Security and Trust

Protection designed for sensitive legal work.

NOA is built to keep confidential patent matters isolated, controlled, and reviewable throughout the prosecution workflow.

Encryption

Data is protected in transit and at rest.

Tenant isolation

Customer environments remain logically separated.

Access control

Permissions follow organization, role, and matter.

Traceability

Relevant system activity remains reviewable.

Data Boundaries

Customer information stays within defined controls.

NOA customer environment data-boundary diagram Authorized users enter the NOA customer environment through controlled access. Matter documents, encrypted processing, and authorized outputs remain inside the tenant boundary. User-directed output goes to approved export, while external model training is marked not used. NOA CUSTOMER ENVIRONMENT TENANT BOUNDARY Authorizedusers CONTROLLEDACCESS Matterdocuments Encryptedprocessing Authorizedoutputs USERDIRECTED Approvedexport NOT USED External modeltraining INGEST PROCESS REVIEW

Security by Design

Controls across the full workflow.

Encryption at rest

Stored matter content remains protected.

Encryption in transit

Connections use protected transport.

Role-based permissions

Access is limited by assigned responsibility.

Tenant separation

Organizations remain logically isolated.

Controlled retention

Data lifecycle follows configured policy.

Reviewable activity

Relevant actions can be traced.

Secure development

Changes follow disciplined review practices.

Incident response

Defined procedures guide investigation and notice.

Frequently Asked Questions

Questions security teams usually ask.

Is customer data used to train shared models?

No. Customer matter content is kept logically isolated and is not used to train shared foundation models. NOA is designed so customer work product remains under defined customer controls.

How is access to matters controlled?

Access is governed through role-based authorization, tenant-level separation, and customer-specific entitlements. Users can access only the matters, workspaces, and environments approved for their organization and role.

Can customers define retention requirements?

Yes. Retention policies can be aligned to customer requirements, including configured data lifecycle controls, backup retention, and environment-specific governance needs.

How is data protected during processing?

Data is protected through encrypted transport, controlled access paths, and isolated processing environments. Access to customer content is limited by approved permissions and governed throughout the workflow.

What activity can be reviewed or audited?

Relevant administrative, access, configuration, and application activity can be reviewed to support oversight, security reviews, and customer reporting. Audit scope can be expanded as customer governance needs mature.

Does NOA support security reviews?

Yes. NOA can support customer security reviews with documentation covering architecture, access controls, data protection, operational safeguards, and the boundaries that govern customer information.