DCT

3:26-cv-02654

Congruent Media Resourcing LLC v. Zscaler Inc

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 3:26-cv-02654, N.D. Tex., 08/10/2026
  • Venue Allegations: Venue is alleged to be proper based on Defendant maintaining a place of business in the Northern District of Texas.
  • Core Dispute: Plaintiff alleges that Defendant's Zscaler AI Guard, a security service for artificial intelligence applications, infringes a patent related to methods for creating and operating secure applications.
  • Technical Context: The lawsuit concerns the field of application security, specifically the technique of "application wrapping" or "securitization," where an existing software application is modified to enforce security policies without altering its source code.
  • Key Procedural History: The complaint does not mention any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the patent-in-suit.

Case Timeline

Date Event
2011-10-10 Priority Date for U.S. Patent No. 9,135,418
2015-09-15 U.S. Patent No. 9,135,418 Issued
2026-08-10 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 9,135,418 - "System and Method for Creating Secure Applications"

  • Patent Identification: U.S. Patent No. 9,135,418, "System and Method for Creating Secure Applications," issued September 15, 2015.

The Invention Explained

  • Problem Addressed: The patent addresses the security risks that arise when enterprises allow corporate data and applications on employees' personal mobile devices, which may contain malware or other insecure software '418 Patent, col. 1:22-41
  • The Patented Solution: The invention describes a method to transform a "target application" into a "secure application" by modifying it without access to its source code '418 Patent, col. 1:57-61 '418 Patent, abstract This is achieved by binding "intercepts" to the application, which can modify the application's behavior to enforce security policies '418 Patent, col. 1:54-61 The patent discloses techniques like byte-code injection or link injection to replace or augment the application's original functions, such as its API calls, with new, secure versions '418 Patent, col. 2:42-48 '418 Patent, col. 4:40-60 The modified application is then "repackaged" as a new, secure entity '418 Patent, col. 2:3-6
  • Technical Importance: This "application wrapping" approach allows for the centralized enforcement of security policies on third-party or existing applications without requiring source code modification, a significant advantage in enterprise environments managing diverse software on employee devices.

Key Claims at a Glance

  • The complaint asserts independent claim 1 '418 Patent, col. 40:45-63 Compl. ¶16
  • The essential elements of Claim 1, a method of operating a secure application, are:
    • Receiving a request to activate a secure application, where the secure application was created from a target application by imposing a second set of functions on the target's first set of functions.
    • In response to the request, forcing the secure application to override the first application behavior with a second application behavior that takes priority.
    • Via a processing unit, performing the second application behavior.
  • The complaint does not explicitly reserve the right to assert other claims.

III. The Accused Instrumentality

Product Identification

  • The accused instrumentality is Defendant's "Zscaler AI Guard" service Compl. ¶17

Functionality and Market Context

  • The complaint alleges that Zscaler AI Guard is a service providing "run-time protection" for AI applications by acting as a security gateway or "guardrail" Compl. ¶18 It is described as sitting between users and AI applications (such as large language models or chatbots) to provide "real time, inline protection" Compl. ¶18 Compl. ¶19
  • Its alleged technical function is to inspect both user prompts sent to an AI and the responses generated by the AI Compl. ¶20, p. 9 Based on this inspection, it applies enterprise policies to "prevent prompt injections, block jailbreak attempts, and stop personal information leakage" Compl. ¶18, p. 6 Policy actions include allowing, detecting, logging, blocking, or redacting content Compl. ¶20 The complaint includes a diagram from Defendant's materials showing Zscaler AI Guard positioned between "Employees" and various "LLMs" (Large Language Models), reinforcing its role as an intermediary security layer Compl. ¶19, p. 8

IV. Analysis of Infringement Allegations

'418 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
A method of operating a secure application, comprising: receiving a request to activate the secure application through an input device, wherein the secure application was created from a target application having a first set of functions associated with a first application behavior and the secure application has a second set of functions that are imposed on the first set of functions and that are associated with a second application behavior: Zscaler AI Guard operates on a target AI application (e.g., a GenAI chatbot) which has a native, unsecured behavior. AI Guard imposes security functions (the "second set") to create a secure, controlled interaction. A user request to the target AI app is routed through AI Guard, activating the secure method. ¶19 col. 6:20-30
in response to the receipt of the request, forcing the secure application to override the first application behavior with the second application behavior, wherein the second application behavior takes priority over the first application behavior; Upon receiving a user's prompt, AI Guard inspects it and the AI's response. It applies policies (e.g., "Prompt Inspection," "Response Inspection") that override the target AI's normal, unfiltered behavior by blocking, redacting, or otherwise altering the interaction. A visual in the complaint shows this inspection workflow. ¶20; ¶20, p. 9 col. 2:47-51
and via a processing unit, performing the second application behavior. AI Guard performs the policy action, such as blocking a malicious prompt or redacting sensitive data from a response. A table in the complaint lists these enforcement actions as the "second application behavior." ¶21; ¶21, p. 13 col. 6:30-32
  • Identified Points of Contention:
    • Scope Questions: Claim 1 recites a "secure application" that was "created from a target application". The patent specification describes this creation process as "repackaging" an application binary after injecting code or modifying links '418 Patent, col. 2:3-6 The complaint alleges Zscaler's AI Guard, a separate cloud service that filters network traffic to and from a target AI application, meets this limitation. This raises the question of whether the claimed "secure application" can be construed as a system of separate components (AI Guard + target AI) or if it requires a single, modified, and repackaged software entity as described in the patent's embodiments.
    • Technical Questions: The analysis may focus on whether AI Guard's interception and modification of data traffic constitutes "forcing the secure application to 'override' the first application behavior." A dispute may arise over whether this term requires altering the internal execution of the target application itself (as suggested by the patent's discussion of byte-code injection) or if merely intercepting and changing the inputs to and outputs from the application is sufficient.

V. Key Claim Terms for Construction

  • The Term: "secure application"

  • Context and Importance: The definition of "secure application" is central to the dispute. The claim requires that the accused method operates a "secure application" that was "created from a target application". The infringement theory depends on whether Zscaler's architecture, which uses a separate security service (AI Guard) to police a target AI application, can be considered a single "secure application" under the patent's definition.

  • Intrinsic Evidence for Interpretation:

    • Evidence for a Broader Interpretation: The claim language itself does not specify the physical or architectural relationship between the "target application" and the "secure application," only that the latter was "created from" the former by imposing new functions. This could support an argument that any system that imposes security functions on a target application qualifies.
    • Evidence for a Narrower Interpretation: The patent's abstract and summary consistently describe a process of modifying and "repackaging the secure application such that the bound intercepts are integrated with the original files" into an "immutable deployable entity" ('418 Patent, col. 2:3-10; '418 Patent, abstract). This language may support a narrower construction requiring a single, self-contained, modified application binary, which would raise questions about its applicability to Zscaler's separate proxy service.
  • The Term: "override the first application behavior"

  • Context and Importance: This term defines the core functional step of the claimed method. Whether Zscaler's filtering of prompts and responses meets this limitation will be a key point of contention.

  • Intrinsic Evidence for Interpretation:

    • Evidence for a Broader Interpretation: The plain meaning of "override" could be argued to include any action that takes precedence over and changes the outcome of another. Plaintiff may argue that by blocking a malicious prompt, AI Guard overrides the AI's native behavior of processing that prompt.
    • Evidence for a Narrower Interpretation: The specification explains that "override" means "to take priority over, and the behavior of the secure application may be based on the secure byte codes instead of the pre-existing byte codes" '418 Patent, col. 2:47-51 This explicit link to byte-code replacement could support a narrower construction requiring a modification of the application's internal execution path, not just filtering its external communications.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges both induced and contributory infringement Compl. ¶22 The basis for these claims is that Defendant provides the Zscaler AI Guard to its customers, along with marketing materials, user guides, and support that allegedly instruct and encourage customers to use the service in a manner that directly infringes claim 1 Compl. ¶¶22-24
  • Willful Infringement: The complaint does not contain a separate count for willful infringement. However, it alleges that Defendant has knowledge of its infringement "at least as of the date of the service of the Original Complaint" and continues to induce and contribute to infringement despite this knowledge Compl. ¶¶23-24 This forms a basis for a claim of post-suit willfulness.

VII. Analyst's Conclusion: Key Questions for the Case

The resolution of this case may depend on the court's determination of two central questions:

  • A core issue will be one of architectural scope: Can the patent's concept of a "secure application"-described in the specification as a single, repackaged software entity created by modifying a target application-be construed to cover Defendant's system, where a separate, network-based security service (Zscaler AI Guard) filters traffic for a distinct and unmodified target AI application?
  • A second key issue will be one of functional interpretation: Does Zscaler AI Guard's method of intercepting and filtering prompts and responses constitute "forcing the secure application to 'override' the first application behavior" as claimed, or does the term "override" require a more fundamental modification to the internal code or execution flow of the target application, as suggested by the patent's detailed examples of byte-code injection?
Loading Complaint