Patterns Process Finder AI Logo

Security & Data Privacy

At Patterns, security and data privacy are at the core of everything we build. Our mission is to help organizations discover and optimize their internal processes — without ever compromising on data integrity, confidentiality, or control. We offer two deployment models, each with its own security posture — see exactly how each handles your data below.

Two Ways to Run Patterns

Same discovery engine, two different security postures. Choose the one that fits your requirements.

Built Into Both Deployment Models

These protections apply whichever way you run Patterns.

Data Minimization & Retention

Raw capture data is deleted every time it's run through summarization — typically within 7 days — regardless of which deployment model or capture tier you use.

  • Raw logs deleted after each summarization scan (~7 days)
  • Only structured, sanitized summaries persist afterward
  • You choose the capture tier for every device

Access & Identity

Comprehensive identity management with granular access controls, on both deployment models.

  • Multi-factor authentication and social sign-on for admin accounts
  • Role-based access — every access to captured data is logged
  • Configuration changes are tracked and reviewed

Application & API Security

All APIs are authenticated and rate-limited with continuous vulnerability scanning.

  • Secure API gateway with signed token authentication
  • Dependencies continuously scanned for known vulnerabilities
  • Encrypted in transit everywhere

Compliance Posture

Our architecture is designed with SOC 2 Type II, ISO 27001, and GDPR requirements in mind — we're still working through formal certification and want to be upfront that it's in progress, not complete.

  • SOC 2 Type II, ISO 27001, and GDPR alignment (pending certification)
  • Patterns Enterprise inherits your own cloud and AI providers' certifications

Security FAQ

What's the difference between Patterns Cloud and Patterns Enterprise?

Patterns Cloud is hosted by us on shared AWS infrastructure, anonymized before storage, with zero deployment work on your end. Patterns Enterprise runs entirely inside your own cloud tenant, using your own AI model deployment, giving you full control over data residency and network isolation.

Which one is right for us?

Most teams start with Patterns Cloud to get running quickly. If your organization has strict requirements around data residency, network isolation, or which AI models are allowed to touch sensitive data, Patterns Enterprise is built for that instead.

Can Patterns staff ever see our data?

No, on either model — just for different reasons. On Patterns Cloud, data is anonymized before it's ever stored, so there's no identifying link back to your account. On Patterns Enterprise, processing happens entirely inside your own tenant, so we have no path to your data from the outside.

Can individual users be identified from the data Patterns processes?

No. Identifying information isn't required by the platform to generate a process summary, and on both deployment models you choose the capture tier — Metadata Only or Full Capture — based on what your organization is comfortable recording.

See exactly what "Metadata Only" vs. "Full Capture" records →

Choose the Deployment That Fits Your Requirements

Whichever model you choose, Patterns is built around the same principles: minimal data collection, clear boundaries on what's captured, and full transparency about how it's handled.