Your data stays on your server
PatentFlow is installed on your own server or with a hosting provider of your choice - the database, the files and the AI model included. It sends no usage data anywhere, and the only outbound connections are the ones you set up.
Installed where you decide
A build script installs the application, the database and - if wanted - the AI model with Docker on a Linux server. The AI can run on the same server or on a separate one that only the application may reach. A local model is not required: firms can connect external providers only or work without AI entirely – then they install the light edition, which contains none.
Outbound connections are limited to what you use: your mail server, the patent offices' interfaces, the weekly fee comparison and external AI providers only if you configure them.
An audit log that cannot be edited
Every change and every opened file, export and download is recorded with user, time, file and result - refused requests and sign-ins included, contents never. The database refuses to change or delete entries. Administrators filter and export the log; the history of a file is visible to everybody who may see the file.
Encrypted backups, tested automatically
A separate container backs up the database and all files every night, encrypted with a passphrase that stays outside the server, and regularly restores the newest backup into a scratch database to prove it can be read back. The status is shown in the settings, with a warning when a backup is missing or a test failed.
Sessions and sign-in
Sign-in uses short-lived access tokens and rotating refresh tokens that are only stored as hashes; a stolen token that is used twice ends the session. Signing out, a password change or a deactivated user end access at once. API keys of AI providers are stored encrypted and never sent back to the browser.