Patterns Process Finder AI Logo

Patterns Enterprise: Security & Data Privacy

Patterns Enterprise runs entirely inside your own cloud environment — your AWS account, your Azure subscription, whichever you use. We don't host your data, and we don't touch it from the outside. If your organization has strict requirements around data residency, network isolation, or which AI models are allowed to touch sensitive information, this is the deployment model built for that.

Your tenant, your rules

All infrastructure is deployed inside your tenant, not ours. That means every security policy you already enforce — network segmentation, encryption key management, access reviews, retention schedules — applies to Patterns the same way it applies to anything else you run.

AI processing stays inside your environment too

We don't call out to an external AI provider on your behalf. Instead, we use whatever model you already have configured inside your own tenant — Amazon Bedrock, Azure AI Foundry, or another provider you've set up. Your data is analyzed by a model running under your own contract and your own data-handling terms with that provider, and it never leaves your environment to get there.

Network & infrastructure controls

  • Runs in private, isolated subnets — no public IP exposure
  • Firewalls and security groups enforce strict ingress/egress rules
  • Every connection between components is authenticated; nothing is trusted by default just because it's on the same network
  • Dependencies are continuously scanned for known vulnerabilities as part of our build process
  • Configuration changes are tracked and reviewed rather than made ad hoc

Raw capture data — which can include field values, on-screen text, and clipboard content in Full Capture mode — is deleted every time it's run through summarization, typically every 7 days. Both data collection tiers, Metadata Only and Full Capture, follow the same boundary: nothing generated by either mode leaves your tenant.

Access & identity

  • Multi-factor authentication and social sign-on (Google, Microsoft) are available for the admin dashboard, so access doesn't come down to a single password
  • Access is role-based, and every access to captured data is logged — you can see who looked at what, and when

Compliance posture

Because everything runs inside your own tenant, you inherit the compliance certifications your cloud provider and AI provider already carry, on top of whatever controls your organization layers on top. On our side, our own architecture is designed with SOC 2 Type II, ISO 27001, and GDPR requirements in mind — we're still working through formal certification and want to be upfront that it's in progress, not complete.

Frequently Asked Questions

Does Patterns ever see our data?

No. Processing happens inside your environment, using your AI model deployment. We don't have a path to your data from the outside.

What AI models power Enterprise?

Whatever you've already configured in your tenant — commonly Amazon Bedrock or Azure AI Foundry.

Can we apply our own security policies on top of this?

Yes — since Patterns runs inside your infrastructure, your existing policies (network rules, key management, retention, access reviews) govern it the same way they govern anything else in your environment.

What happens in a security incident?

Because the deployment lives in your tenant, your existing incident response process and tooling apply directly. We work with your team on anything specific to the Patterns application itself.

Can individual users be identified from the data Patterns processes?

Identifying information is not required by the platform to generate a process summary, and capture modes are chosen by you based on what your organization is comfortable recording.

Want to Get Started Faster Instead?

See how Patterns Cloud gets you running with zero deployment work, or head back to the Security Overview.