Systems and methods for code insurance policy for ai generated code
The described platform efficiently evaluates software code risk and generates insurance policies using AI, addressing inefficiencies in existing methods by providing a unified, automated solution for code analysis and monetization, enhancing accessibility and reducing costs.
Patent Information
- Application Number
- PCT/US2025/041788
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-13
- Filing Date
- 2025-08-13
- Publication Date
- 2026-02-19
AI Technical Summary
Existing methods for evaluating software code risk and generating insurance policies are inefficient, requiring extensive manual intervention and third-party systems, leading to incomplete and time-consuming assessments without a unified platform for stakeholder access.
A seamless platform for storing, evaluating, and certifying computer code using AI, enabling automated insurance policy generation based on risk evaluation, with features like code replication, analysis dashboards, and monetization tools, utilizing cloud services like Azure and AI chatbots.
Facilitates efficient and comprehensive code risk evaluation, providing a unified platform for stakeholders, automated insurance policies, and accurate code monetization, reducing time and costs while ensuring code integrity and accessibility.
Smart Images

Figure US2025041788_19022026_PF_FP_ABST
Abstract
Description
SYSTEMS AND METHODS FOR CODE INSURANCE POLICY FOR Al GENERATED CODECross-Reference to Related Applications
[0001] This application claims priority to U.S Application No. 63 / 682,535, filed August 13, 2024, which application is incorporated herein by reference in its entirety.Field of the Invention
[0002] The present invention relates to a method and system for identifying risk in software code libraries and creating derisking products for same.Brief Summary of the Invention
[0003] In an exemplary embodiment, systems and methods may be provided for the risk evaluation of deployed software code and an automatically generated insurance policy covering at least part of the identified risk.
[0004] Advantages will become more apparent to those skilled in the art from the following description of the preferred embodiments which have been shown and described by way of illustration. As will be realized, the present embodiments may be capable of other and different embodiments, and their details are capable of modification in various respects. Accordingly, the drawings and description are to be regarded as illustrative in nature and not as restrictive.Brief Description of the Drawings
[0005] This disclosure is illustrated by way of example and not by way of limitation in the accompanying figure(s). The figure(s) may, alone or in combination,56048981.1Docket No. 394493.00010 illustrate one or more embodiments of the disclosure. Elements illustrated in the figure(s) are not necessarily drawn to scale. Reference labels may be repeated among the figures to indicate corresponding or analogous elements.
[0006] The detailed description makes reference to the accompanying figures in which:
[0007] Fig. 1 illustrates a document analysis (DA) system in accordance with an exemplary embodiment of the present disclosure;
[0008] Fig. 2 illustrates an exemplary client computing device that may be used with the DA system illustrated in Fig. 1;
[0009] Fig. 3 illustrates an exemplary server system that may be used with the DA system illustrated in Fig. 1 ;
[0010] Fig. 4 illustrates an embodiment of the present invention;
[0011] Fig. 5 illustrates an embodiment of the present invention;
[0012] Fig. 6 illustrates an embodiment of the present invention;
[0013] Fig. 7 illustrates an embodiment of the present invention;
[0014] Fig. 8 illustrates an embodiment of the present invention;
[0015] Fig. 9 illustrates an embodiment of the present invention;
[0016] Fig. 10 illustrates an embodiment of the present invention;
[0017] Fig. 11 illustrates an embodiment of the present invention; and
[0018] Fig. 12 illustrates an embodiment of the present invention.Detailed Description256048981.1Docket No. 394493.00010
[0019] The figures and descriptions provided herein may have been simplified to illustrate aspects that are relevant for a clear understanding of the herein described apparatuses, systems, and methods, while eliminating, for the purpose of clarity, other aspects that may be found in typical similar devices, systems, and methods. Those of ordinary skill may thus recognize that other elements and / or operations may be desirable and / or necessary to implement the devices, systems, and methods described herein. But because such elements and operations are known in the art, and because they do not facilitate a better understanding of the present disclosure, for the sake of brevity a discussion of such elements and operations may not be provided herein. However, the present disclosure is deemed to nevertheless include all such elements, variations, and modifications to the described aspects that would be known to those of ordinary skill in the art.
[0020] The present embodiments may relate to systems and methods may be provided for the risk evaluation of deployed software code and an automatically generated insurance policy covering at least part of the identified risk.
[0021] Today how you would answer this question is to walk over to your CTO or Zoom him or her and wait for him or her to get you some / not all of this information. Then you would have to interface with multiple third-party systems or cloud service providers to get some of the answers. Engage IP Counsel or consultant to provide a 2-4 month IP Audit, then be handed a password to a developers code service that is made for technical developer356048981.1Docket No. 394493.00010 to access and analyze the code base through a third party hub written for and by them.
[0022] So the result is this problem is never cleanly answered. Thousands are spent to answer one third the problem and months of time are taken to answer most of them. Then there is not one place where all stakeholders can access the same information in an easy to consume way. Thus, the present invention provides a seamless and efficient platform to help store, evaluate, replicate, and certify computer code.
[0023] Fig. 1 depicts an exemplary artificial intelligence (Al) computing system 100. Al computing system 100 may include an Al computing device 102 (also referred to herein as Al server or Al computer device). Al computing device 102 may include a database server 104. Further, Al computing device 102 may be in communication with, for example, a database 106, one or more client devices 108a and 108b, and a client computing device, such as user computing device 110.
[0024] In the exemplary embodiments, client devices 108a and 108b may be computers that include a web browser or a software application, which enables the devices to access remote computer devices, such as Al computing device 102, using the Internet or another type of network. More specifically, client devices 108a and 108b may be communicatively coupled to Al computing device 102 through many interfaces including, but not limited to, at least one of the Internet, a network, such as the Internet, a local area network (LAN), a wide area network (WAN), or an integrated456048981.1Docket No. 394493.00010 services digital network (ISDN), a dial-up-connection, a digital subscriber line (DSL), a cellular phone connection, and a cable modem. Client devices 108a and 108b may be any device capable of accessing the Internet including, but not limited to, a desktop computer, a laptop computer, a personal digital assistant (PDA), a cellular phone, a smartphone, a tablet, a phablet, wearable electronics, smart watch, or other web-based connectable equipment or mobile devices.
[0025] User device 110 may be a computer that includes a web browser or a software application, which enables user device 110 to access remote computer devices, such as Al computing device 102, using the Internet or other network. In some embodiments, user device 110 may be associated with, or part of a computer network associated with, a medical records company. In other embodiments, user device 110 may be associated with a third party. More specifically, user device 110 may be communicatively coupled to the Internet through many interfaces including, but not limited to, at least one of a network, such as the Internet, a local area network (LAN), a wide area network (WAN), or an integrated services digital network (ISDN), a dial-up-connection, a digital subscriber line (DSL), a cellular phone connection, and a cable modem. User device 110 may be any device capable of accessing the Internet including, but not limited to, a desktop computer, a laptop computer, a personal digital assistant (PAI), a cellular phone, a smartphone, a tablet, a phablet, wearable electronics, smart watch, or other web-based connectable equipment or mobile devices.556048981.1Docket No. 394493.00010
[0026] Database server 104 may be communicatively coupled to database 106 that stores data. In one embodiment, database 106 may include user data associated with users (e.g., personal information, medical data), prediction data, third party data, etc. In the exemplary embodiment, database 106 may be stored remotely from Al computing device 102. In some embodiments, database 106 may be decentralized. In the exemplary embodiment, a user may access database 106 and / or Al computing device 102 via client devices 108a and 108b.EXEMPLARY CLIENT COMPUTING DEVICE
[0027] Fig. 2 illustrates a block diagram 200 of an exemplary client computing device 202 that may be used with the artificial intelligence (Al) computing system 100 shown in Fig. 1. Client computing device 202 may be, for example, at least one of devices 108a, 108b, and 110 (all shown in Figure 1)-
[0028] Client computing device 202 may include a processor 205 for executing instructions. In some embodiments, executable instructions may be stored in a memory area 210. Processor 205 may include one or more processing units (e.g., in a multi-core configuration). Memory area 210 may be any device allowing information such as executable instructions and / or other data to be stored and retrieved. Memory area 210 may include one or more computer readable media.
[0029] In exemplary embodiments, processor 205 may include and / or be communicatively coupled to one or more modules for implementing the656048981.1Docket No. 394493.00010 systems and methods described herein. For example, in one exemplary embodiment, a module may be provided for receiving data and building a model based upon the received data. Received data may include, but is not limited to, medical information data pertaining to users, medication dosage data, and / or medical treatment data pertaining to users. A model may be built upon this received data, either by a different module or the same module that received the data. Processor 205 may include or be communicatively coupled to another module for generating a OCR prediction data based upon received data pertaining to a user, such as one or more of medical diagnosis, medications, or the like.
[0030] In one or more exemplary embodiments, computing device 202 may also include at least one media output component 215 for presenting information a user 201. Media output component 215 may be any component capable of conveying information to user 201. In some embodiments, media output component 215 may include an output adapter such as a video adapter and / or an audio adapter. An output adapter may be operatively coupled to processor 205 and operatively coupled to an output device such as a display device (e.g., a liquid crystal display (LCD), a light emitting diode (LED) display, an organic light emitting diode (OLED) display, a cathode ray tube (CRT) display, an “electronic ink” display, a projected display, etc.) or an audio output device (e.g., a speaker arrangement or headphones). Media output component 215 may be configured to, for example, display a status of the model and / or display a prompt for user 201 to input user data.756048981.1Docket No. 394493.00010
[0031] Client computing device 202 may also include an input device 220 for receiving input from a user 201 . Input device 220 may include, for example, a keyboard, a pointing device, a mouse, a stylus, a touch sensitive panel (e.g., a touch pad or a touch screen), a scanner, an image capturing device, or an audio input device. A single component, such as a touch screen, may function as both an output device of media output component 215 and an input device of input device 220.
[0032] Client computing device 202 may also include a communication interface 225, which can be communicatively coupled to a remote device, such as LP computing device 102, shown in Figure 1. Communication interface 225 may include, for example, a wired or wireless network adapter or a wireless data transceiver for use with a mobile phone network (e.g., Global System for Mobile communications (GSM), 3G, 4G, or Bluetooth) or other mobile data networks (e.g., Worldwide Interoperability for Microwave Access (WIMAX)). The systems and methods disclosed herein are not limited to any certain type of short-range or long-range networks.
[0033] Stored in memory area 210 may be, for example, computer readable instructions for providing a user interface to user 201 via media output component 215 and, optionally, receiving and processing input from input device 220. A user interface may include, among other possibilities, a web browser or a client application. Web browsers may enable users, such as user 201 , to display and interact with media and other information typically embedded on a web page or a website.856048981.1Docket No. 394493.00010
[0034] Memory area 210 may include, but is not limited to, random access memory (RAM) such as dynamic RAM (DRAM) or static RAM (SRAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and non-volatile RAM (NVRAN). The above memory types are exemplary only, and are thus not limiting as to the types of memory usable for storage of a computer program.EXEMPLARY SERVER COMPUTING DEVICE
[0035] Fig. 3 depicts a block diagram 300 showing an exemplary server system 301 that may be used with the Al system 100 illustrated in Fig. 1. Server system 301 may be, for example, Al computing device 102 or database server 104 (shown in Fig. 1 ).
[0036] In exemplary embodiments, server system 301 may include a processor 305 for executing instructions. Instructions may be stored in a memory area 310. Processor 305 may include one or more processing units (e.g., in a multi-core configuration) for executing instructions. The instructions may be executed within a variety of different operating systems on server system 301 , such as UNIX, LINUX, Microsoft Windows®, etc. It should also be appreciated that upon initiation of a computer-based method, various instructions may be executed during initialization. Some operations may be required in order to perform one or more processes described herein, while other operations may be more general and / or specific to a particular956048981.1Docket No. 394493.00010 programming language (e.g., C, C#, C++, Java, or other suitable programming languages, etc.).
[0037] Processor 305 may be operatively coupled to a communication interface 315 such that server system 301 can communicate with Al computing device 102, client devices 108a, 108b, and 110 (all shown in Fig. 1), and / or another server system. For example, communication interface 315 may receive data from user devices 108a and 108b via the Internet.
[0038] Processor 305 may also be operatively coupled to a storage device 317, such as database 106 (shown in Fig. 1). Storage device 317 may be any computer-operated hardware suitable for storing and / or retrieving data. In some embodiments, storage device 317 may be integrated in server system 301. For example, server system 301 may include one or more hard disk drives as storage device 317. In other embodiments, storage device 317 may be external to server system 301 and may be accessed by a plurality of server systems. For example, storage device 317 may include multiple storage units such as hard disks or solid state disks in a redundant array of inexpensive disks (RAID) configuration. Storage device 317 may include a storage area network (SAN) and / or a network attached storage (NAS) system.
[0039] In some embodiments, processor 305 may be operatively coupled to storage device 317 via a storage interface 320. Storage interface 320 may be any component capable of providing processor 305 with access to storage device 317. Storage interface 320 may include, for example, an1056048981.1Docket No. 394493.00010Advanced Technology Attachment (ATA) adapter, a Serial ATA (SATA) adapter, a Small Computer System Interface (SCSI) adapter, a RAID controller, a SAN adapter, a network adapter, and / or any component providing processor 305 with access to storage device 317.
[0040] Memory area 310 may include, but is not limited to, random access memory (RAM) such as dynamic RAM (DRAM) or static RAM (SRAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and non-volatile RAM (NVRAM). The above memory types are exemplary only, and are thus not limiting as to the types of memory usable for storage of a computer system.
[0041] In some embodiments, the systems and methods described herein may implemented by back-end (e.g., PHP), front-end (e.g., JavaScript), scripting (e.g., BASH, and structured languages (e.g., SQL). The embodiments described are merely exemplary to provide a better understanding of the disclosed. The systems and methods described are in no way limited to these certain languages. Additionally, one or more software extensions may be used, such as Composer packages, jQuery Library, Node.js, Node modules, and Gulp for building and compiling tasks, for example. Additionally, or alternatively, a plurality of third-party services and technologies may be used, such as AWS, Setasign, Pixelcave, and hundreds of Fedora OS packages, for example. Those of skill in the art will appreciate that the herein described apparatuses, engines, devices,1156048981.1Docket No. 394493.00010 systems and methods are susceptible to various modifications and alternative constructions. There is no intention to limit the scope of the invention to the specific constructions described herein. Rather, the herein described systems and methods are intended to cover all modifications, alternative constructions, and equivalents falling within the scope and spirit of the disclosure, any appended claims and any equivalents thereto.
[0042] Computer code replication refers to the process of duplicating or reproducing sections of code within a software program. It involves copying and pasting code snippets or entire functions to create multiple instances of the same logic in different parts of the program.
[0043] Code replication can occur for various reasons, such as code reuse, convenience, or performance optimization. However, excessive code replication can lead to several issues:
[0044] Code duplication: When the same logic is replicated across multiple places, any changes or bug fixes must be applied to each instance individually. This makes the codebase more difficult to maintain and increases the likelihood of introducing inconsistencies or errors.
[0045] Increased code size: Replicating code can result in larger codebases, leading to decreased readability and increased complexity. This can make the code harder to understand, debug, and maintain.
[0046] Reduced flexibility: If similar functionality is replicated instead of being abstracted into reusable functions or modules, it becomes harder to modify or extend that functionality in the future. Making changes in one place may1256048981.1Docket No. 394493.00010 require updating multiple instances, which can be time-consuming and error-prone.
[0047] Maintenance challenges: With code replication, it becomes challenging to ensure that all replicated instances are kept up to date and consistent It can be harder to track down bugs or apply updates across multiple copies of the same code.
[0048] To mitigate these issues, software developers often strive for code reuse and modular design. By abstracting common functionality into reusable components, such as functions, classes, or libraries, they can reduce code replication and improve maintainability, readability, and overall software quality.
[0049] A computer code repository, also known as a code repository or source code repository, is a central location or storage system where developers can store, manage, and collaborate on computer code. It serves as a version control system that keeps track of changes made to the codebase over time and provides a platform for collaboration among multiple developers.
[0050] Code repositories are used to facilitate software development by offering the following features:
[0051] Version control: Code repositories enable developers to track changes to their codebase over time. They provide mechanisms to create new versions of the code, compare differences between versions, and revert to previous versions if needed. This helps manage code history, allows collaboration1356048981.1Docket No. 394493.00010 between developers, and provides a way to review and manage code changes.
[0052] Collaboration: Code repositories allow multiple developers to work together on the same codebase. They provide features like branching and merging, which enable developers to work on separate versions of the code and later integrate their changes. Collaboration tools such as issue tracking, comments, and pull requests facilitate communication and coordination among team members.
[0053] Backup and recovery: By storing code in a code repository, developers have a centralized backup of their codebase. In case of accidental data loss or system failures, the code can be recovered from the repository. Repositories often have backup and redundancy measures in place to ensure the safety and availability of code.
[0054] Code sharing and reuse: Code repositories provide a platform for sharing code with others. Developers can make their code public, allowing others to view, clone, and use their code in their own projects. This promotes code reuse, knowledge sharing, and collaboration within the developer community.
[0055] Commonly used code repository systems include Git (along with platforms like GitHub, GitLab, and Bitbucket), Subversion (SVN), and Mercurial. These systems offer command-line tools and web-based interfaces to interact with the code repository, manage code versions, and collaborate with other developers.1456048981.1Docket No. 394493.00010
[0056] In an embodiment of the present invention, a code vault may be provided to store uploaded code. Ability to upload code from archives (zip / tar etc) or connect to code repositories as sources. However the code is provided, the platform will create a secure “image” of the code. This becomes the user’s one true source of their IP. They can review the code in this vault and can re-upload with new code archives, or re-sync with code repositories if needed. Full auditable version history with ability to restore previous versions
[0057] Once vaulted, users will have the ability to replicate their entire IP codebase as many times as they want. Each replication is a private, self-contained server with full root terminal access and cloud based code editor (Microsoft VSCode Server).
[0058] Code inside a replication can be editable, or readonly, and because each replication is a self-contained server, there’s no risk that the original IP can be affected accidentally. If the IP has a web element to it (i.e. a web app, website etc) then each replication will be viewable in a browser to review / test web interfaces. Each replication may be disposable and can simply be deleted. Or a replication can become the new version of the IP (once reviewed and approved by an account manager).
[0059] This could be used for many purposes, such as: creating a new editable version of the IP that developers could be invited to to work on, which can then become the new IP version after review, creating a read only version of the IP that potential investors or security analysts can review, before the1556048981.1Docket No. 394493.00010 replication is deleted, spinning off a version of the IP that can be changed to become a new product, without affecting the original IP. There will be a full history of all replication actions and changes.
[0060] Once vaulted and analysis processes have been ran, the user will be presented with a modern interactive dashboard that can have charts and widgets for data such as: How many lines of code the IP contains; How many files, and what languages they are; If third party packages are used, what are they and are they outdated? (will have to be a supported programming language); Any known security vulnerabilities within the code from vulnerability databases; Any detected malware within the code; If the source of code was a GIT repository, how many contributors have worked on the IP and what are their stats (i.e. how many changes, most recent changes) (will depend on a supported GIT platform - i.e. github, gitlab); Potentially an analysis of coding standards and quality of code.
[0061] In an embodiment of the present invention, an analysis dashboard may be downloadable as a presentable PDF containing all of the facts.
[0062] Using a specially curated and patented valuation algorithm using various factors including the codebase and details of the business model, The present invention may give an IP a monetary valuation and may estimate how many man hours and time / cost it would take to replicate the user’s IP, based on various factors.
[0063] Monetarily evaluating computer code can be a complex task, and the approach to valuation may vary depending on the specific circumstances1656048981.1Docket No. 394493.00010 and context. Here are a few common methods used to monetarily evaluate computer code:
[0064] Cost-based approach: This approach focuses on the cost required to develop or maintain the code. It involves evaluating the resources, time, and effort invested in creating the code. Factors such as development hours, personnel costs, software and hardware expenses, and ongoing maintenance costs are considered. This method provides a rough estimate of the value based on the expenses incurred.
[0065] Market-based approach: In this approach, the value of the code is determined by assessing the market demand and pricing for similar code or software products. Comparable sales, licensing fees, or benchmarking against similar products in the market can be used to estimate the value. This method relies on market research and analysis to determine the value based on supply and demand dynamics.
[0066] Income-based approach: This approach focuses on estimating the potential income or financial benefits that can be generated by the code. It involves evaluating factors such as projected revenue, cost savings, increased efficiency, and potential market share. This method is often used for evaluating commercial software products or codebases with revenuegenerating potential.
[0067] Royalty-based approach: If the code is intended for licensing or royaltybased revenue models, this approach can be used. The value is determined by estimating the potential royalty payments or licensing fees that can be1756048981.1Docket No. 394493.00010 generated from the code over a specific period. Factors such as market size, expected usage, and licensing terms are considered in this approach.
[0068] The present invention may utilize an Al chatbot with a name and avatar, using the OpenAI set of APIs and the latest GPT4 model and plugin functionality. Users may be able to ask questions / tasks such as; “Who has contributed the most code on my IP?”; “What are the 3 primary languages or technologies used in my IP?”; “Please write a brief for a new development team explaining how the IP works so they can develop it further”; “What packages or languages are out of date?”; “What are the most important out of date packages which we should get fixed ASAP?”; and “Who can I talk to about selling my product?”, for example.
[0069] In an embodiment of the present invention, the IP Replication functionality may be used from third party databases, such as from Clonr, for example.
[0070] The present invention may us a service, such as, for example, the Microsoft Azure cloud. One of the driving decisions for this is that a lot of their serverless services can be “scale-to-zero” by default. Which means we can do things like create replications and servers that don’t cost anyone anything when they’re “idle” (not actively being used).
[0071] The present invention may have an architecture covering all of the above features. For example, the main portal website may be built with Laravel as the backend, and VueJS as the responsive frontend. It may also be hosted on Azure App Service. The database may be using an Azure MySQL server, and any files will be stored on Azure Blob Storage (Azure’s version of AWS1856048981.1Docket No. 394493.00010S3). Each IP vault may be a container image, stored on Azure’s secure container registry using “encryption at rest” for maximum security of any IP code. Each IP code replication may use Azure’s Container App service, with “scale-to-zero” configured by default
[0072] There may be various Python functions developed using Azure Functions, which will be triggered by various events. For example once a vault is created, an analysis function will be triggered that will analyze the code for primary languages, total lines of code and more. The present invention may also use OpenAI API with the GPT4 model, and developing a ChatGPT plugin to enable the Al Assistant to consume information about the user’s IP vaults and answer questions.
[0073] In an exemplary embodiment, systems and methods may be provided for the risk evaluation of deployed software code and an automatically generated insurance policy covering at least part of the identified risk.
[0074] In the foregoing detailed description, it may be that various features are grouped together in individual embodiments for the purpose of brevity in the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that any subsequently claimed embodiments require more features than are expressly recited.
[0075] Further, the descriptions of the disclosure are provided to enable any person skilled in the art to make or use the disclosed embodiments. Various modifications to the disclosure will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other1956048981.1Docket No. 394493.00010 variations without departing from the spirit or scope of the disclosure. Thus, the disclosure is not intended to be limited to the examples and designs described herein, but rather is to be accorded the widest scope consistent with the principles and novel features disclosed herein.2056048981.1
Claims
Docket No. 394493.00010Claims1 . A system comprising a server having a memory and a processor, the memory containing instructions configured to cause the processor to: synchronize a code vault database with a user’s code repository; receive a set of code from the user’s code repository; detect a security vulnerability in the set of code; detect malware within the set of code; detect third-party packages within the set of code, determine whether the third- party packages are outdated, and determine whether the third-party packages are subject to a commercial license; estimate a valuation of the intellectual property represented by the set of code; estimate an amount of monetary risk incurred by use of the set of code; and recommend an insurance product based on the amount of monetary risk.
2. The system of claim 1 , wherein the instructions are further configured to cause the processor to edit the set of code such that the amount of monetary risk incurred by use of the set of code is reduced.2156048981.1
Citation Information
Patent Citations
Digital information infrastructure and method
US20090254572A1
Probabilistic Model For Cyber Risk Forecasting
US20150381649A1
System and method for assessing cybersecurity risk of computer network
US20190052664A1
Methods and systems for detecting reconnaissance and infiltration in data lakes and cloud warehouses
US20240106847A1