Patterns Cloud: Security & Data Privacy
Patterns Cloud is the fastest way to get started with Patterns — the same process discovery engine as Patterns Enterprise, hosted on infrastructure we manage, with no deployment work on your end. Here's exactly how your data is handled.
Where your data lives
Log data is stored on Amazon S3, in AWS's us-east-1 (N. Virginia) region. This is a multi-tenant environment we operate on your behalf — the trade-off that lets you skip standing up your own infrastructure.
We anonymize logs on the way in
Before a log is written to storage, it's stripped of anything that would tie it back to a specific account or user. We don't store your identity alongside the log data, which means that even we can't look at a stored log and say who it came from.
Built on Amazon S3 — and its security track record
Rather than build our own storage layer, we run on S3 so we can inherit security work that's already been independently audited:
- Encrypted at rest and encrypted in transit between your browser, our servers, and S3
- Every access to the bucket is logged via AWS CloudTrail, giving a full audit trail of who touched what, and when
- AWS accounts and IAM roles with access to this data require multi-factor authentication
- Buckets are private with public access blocked at the account level
- Operates under AWS's SOC 1, SOC 2, SOC 3, and ISO 27001/27017/27018 certifications, built for 99.999999999% durability
To be clear: those are certifications of the infrastructure we run on, not of Patterns itself. We're not claiming SOC 2 or ISO certification for Patterns as a company — see the compliance note below.
Raw logs don't stick around
Raw capture data — which can include field values, on-screen text, and clipboard content in Full Capture mode — is deleted every time it's run through summarization. Summarization happens on a recurring scan, typically every 7 days, so that's the outer bound on how long a raw log sits in storage before it's reduced to a structured summary and discarded.
Both data collection tiers — Metadata Only and Full Capture — go through the same anonymization, storage, and deletion process described here.
AI processing: Google Gemini
Cloud's summarization step calls Google's Gemini API on Google's paid tier. Under those terms, prompts and outputs sent through the API aren't used to train Google's models. Data sent to Gemini is encrypted in transit.
Admin access
The admin dashboard supports multi-factor authentication and social sign-on, so your admins aren't relying on a single password that could be reused or phished elsewhere.
What Cloud doesn't include
Cloud trades some control for convenience. It doesn't include:
- Dedicated, single-tenant infrastructure
- A choice of data residency (data stays in us-east-1)
- The option to route AI processing through a model you already have configured (e.g., your own Bedrock or Azure AI Foundry deployment)
If your organization needs any of the above — typically because of internal policy or a regulatory requirement — that's what Patterns Enterprise is for.
Compliance posture
We're straightforward about where we are: we haven't completed SOC 2, ISO 27001, or similar third-party certifications yet. What we can say accurately today is what's described above — anonymization before storage, encryption, audit logging, and reliance on already-certified infrastructure providers. If a specific certification is a requirement for your organization, Patterns Enterprise (where you control the infrastructure and inherit your own compliance posture) is usually the better fit in the meantime.
Questions a security-conscious buyer would ask
Can Patterns employees see my raw data?
Raw logs are anonymized before they're stored, so there's no identifying link back to your account. They persist until the next summarization scan — typically within 7 days — at which point the raw version is deleted and only the structured, sanitized summary remains.
Where exactly is my data stored?
AWS S3, us-east-1 (N. Virginia).
Can I delete my data on request?
Yes. Contact us and we'll process the deletion request.
Should I put sensitive/regulated data through Cloud?
Cloud is anonymized and encrypted, but it's shared infrastructure without the residency or AI-routing control Enterprise offers. For regulated data, we'd point customers toward Patterns Enterprise.
Need Full Tenant Isolation Instead?
See how Patterns Enterprise runs entirely inside your own cloud environment, or head back to the Security Overview.
