Security & Data Privacy
At Patterns, security and data privacy are at the core of everything we build. Our mission is to help organizations discover and optimize their internal processes — without ever compromising on data integrity, confidentiality, or control. We offer two deployment models, each with its own security posture — see exactly how each handles your data below.
Two Ways to Run Patterns
Same discovery engine, two different security postures. Choose the one that fits your requirements.
Patterns Cloud
Hosted by Patterns on shared AWS infrastructure.
- Data anonymized before storage on AWS S3 (us-east-1)
- Secure AI processing via Google Gemini (Your data will not be used to train Google models)
- Multi-tenant, Patterns-managed infrastructure
- Best for teams who want to start quickly
Patterns Enterprise
Deployed entirely inside your own cloud tenant.
- Runs inside your AWS/Azure tenant, not ours
- AI processing via your own model (e.g. Bedrock, Azure AI Foundry)
- Single-tenant, full network and data-residency control
- Best for regulated or security-sensitive environments
Built Into Both Deployment Models
These protections apply whichever way you run Patterns.
Data Minimization & Retention
Raw capture data is deleted every time it's run through summarization — typically within 7 days — regardless of which deployment model or capture tier you use.
- Raw logs deleted after each summarization scan (~7 days)
- Only structured, sanitized summaries persist afterward
- You choose the capture tier for every device
Access & Identity
Comprehensive identity management with granular access controls, on both deployment models.
- Multi-factor authentication and social sign-on for admin accounts
- Role-based access — every access to captured data is logged
- Configuration changes are tracked and reviewed
Application & API Security
All APIs are authenticated and rate-limited with continuous vulnerability scanning.
- Secure API gateway with signed token authentication
- Dependencies continuously scanned for known vulnerabilities
- Encrypted in transit everywhere
Compliance Posture
Our architecture is designed with SOC 2 Type II, ISO 27001, and GDPR requirements in mind — we're still working through formal certification and want to be upfront that it's in progress, not complete.
- SOC 2 Type II, ISO 27001, and GDPR alignment (pending certification)
- Patterns Enterprise inherits your own cloud and AI providers' certifications
Security FAQ
What's the difference between Patterns Cloud and Patterns Enterprise?
Patterns Cloud is hosted by us on shared AWS infrastructure, anonymized before storage, with zero deployment work on your end. Patterns Enterprise runs entirely inside your own cloud tenant, using your own AI model deployment, giving you full control over data residency and network isolation.
Which one is right for us?
Most teams start with Patterns Cloud to get running quickly. If your organization has strict requirements around data residency, network isolation, or which AI models are allowed to touch sensitive data, Patterns Enterprise is built for that instead.
Can Patterns staff ever see our data?
No, on either model — just for different reasons. On Patterns Cloud, data is anonymized before it's ever stored, so there's no identifying link back to your account. On Patterns Enterprise, processing happens entirely inside your own tenant, so we have no path to your data from the outside.
Can individual users be identified from the data Patterns processes?
No. Identifying information isn't required by the platform to generate a process summary, and on both deployment models you choose the capture tier — Metadata Only or Full Capture — based on what your organization is comfortable recording.
See exactly what "Metadata Only" vs. "Full Capture" records →Choose the Deployment That Fits Your Requirements
Whichever model you choose, Patterns is built around the same principles: minimal data collection, clear boundaries on what's captured, and full transparency about how it's handled.
