By Erik Bailey, CIO, Anaqua
There's a misconception at the heart of many AI conversations: that intelligence is the actual innovation, and security is merely the prerequisite – not so much an afterthought, but not front-of-mind either. That may have been true when AI was simply generating ideas and answering questions. But as AI begins touching confidential disclosures, drafting responses, and taking action inside mission-critical intellectual property (IP) workflows, as well as being the basis for ever-more-sophisticated and rapid security threats, the infrastructure beneath it stops being a technical detail and becomes the foundation of trust.
Our clients don't just rely on us to manage IP. They trust us with information that often represents years of investment, innovation, and competitive advantage. These are inventions not yet protected, brand strategies not yet unveiled, and business positions not yet tested in the market. As AI takes on a more active role in IP operations and security, that trust becomes even more critical. It can't be treated as a feature or a compliance requirement; it must be the literal platform on which everything else is built.
Why "secure" must mean something specific
Anaqua holds ISO 27001 certification, has successfully completed the Type 2 SOC 2 examination for our security program, and holds ISO 9001 certification for our payment services process quality—the same standards regulators, auditors, and enterprise security teams expect from any vendor entrusted with mission-critical infrastructure. These audits require us to demonstrate, not just assert, that our controls hold up under scrutiny. For clients managing highly sensitive or export-controlled U.S. data, AnaquaGov provides an additional layer of protection: secure US-only staffing and infrastructure, independently assessed and validated against NIST SP 800-171 controls.
But certifications, as important as they are, are snapshots. What matters more is the architecture underneath them, because that's what determines whether those guarantees hold as the platform evolves.
Purpose-built as a design principle, not an afterthought
What’s unique about Anaqua is that we built our platform specifically to manage the sensitivity, complexity, and compliance requirements of intellectual property. That design choice matters more, not less, in an agentic AI world. As AI systems gain the ability to act across workflows, the boundaries between environments must be unambiguous. As new capabilities are introduced, privacy, security, and isolation guarantees don't have to be added on. They're already built into Anaqua’s foundation (Microsoft Azure hosting, encryption-at-rest and -in-transit, 24×7 operational monitoring across multiple data centers) that makes trusted AI possible. Staying ahead of the curve.
Most of our certifications exist because clients require us to have them (and we put many of the same requirements on our own suppliers). But we're also pursuing ISO 42001, the emerging standard for AI governance, before any client has made it a requirement. We believe AI governance is heading toward the same rigor that data security did a decade ago, and we'd rather be building that discipline now than react to it later. This involves mapping out all interaction points with AI technologies, including where data is stored and processed, and ensuring that the governance controls are solidly in place.
We're not going to overstate where we are. This is a certification we're actively working toward, not one we hold today, and we'll be transparent with clients about our progress as we go. But the posture matters: we're choosing to invest ahead of the requirement, because we think that's what a long-term partner does.
Confidence, without false certainty
Here's what we won't tell you: that a security incident is impossible. No vendor, whether in IP or any other industry, can honestly make that promise, and we think you should be skeptical of any partner who does.
What we can tell you is this: security at Anaqua isn't a checklist we complete once. It's a continuous practice that gets re-evaluated every time we introduce a new capability, including new AI functionality, so that our isolation guarantees, encryption standards, and access controls evolve in lockstep with the platform rather than trailing behind it. Anaqua staff complete regular security training, and secure-by-design is a core value in all aspects of our operations. Our security partners are on the forefront of AI as well, with state-of-the-art detection, alerting, and isolation capabilities that are optimized for the latest AI-driven threats, but still have humans in the loop for overall command and control. As AI expands what's technically possible, we treat every expansion as a reason to re-examine our controls, both internal and external, not a reason to assume they still apply.
Why this is the differentiator, not the disclaimer
Anaqua CEO Justin Crotty noted in his blog that the vendors most exposed to AI disruption are the ones whose value depended on pure information arbitrage or human-labor-intensive services, exactly the models that AI commoditizes quickly. Security and infrastructure sit on the opposite end of that spectrum. They're not commoditized by AI. If anything, they become the scarcer, more valuable capability, because the organizations racing fastest to adopt agentic AI are the ones most exposed if their underlying platform can't govern it responsibly.
That's the bet we're making: that in an AI-native era of IP, the vendors who earn long-term trust won't be the ones who talk the most about AI. They'll be the ones whose infrastructure was (and is) strong enough to deploy it safely in the first place. Anaqua has spent twenty years building that infrastructure. We intend to spend the next twenty extending and transforming it.
Anaqua is committed to helping our clients protect the world's most valuable IP portfolios with the rigor, transparency, and continuous investment that responsible AI adoption demands.
About the Author:
Erik came to Anaqua in 2006 as a Senior Director of Engineering; since then, he has held leadership positions in Client Support and R&D until moving into the CIO role in 2019. Erik has over 30 years of combined experience in software development, quality assurance, system implementation, and global information technology. Prior to joining Anaqua, Erik earned a degree from Brown University and worked at companies including Cambridge Technology Partners and AGENCY.COM.
Weitere Lektüre