What we do, and what we do not do yet.
A trademark register holds documents and deadlines that matter. This page is the honest state of how we protect them, including the gaps.
Last updated 23 Sep 2026
| Control | Status | Detail |
|---|---|---|
| Encryption in transit | In place | TLS 1.2+ on every host. HSTS. Cookies are Secure, HttpOnly, SameSite=Lax. |
| Encryption at rest | In place | Database volumes and object storage are encrypted at rest by the providers. Backups are encrypted. |
| Private document storage | In place | Documents live in a private Cloudflare R2 bucket the application never proxies. Uploads use presigned URLs valid for 10 minutes with content type and length pinned; downloads use presigned URLs valid for 2 minutes and are audited. |
| Upload verification | In place | Type allow-list (PDF, JPEG, PNG, WebP, TIFF), 25 MB cap, magic-byte check, and a SHA-256 computed server-side and compared with the declared hash. A mismatch deletes the object. |
| Append-only versions | In place | A new version is a new object. Nothing is overwritten. Deletes are soft for 30 days, refused under legal hold. |
| Tenant isolation | In place | Every table carries the organization id; every read is scoped; cross-organization reads return 404. CI checks that every loader takes an organization id and that no model with an organization id is read unscoped. |
| Sessions and CSRF | In place | Short-lived signed access tokens with rotating refresh tokens and reuse detection, in HttpOnly cookies. CSRF synchronizer token bound to the session plus an exact-origin allow-list. Login lockout after 10 failed attempts. |
| Audit log | In place | Append-only. Downloads, exports, member and role changes, acknowledgements, organization deletion, and session revocation are written with who and when. |
| Backups | In place | Nightly database dump to a separate private bucket, kept for 35 days. |
| Outbound allow-list | In place | The service makes outbound requests only to the USPTO's TSDR host, SendGrid, and Stripe. No user-supplied URL is ever fetched; specimen URLs are stored, not visited. |
| Dependency and code scanning | In place | gosec, govulncheck, gitleaks, and pnpm audit in CI on every change; Dependabot for updates. |
| Secrets | In place | Secrets exist only in the hosting platform's secret store. The service refuses to start in production with default or short secrets or without TLS to the database. |
| SOC 2 report | Not yet | Designed against the Trust Services Criteria; not audited and not certified. We will say so plainly until a report exists. |
| Third-party penetration test | Not yet | None yet. Internal review only. A first external test is planned before the Agency plan opens. |
| Multi-factor authentication | Not yet | Not yet available. Google sign-in with your own MFA is the current option. |
| Malware scanning of uploads | Not yet | Uploads are type- and hash-checked, not scanned for malware. We make no scanned claim until that exists. |
Reporting a vulnerability
Email [email protected] with what you found and how to reproduce it. We acknowledge within two business days and keep you informed until it is fixed. Please do not access other people’s data, and give us a reasonable time to fix before disclosing. Our security.txt carries the same contact.
Hosting
The application and database run on ComputeSphere in the United States. Documents and backups are in Cloudflare R2. Email goes through SendGrid; payments through Stripe. The full list, with regions, is on the subprocessors page.
Everything on this page describes the service as of the date above. When a control changes, this page changes with it.