Security Notice
Last Updated: July 16, 2026
This Security Notice summarizes how Keyora, Inc. (“Keyora”, “we” or “us”) will make sure your data is secure when you use Patented, our AI-enabled application that generates complete patent applications from user-provided invention disclosures or our other applications, products, services, tools and features, or otherwise interact with us (collectively, the “Services”). Please note that the Services are designed for users in the United States only and are not intended for users located outside the United States.
The computing services utilized to offer the Services are cloud-based and provided to Keyora by one or more cloud service providers and represent our “Cloud Environment.”
“Customer” refers to an entity that has entered into an agreement with Keyora for Keyora’s Services.
“Customer Data” refers to any inputs, outputs, or other content that the Customer or its users upload to or download from the Services.
1. AUDITS AND CERTIFICATIONS
The information security management system used to provide the Services shall be assessed by independent third-party auditors as described in the following audits and certifications (“Third-Party Audits”) on not less than an annual basis:
SOC 2 Type II
ISO 27001
Third-Party Audits are made available to you as described in Section 8.
To the extent that Keyora decides to discontinue a Third-Party Audit, Keyora will adopt an equivalent, industry-recognized framework.
2. HOSTING LOCATION OF CUSTOMER DATA
Customer Data hosted or processed by Keyora or its vendors will located within the region(s) specified in the applicable agreement between Keyora and the Customer.
3. ENCRYPTION
Keyora encrypts Customer Data at-rest using AES 256-bit (or better) encryption. Keyora uses Transport Layer Security 1.2 (or better) for Customer Data in-transit. With respect to encryption keys, we regularly rotate encryption keys and utilize hardware security modules to safeguard critical security keys. Keyora logically separates encryption keys from Customer Data.
4. SYSTEM AND NETWORK SECURITY
4.1 Keyora Personnel
Keyora personnel access our Cloud Environment with a unique user ID consistent with the principle of least privilege. Access requires a secure connection, multi-factor authentication, and passwords meeting or exceeding reasonable length and complexity requirements. When accessing our Cloud Environment, Keyora personnel use laptops with security controls that include encryption and that also include endpoint detection and response tools to monitor and alert for suspicious activities and malicious code and vulnerability management as described in Section 4.2. Keyora personnel will not access Customer Data except (a) to provide or support the Service or (b) to comply with the law or a binding order of a governmental body
4.2 Cloud Environment Security
Keyora shall protect its Cloud Environment using at least industry standard firewall and security practices. Keyora’s Cloud Environment leverages industry-standard threat detection tools with daily signature updates, which are used to monitor and alert for suspicious activities, potential malware, viruses and/or malicious computer code (collectively, “Malicious Code”). Keyora does not monitor Customer Data for Malicious Code.
4.3 Penetration Testing
Keyora engages an independent third party to conduct penetration tests of the Service at least annually. Summary results of such penetration tests can be made available to you as described in Section 8 at your request.
4.4 Vulnerability Remediation
Vulnerabilities that meet defined risk criteria are promptly flagged and prioritized for remediation based on their potential impact on the Service. Upon discovery, Keyora will use commercially reasonable efforts to remediate:
Critical vulnerabilities within 24-72 hours;
High-severity vulnerabilities within 7-14 days;
Medium-severity vulnerabilities within 30-60 days; and
Low-severity vulnerabilities within 90 days.
5. ADMINISTRATIVE CONTROLS
Keyora maintains security awareness and training programs for its personnel including at time of onboarding and at least annually thereafter. Keyora personnel are required to sign confidentiality agreements and are required to acknowledge responsibility for reporting security incidents.
Keyora reviews the access privileges of its personnel to its Cloud Environment at least annually, and removes access on a timely basis for all terminated personnel.
Keyora ensures that any of its vendors that process Customer Data maintain security measures consistent with Keyora’s obligations in the applicable agreement between Keyora and the Customer.
6. PHYSICAL DATA CENTER CONTROLS
Our Cloud Environment is maintained by one or more cloud service providers. We ensure that our cloud service providers data centers have appropriate controls as audited under their third-party audits and certifications. Each cloud service provider shall have SOC 2 Type II annual audit and ISO 27001 certification, or industry recognized equivalent frameworks. Such controls include:
Physical access to facilities are controlled at building ingress points;
Visitors are required to present ID and must be signed in;
Physical access to servers is managed by access control devices;
Physical access privileges are reviewed regularly;
Facilities utilize monitor and alarm response procedures;
Facilities utilize CCTV;
Facilities have adequate fire detection and protection systems;
Facilities have adequate back-up and redundancy systems; and
Facilities have appropriate climate control systems.
Keyora does not maintain physical offices other than for than for limited corporate and executive purposes. Under no circumstances is Customer Data stored or hosted at such offices.
7. INCIDENT DETECTION AND RESPONSE
If Keyora becomes aware of a breach of security leading to the destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data (a “Security Incident”), Keyora shall notify you without undue delay, and in any case, within 72 hours after becoming aware.
In the event of a Security Incident as described above, Keyora shall promptly take reasonable steps to contain, investigate, and mitigate any Security Incident in accordance with its incident response protocols.
8. CUSTOMER RIGHTS AND RESPONSIBILITIES
8.1 Audit Reports
Upon request, and at no additional cost to the Customer, Keyora shall provide the Customer, and/or its appropriately qualified third-party representative (collectively, the “Auditor”), access to reasonably requested documentation evidencing our compliance with our obligations under this Security Notice (collectively with Third-Party Audits, “Audit Reports”). Where an Auditor is a third party, such third party will be required to execute a separate confidentiality agreement with Keyora prior to any review of Audit Reports. Keyora is not responsible for any expenses incurred by an Auditor in connection with any review of Audit Reports.
8.2 Customer Responsibilities
It is the Customer’s responsibility to ensure that it is authorized to use any Customer Data with the Service and that its usage complies with relevant legal and regulatory obligations.
You are responsible for managing and protecting your credentials to access the Service. User credentials must be kept confidential and may not be shared with unauthorized parties. You must promptly report any suspicious activities related to your account(s) (such as when you reasonably believe that credentials have been compromised).
you are responsible for keeping your relevant IT systems (such as the browser you use to access the Service) up-to-date and appropriately patched.
9. HOW TO CONTACT US
If you have any questions about our security practices, this Security Notice or security-related issues, please contact us at security@keyora.ai.