Google Gemini via Google Cloud in Finland. Everything stays within the EU, and every infrastructure vendor we use must itself hold SOC 2 or ISO 27001 certification, plus GDPR compliance.
Yes. Lightbringer's role-based access lets you assign each team member as Inventor, Attorney, Moderator, or Primary Contact, so visibility into your inventions and documents matches their actual role.
No. Data sent to OpenAI is processed under a Zero Data Retention configuration with EU residency — it isn't stored once the request completes, and it's never used to train OpenAI's models. Data sent to Google's Gemini is likewise never used by Google to train its models. Both providers' own data-processing terms confirm this.
We've assessed that Lightbringer's use of AI doesn't fall into the Act's high-risk categories, so our core obligation is transparency: making clear when content is AI-generated. Beyond that, the safeguards the Act is built around (data governance, access control, audit logging, risk management) are the same ones already verified through our SOC 2 Type II certification, reinforced by the fact that we never train AI models on your data.
Have a security questionnaire from your legal or procurement team? Send it over.
