A new way to access patent intelligence. Meet your AI assistant, LexisNexis® Protégé™ in PatentSight+™ for strategic patent analysis. Explore Now

LexisNexis Protégé™
in PatentSight+™
Security Information

Trust, Transparency and Security: Our Promise

LexisNexis® prioritizes security and customer data protection throughout the entire product development lifecycle. We are committed to delivering our customers the highest-quality and most cutting-edge solutions with the deepest levels of security, compliance, and privacy. To ensure comprehensive security controls, our team of application and security experts work hand-in-hand with our talented product development and engineering teams, as well as our data protection officers, ensuring that each product meets rigorous, audited standards.

This security overview of Protégé in PatentSight+ provides answers to some of the frequently asked questions about security and how LexisNexis protects our customers and their data.

This document presents an overview of the digital information security measures and standards that LexisNexis applies globally as of November 2025. In light of the dynamic nature of the information security space and in order to reflect the evolving nature of the relevant procedures, regulations, and threats, LexisNexis may update these technical, organizational, and physical measures from time to time, without notice, as long as such changes do not materially lower the protection of information and are not materially inconsistent with the protections described herein.

Your Data

Your data is securely stored and encrypted at rest using AES-256 in our private cloud. Your data is always encrypted in transit using TLS 1.2 or higher.

Your Prompts

  • Each customer request or “prompt” is processed separately, creating an isolated transaction with the generative and analytic capabilities.
  • Prompts are securely retained for up to 90 days (or until deleted by the user) to support transparency, auditability, and responsible model governance.
  • All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Access to stored prompts is strictly limited through role-based controls and multi-factor authentication, with every access event logged and monitored.
  • The retention environment is isolated, continuously monitored for anomalies, and regularly audited against ISO 27001 standards. Cloud providers may log in for system support and troubleshooting purposes only and have no access to user prompts.

Your Conversation

  • Conversations are purged after 90 days or until the user deletes them (whichever occurs first).
  • All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Access to stored prompts is strictly limited through role-based controls and multi-factor authentication, with every access event logged and monitored.
  • The retention environment is isolated, continuously monitored for anomalies, and regularly audited against ISO 27001 standards.
  • Cloud providers may log in for system support and troubleshooting purposes only and have no access to user prompts.

Privacy

LexisNexis processes personal data in compliance with data protection laws, our Privacy Policy, and Data Processing Addendum. We process personal data solely to provide the services listed on our Subprocessors page.

Vulnerability Scanning

We perform penetration testing using internal tools and trusted third-party firms to validate our defenses. Regular internal and external vulnerability scanning helps maintain visibility into potential risks across our systems and hardware. Findings are tracked centrally to ensure proper risk prioritization, and remediation efforts are coordinated with the supporting teams based on risk severity.

Application Security Program

Your data is securely stored and encrypted at rest using AES-256 in our private cloud. Your data is always encrypted in transit using TLS 1.2 or higher.

Application Testing

  • Protégé in PatentSight+ code undergoes static application security testing (SAST) prior to being deployed to a live environment. Software Component Analysis (SCA) is performed as part of the CI/CD pipeline to identify and manage third-party and open-source components within our software. Dynamic application security testing (DAST) scanning and penetration testing is also performed on the solution.
  • Penetration test reports are available to customers upon request. Further application security questions can be addressed for customers under a non-disclosure agreement (NDA).
  • Security gates are in place to prevent insecure code from being introduced to production.
  • The application security team works with development teams to resolve vulnerabilities regardless of the source, in accordance with established remediation timelines based on criticality.
Security Information Protege in PatentSight

Authentication

We offer two authentication options. LexisNexis® PatentSight+™ uses its own Web Access Management (WAM) system for user authentication and also supports federated Single Sign-On (SSO) using SAML 2.0. Our technical support team will assist during onboarding with the SSO setup.

Network Security Controls

Network security controls are implemented based on a least access principle. The controls also provide protection against unauthorized access and traffic interception. These protections are in place to restrict access inbound and outbound along with internal traffic to/from systems. Where possible and necessary, private endpoints are utilized to securely access cloud services to ensure security of associated transactions.

Our Own Network Access

LexisNexis employees’ access to company networks is restricted to corporate managed devices and uses multi-factor authentication. Authorizations are based on the least privilege principle. Privileged accounts are provided based on the need to perform job function and approved by management, with regular access reviews undertaken. Access is automatically removed upon termination.

Data Analytics

LexisNexis allows access to data only by authorized support personnel with permissions on a need-to-know basis (principle of least privilege).

LexisNexis gathers analytical statistics regarding usage of application functions but does not process any customer data specifically.

Third Parties

The LexisNexis Vendor Management program performs vendor security checks and assessments during the procurement process. Initial approval is followed by a periodic review of the vendor’s security posture. Vendors are assessed on a risk-based approach using several factors including access to data (customer/company), system access, and performing a critical function on behalf of the company.

Policies, Standards and Guidelines

LexisNexis has strict company-wide security policies, standards and guidelines that detail the necessary security controls and configurations that ensure all systems and data managed by LexisNexis remain secure.

These policies are reviewed and updated regularly, considering changes in legal, regulatory, and operational environments, as well as to address new and emerging threats.

Employees are required to complete computer-based training upon hire and periodically thereafter covering topics to include our security policies and practices, code of ethics, and data privacy.

Robust Incident Response

LexisNexis has a robust set of Information Security policies. This enables us to efficiently respond to potential threats against our systems. Our incident response plans, which are updated and tested periodically, include technical, administrative, business, and executive escalation processes. The company has external firms on retainer to provide expertise and guidance, as needed.

Audit Reports

We operate consistent policies and controls across our product space. Protégé in PatentSight+ will be ISO-27001 certified.

Our cloud environments, key products, and security programs are audited annually with focus on various controls in place for customer data protection, including:

  • Encryption controls
  • Data backup
  • Disaster recovery
  • Security groups utilized to assign role-based
    access privileges and segregate access to data
  • User access reviews to ensure access is restricted and authorized
  • Data destruction controls backup
  • Blocking suspected or actual network breaches
  • Maintaining confidentiality of customer data

Data & Infrastructure Security

Protégé in PatentSight+ is deployed and maintained using LexisNexis infrastructure, following the same security architecture, reviews, audits, and validation processes applied to other LexisNexis products including Lexis+ AI. Generative and agentic AI capabilities have been engineered and deployed to meet our high-level security standards, with a key focus on protecting and segmenting customer activity. Our security team continues to be actively engaged in all aspects of the engineering and deployment of Protégé in PatentSight+.

Architecture of Protégé in PatentSight+

High-Level Architecture Flow:

  • A user logs into the Protégé in PatentSight+ using WAM to securely access the application.
  • All user’s prompts are sent securely using TLS 1.2 or later to PatentSight+ AI service.
  • PatentSight+ AI service parses the prompt for intent and then construct a PatentSight+ Search Syntax statement using an LLM.
  • An authenticated request is sent securely using TLS 1.2 or later to LNIP API using the generated PatentSight+ Search Syntax.
  • PatentSight+ AI service processes the returned results by performing a sanity check, analyzing them, preparing visualizations, and utilizing an LLM before returning them to Protégé in PatentSight+.
  • All interactions within PatentSight+ AI service are securely recorded and encrypted at rest within conversation history for up to 90 days or until deleted by user.
  • Anthropic and OpenAI LLMs are utilized with a zero data retention policy but are isolated from PatentSight+ AI service.

Q&A

Will my entries into the tool be used to train the Protégé in PatentSight+ model?

LexisNexis does not use customer data to tune or train our Large Language Models. Users also have individual control of prompt history and options to delete prompt history from our services. For further information, you can access our privacy policy page.

What are your encryption standards?

All Protégé in PatentSight+ customer data is encrypted at rest (AES-256) and traffic in transit (TLS 1.2 or higher).

Can LexisNexis employees see my chat queries?

A restricted group of product support experts with appropriate accesses will be able to review customer usage data for the purpose of product support and technical troubleshooting.

Access is limited only to authorized personnel and customer association is pseudo-anonymized.

All reports and documents are available on a per-request basis. Contact your account team for more information.

Is my Protégé data made available to other services within LexisNexis?

Customer data is only used and stored within the specific product context in which it was entered and is not shared with other LexisNexis products unless explicitly granted and communicated.

Other Materials

LexisNexis Legal & Professional Data Privacy Principles

Responsible Artificial Intelligence Principles at RELX

Your Peace of Mind Is Our Priority

In-depth InfoSec Documents: Available Upon Request

Detailed Architectural Drawings: Available Upon Request