How does Lightbringer ensure confidentiality in its service?
Lightbringer is contractually bound to keep every idea you submit confidential, never trains AI models on your data, and is SOC 2 Type II certified, audited annually by an independent third party.
Frequently asked questions
No. Lightbringer uses only pre-trained models — OpenAI's GPT, used with EU data residency and Zero Data Retention, and Google's Gemini via Google Cloud Platform (hosted in Finland). Your data is never used to train these models, and it isn't shared back to OpenAI or Google for their own training purposes.
Access follows the principle of least privilege — Lightbringer staff can only see what's necessary to provide the Service. Within your own organization, you control visibility through four roles: Inventor, Attorney, Moderator, and Primary Contact.
Yes — Lightbringer has been SOC 2 Type II certified since January 2025, audited annually by Insight Assurance. Contact us and we'll share the current report.
We follow a documented Incident Response Policy. Customer data is backed up every 12 hours and retained for a minimum of 7 days, and we can roll back or fully redeploy the service within 48 hours of a disaster event. We run disaster recovery drills annually to confirm this works.
Your core application data is stored on Microsoft Azure and PlanetScale (hosted on AWS, Frankfurt), with backups replicated to Google Cloud Platform, also in Frankfurt. When your data is processed by our AI providers, that happens via OpenAI (EU residency, Zero Data Retention) and Google Gemini via Google Cloud in Finland. Everything stays within the EU, and every infrastructure vendor we use must itself hold SOC 2 or ISO 27001 certification, plus GDPR compliance.
Yes. Lightbringer's role-based access lets you assign each team member as Inventor, Attorney, Moderator, or Primary Contact, so visibility into your inventions and documents matches their actual role.
No. Data sent to OpenAI is processed under a Zero Data Retention configuration with EU residency — it isn't stored once the request completes, and it's never used to train OpenAI's models. Data sent to Google's Gemini is likewise never used by Google to train its models. Both providers' own data-processing terms confirm this.
We've assessed that Lightbringer's use of AI doesn't fall into the Act's high-risk categories, so our core obligation is transparency: making clear when content is AI-generated. Beyond that, the safeguards the Act is built around (data governance, access control, audit logging, risk management) are the same ones already verified through our SOC 2 Type II certification, reinforced by the fact that we never train AI models on your data.