Security, Confidentiality, and Model Governance
23VIP is built around a clear model-governance choice: EU-hosted open-source models such as Mistral, or frontier models (Gemini, GPT, Claude) used under business terms that prohibit training on your data. The open-source path supports EU-hosted, ephemeral processing within European infrastructure; the frontier path brings frontier-class reasoning under contractual no-training terms. Both are designed for confidentiality-sensitive patent practice, and organisations decide which paths their teams may use.
EU-Hosted Open-Source Models
Open-source models hosted in Europe by European providers.
- Available in Claim Drafter and Web Drafter for claims, full drafts, and drawing workflows
- The AI model does not train on your data and does not retain it after your session
- Keeps processing on EU infrastructure for disclosures that must stay in the EU
Frontier Models
Gemini, GPT, and Claude, used under business terms that prohibit training on your data. Reply Drafter runs exclusively on frontier models; in Claim Drafter and Web Drafter they are one of the two selectable paths, and they can be disabled by policy.
- No training on your data — contractually guaranteed by all providers
- Zero retention by Claude. Provider-dependent otherwise
- Selectable per tool and per task
- Suitable for teams with mixed AI policies
- Can be turned off per user or per organisation
Our Security Commitments
Across all tools, the service is designed to prevent internal access to your inputs and outputs.
Your invention disclosures, technical specifications, and draft applications are not used to train any models, whether you use the EU-hosted open-source path or a frontier model. On the EU-hosted path, the system is configured for ephemeral EU-hosted processing and is intended to minimize exposure outside the EU, including to non-EU legal regimes. This describes the AI model's processing of your data; see "What is 23VIP's data retention policy?" below for how saved projects and security-flagged input are separately stored.
Data Processing Architecture
- Isolated processing: Each drafting session runs in a fully isolated European environment
- Encryption in transit: All data is protected with TLS 1.3
- Encryption at rest: Data is encrypted at rest on our hosting infrastructure
- Provider separation: The two model paths are kept clearly separate, and organisations control which paths their users may select
GDPR Compliance
As a Belgian company with application logic and databases hosted in Europe, 23VIP is designed with GDPR requirements and European data protection principles in mind:
- Personal Data minimisation: We collect and process only what is strictly necessary
- Right to erasure: You can request deletion of your personal data at any time
Frequently Asked Questions
Does 23VIP's AI learn from my patent applications?
No. 23VIP enforces a strict no-training policy on all models. Whichever path you choose — EU-hosted open-source or frontier — the models are used under terms that prohibit training on your data.
Can 23VIP employees see my patent drafts?
No. Across all drafting tools, the service is designed to prevent internal access to your inputs and outputs.
How does 23VIP compare to general-purpose tools like ChatGPT for confidentiality?
Unlike consumer tools such as ChatGPT, which may retain your data and use your inputs for training, 23VIP gives you a governed choice: an EU-hosted open-source path configured for ephemeral processing within Europe, or frontier models used under business terms that prohibit training on your data. Organisations can restrict the choice by policy.
What is 23VIP's data retention policy?
Model processing itself is ephemeral: on the EU-hosted open-source path, the system is configured for real-time processing and the model does not retain inputs or outputs after the session. On the frontier path, provider retention terms apply, and all providers are contractually prohibited from training on your data.
Saved projects. If you save your work in a named project (Claim Drafter, Web Drafter, or Reply Drafter), that project's content — invention text, claims, drafts, and drawings, or for Reply Drafter, case documents, phase outputs, and reply/style templates — is stored under your account until you delete the project. Deleting a project removes it from your account and it is no longer accessible to you.
Security scanning. Input to our drafting tools may be automatically scanned for prompt-injection attempts, using the same model family you have selected — an EU-hosted model on the EU-hosted path, or the applicable frontier model otherwise. Flagged input is retained for 30 days for security review and then automatically deleted.
How does 23VIP help with EU AI Act compliance?
23VIP is designed from the ground up to meet the transparency and risk-management requirements of the EU AI Act. Furthermore, our AI Literacy Training programme helps your team fulfil Article 4 obligations with interactive training, testing, and verifiable certificates.
What about the environmental impact?
23VIP's EU-hosted open-source path has a significantly lower carbon and water footprint than typical US-based AI services. European data centres run on one of the cleanest grids in the world, and the efficient open-source architecture reduces overall energy consumption.
Contact for Security Inquiries
Email: christophe.ego@23vip.be
Company: 23VIP srl
VAT: BE0849.690.306