DCT

1:26-cv-02342

QuickVault Inc v. IBM Corp

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification:
    • Case Name: QuickVault, Inc. v. International Business Machines Corporation
    • Case Number: 1:26-cv-02342, W.D. Tex., 08/26/2026
  • Venue Allegations: Plaintiff alleges venue is proper in the Western District of Texas because Defendant IBM has committed acts of infringement in the District and maintains a regular and established place of business there, including an office in Austin.
  • Core Dispute: Plaintiff alleges that Defendant's IBM Guardium portfolio of data security products infringes six patents related to methods and systems for forensic data tracking.
  • Technical Context: The technology concerns enterprise data security, specifically the tracking and management of sensitive data elements across computer networks to prevent unauthorized access and data leakage, a critical function for entities subject to regulations like HIPAA.
  • Key Procedural History: The complaint alleges that Defendant had pre-suit knowledge of its infringement based on a license offer made in "early 2026" and, in any event, no later than a written notice sent on June 5, 2026. These allegations may form the basis for a claim of willful infringement.

Case Timeline

Date Event
2014-09-12 Earliest Priority Date ('134, '125, '840, '300, '092, '200 Patents)
2015-01-01 QuickVault creates its CloudVault® Health business unit
2017-02-07 U.S. Patent No. 9,565,200 Issues
2018-05-01 U.S. Patent No. 9,961,092 Issues
2021-05-04 U.S. Patent No. 10,999,300 Issues
2023-04-25 U.S. Patent No. 11,637,840 Issues
2024-02-06 U.S. Patent No. 11,895,125 Issues
2025-07-15 U.S. Patent No. 12,363,134 Issues
Early 2026 Alleged license offer made to IBM
2026-06-05 Alleged written notice of infringement sent to IBM
2026-08-26 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 12,363,134 - "Method and System for Forensic Data Tracking"

  • Patent Identification: U.S. Patent No. 12,363,134, "Method and System for Forensic Data Tracking," issued July 15, 2025.

The Invention Explained

  • Problem Addressed: The patent family addresses the shortcomings of existing security measures (like firewalls and encryption) that fail to track and protect sensitive data, such as Protected Health Information (PHI), once it moves outside of a secure, authorized environment (e.g.,'300 Patent, col. 2:29-52). This creates compliance risks under regulations like HIPAA, as organizations lose visibility and control over data leakage to unauthorized users or devices '300 Patent, col. 2:6-12
  • The Patented Solution: The invention describes a "Forensic Computing Platform" that deploys software agents on network endpoints to scan for sensitive data (('134 Patent, Exhibit A, Fig. 1)). These agents create and transmit "meta logs"-containing information like file name, data classification, user name, and endpoint ID-to a central cloud server for analysis, alerting, and reporting (('134 Patent, Exhibit A, Fig. 2)). The system can also encode files with tracking elements, allowing their movement to be monitored even on unauthorized devices, thereby maintaining a "forensic" trail of the data's provenance (('134 Patent, Exhibit A, col. 9:22-40)).
  • Technical Importance: The technology aimed to extend data governance beyond the network perimeter, providing a method to track data provenance and detect policy violations in environments where traditional data loss prevention (DLP) tools were ineffective (('134 Patent, Exhibit A, col. 2:41-52)).

Key Claims at a Glance

The complaint asserts claim 1 of the '134 Patent (Compl. ¶29). As the complaint does not contain the full text of the patent, the following claim breakdown is based on representative claim language from a related, asserted patent in the same family (U.S. Patent No. 10,999,300).

  • Essential elements of a representative independent claim include:
    • A forensic computing platform deployed as a cloud control server comprising an analytic component, a reporting component, an alerting component, and various databases.
    • At least one endpoint with modules to detect, classify, and perform actions on data.
    • Receiving a "meta log" from an endpoint, the log comprising a file name, data element tags, a date, and an endpoint ID.
    • Storing the meta log in a meta database on the cloud server.
    • Analyzing the data element tags based on a configured setting to determine a data classification.
    • Predicting data breaches based on changes in data topology.
  • The complaint reserves the right to assert "one or more claims" of the '134 Patent (Compl. ¶27).

U.S. Patent No. 11,895,125 - "Method and System for Forensic Data Tracking"

  • Patent Identification: U.S. Patent No. 11,895,125, "Method and System for Forensic Data Tracking," issued February 6, 2024.

The Invention Explained

  • Problem Addressed: As with the '134 Patent, the '125 Patent addresses the inability of conventional security systems to prevent the leakage of sensitive data and track its movement and use, particularly once it is downloaded to an unsecure computer or shared with an unauthorized user (('125 Patent, Exhibit B, col. 2:29-52)).
  • The Patented Solution: The invention provides a system architecture where agents on endpoints communicate with a central server (('125 Patent, Exhibit B, Fig. 1)). This architecture enables functions to "detect, catalog, secure, deliver, control, and monitor" data movement (('125 Patent, Exhibit B, Fig. 3)). By creating and analyzing logs of data activity from across the network, the system can identify and predict policy violations (('125 Patent, Exhibit B, Fig. 20)).
  • Technical Importance: The described solution provides a framework for comprehensive data governance that focuses on the data itself, rather than just the network perimeter, enabling enterprises to manage regulatory compliance and risk more effectively (('125 Patent, Exhibit B, col. 2:53-59)).

Key Claims at a Glance

The complaint asserts claim 1 of the '125 Patent (Compl. ¶39). As the complaint does not contain the full text of the patent, the following claim breakdown is based on representative claim language from a related, asserted patent in the same family (U.S. Patent No. 10,999,300).

  • Essential elements of a representative independent claim include the same core components as described for the '134 Patent, such as a cloud server, endpoint agents, and the creation, transmission, and analysis of meta logs for data classification and activity monitoring.
  • The complaint reserves the right to assert "one or more claims" of the '125 Patent (Compl. ¶37).

Multi-Patent Capsule: U.S. Patent No. 11,637,840

  • Patent Identification: U.S. Patent No. 11,637,840, "Method and System for Forensic Data Tracking," issued April 25, 2023 (Compl. ¶18).
  • Technology Synopsis: This patent, part of the same family, describes a system for tracking data elements as they move between devices and users. It addresses the problem of data leakage and the need to maintain an audit trail for sensitive information to comply with regulations (('840 Patent, Exhibit C, abstract)).
  • Asserted Claims: Claim 1 is asserted (Compl. ¶49).
  • Accused Features: The complaint alleges that the functions of IBM's Guardium agents and appliances for detecting, classifying, and tracking data infringe the '840 Patent (Compl. ¶6).

Multi-Patent Capsule: U.S. Patent No. 10,999,300

  • Patent Identification: U.S. Patent No. 10,999,300, "Method and System for Forensic Data Tracking," issued May 4, 2021 (Compl. ¶20).
  • Technology Synopsis: This patent discloses a system for tracking the movement of data between authorized and unauthorized devices and users. The solution involves a cloud-based server that receives and analyzes meta logs from agents on endpoints to monitor data and report on policy violations (('300 Patent, abstract)).
  • Asserted Claims: Claim 1 is asserted (Compl. ¶59).
  • Accused Features: The complaint alleges that the functions of IBM's Guardium agents and appliances for detecting, classifying, and tracking data infringe the '300 Patent (Compl. ¶6).

Multi-Patent Capsule: U.S. Patent No. 9,961,092

  • Patent Identification: U.S. Patent No. 9,961,092, "Method and System for Forensic Data Tracking," issued May 1, 2018 (Compl. ¶22).
  • Technology Synopsis: This patent describes a system for forensic data tracking that addresses the need to monitor sensitive data as it is shared across networks. The system uses a central server and endpoint agents to discover, classify, and track data, and to remediate policy violations (('092 Patent, Exhibit E, abstract)).
  • Asserted Claims: Claim 1 is asserted (Compl. ¶69).
  • Accused Features: The complaint alleges that the functions of IBM's Guardium agents and appliances for detecting, classifying, and tracking data infringe the '092 Patent (Compl. ¶6).

Multi-Patent Capsule: U.S. Patent No. 9,565,200

  • Patent Identification: U.S. Patent No. 9,565,200, "Method and System for Forensic Data Tracking," issued February 7, 2017 (Compl. ¶24).
  • Technology Synopsis: This patent, the earliest issued in the asserted family, outlines the foundational system for tracking data elements. It describes a client-server architecture for monitoring data on endpoints, analyzing activity, and reporting on policy violations to maintain data provenance (('200 Patent, Exhibit F, abstract)).
  • Asserted Claims: Claim 1 is asserted (Compl. ¶79).
  • Accused Features: The complaint alleges that the functions of IBM's Guardium agents and appliances for detecting, classifying, and tracking data infringe the '200 Patent (Compl. ¶6).

III. The Accused Instrumentality

Product Identification

  • The accused instrumentalities are IBM's Guardium portfolio of data security products and services, including Guardium Data Security Center, Guardium Data Protection, Guardium Discover and Classify, Guardium Insights, and related agents (such as S-TAP), appliances, and components (collectively, the "Accused Products") (Compl. ¶5).

Functionality and Market Context

  • The complaint alleges the Accused Products operate as a "unified platform" managing the "full data security lifecycle, from discovery to remediation" (Compl. ¶5). A central function is the use of software agents deployed on endpoints and servers. These agents are alleged to detect, classify, and track data; collect and transmit metadata to central Guardium appliances; and enable administrators to monitor, analyze, and remediate policy violations (Compl. ¶6).
  • The complaint provides a diagram, labeled Figure 1, illustrating how the accused File Activity Monitoring (FAM) functionality uses a Guardium appliance in coordination with agents (S-TAP) and a classifier on a UNIX file server to create a file activity audit Compl. p. 3, Fig. 1 A similar diagram for Windows file servers is also included Compl. p. 3, Fig. 2 These visuals depict the core client-server architecture that Plaintiff alleges infringes its patents.

IV. Analysis of Infringement Allegations

The complaint references external exhibits for its detailed infringement charts, which are not provided in the document (Compl. ¶29; Compl. ¶39). Therefore, the infringement analysis is summarized in prose based on the narrative allegations in the complaint.

'134 Patent Infringement Allegations

  • The complaint alleges that the Accused Products directly infringe at least claim 1 of the '134 Patent (Compl. ¶29). The infringement theory is that the Accused Products embody the claimed system by deploying software agents on endpoints to detect and classify data, which then transmit metadata to central Guardium appliances for monitoring, analysis, and remediation (Compl. ¶6). The complaint further alleges that for any method claims, the steps are performed either directly by IBM or by its customers acting under IBM's direction and control (Compl. ¶29).

'125 Patent Infringement Allegations

  • The infringement allegations for the '125 Patent are substantively identical to those for the '134 Patent. The complaint asserts that the Accused Products' agent-based architecture for data discovery, classification, monitoring, and remediation directly infringes at least claim 1 of the '125 Patent (Compl. ¶6; Compl. ¶39). It similarly alleges divided infringement liability, where customers perform certain claimed steps under IBM's direction and control (Compl. ¶39).

Identified Points of Contention

  • Scope Questions: A central dispute may arise over the meaning of "forensic data tracking," a term used in the titles of all asserted patents. The court may need to determine if this term limits the claims to after-the-fact investigations of data breaches, or if it can be construed more broadly to cover the real-time data security and activity monitoring functions that the complaint alleges the IBM Guardium platform performs.
  • Technical Questions: An evidentiary question will be whether the data transmissions from IBM's agents (e.g., S-TAP) to its appliances meet the specific definition of a "meta log" as required by representative claims. The analysis will likely focus on whether the accused data packets contain the specific elements recited in the claims (e.g., file name, data classification, user name, endpoint ID) and are processed by the server in the claimed manner.

V. Key Claim Terms for Construction

The complaint does not provide sufficient detail for analysis of specific claim terms as the full patent texts and claim chart exhibits are not included. However, based on the patents' titles and general descriptions, the following terms are likely to be central to the dispute.

The Term: "forensic data tracking"

  • Context and Importance: This term appears in the title of every asserted patent and is foundational to the claimed invention. Practitioners may focus on this term because its construction could be case-dispositive. Defendant may argue that its Guardium products perform "data security" or "activity monitoring," not "forensic" tracking, attempting to frame the patented invention as being limited to post-breach investigation, a potentially narrower field of use than real-time security.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification's summary states the invention relates to "tracking the movement of data elements as they are shared and moved," without an explicit limitation to post-breach scenarios (e.g.,'300 Patent, abstract). The background's focus on meeting regulatory requirements like HIPAA suggests a broad applicability to general data security and compliance (e.g.,'300 Patent, col. 1:45-53).
    • Evidence for a Narrower Interpretation: The term "forensic" itself carries a strong connotation of scientific investigation for use in a court of law. Defendant may argue that the repeated use of this term limits the claims to a post-hoc investigative purpose, distinguishing it from the preventative, real-time nature of a data security product.

The Term: "meta log"

  • Context and Importance: This term defines the specific data structure that is transmitted from the endpoint agent to the central server. The infringement analysis will depend on whether the data packets used in the Accused Products meet the structural and content requirements of the claimed "meta log."
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification provides an exemplary, non-limiting list of contents, including "file name, data classification, date created or modified, user name, and endpoint ID" (e.g.,'300 Patent, col. 3:20-24). Plaintiff may argue that any data transmission containing this type of information qualifies as a "meta log."
    • Evidence for a Narrower Interpretation: Defendant may point to specific figures and descriptions of the "meta log" and its processing to argue for a more rigid structural definition (e.g.,'300 Patent, Fig. 2). If IBM's agent-to-server communications are structured differently or omit a required element, it could support a non-infringement argument.

VI. Other Allegations

Indirect Infringement

  • The complaint alleges that IBM induces infringement by providing the Accused Products to its customers and intentionally encouraging infringing use through its "publication of its Guardium product listings and descriptions," "documentation," and "support materials" (Compl. ¶32; Compl. ¶34; Compl. ¶42; Compl. ¶44). The complaint also asserts theories of divided infringement, alleging customers perform some steps of the claimed methods under IBM's "direction and control" (Compl. ¶29; Compl. ¶39).

Willful Infringement

  • Willfulness is alleged based on IBM's purported knowledge of the Asserted Patents prior to the lawsuit. The complaint specifically alleges that IBM had knowledge via "a license offer made in early 2026" and a subsequent "written notice" on June 5, 2026, but "nevertheless continued its infringing conduct" (Compl. ¶30; Compl. ¶40; Compl. ¶50).

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue will be one of definitional scope: can the term "forensic data tracking," which is central to the identity of the asserted patents, be construed broadly enough to read on the functions of a commercial, real-time "data security" platform like IBM Guardium, or will the term's investigative connotation limit the claims to a narrower, after-the-fact application?
  • A key evidentiary question will be one of technical correspondence: does the architecture of the IBM Guardium platform, particularly the specific content and structure of the data transmitted from its endpoint agents (e.g., S-TAPs) to its central appliances, meet the specific structural and functional limitations of the "meta log" as required by the asserted claims?
  • A third question will concern knowledge and intent: what evidence will emerge regarding the alleged "license offer" in early 2026 and the subsequent notice letter, and will this evidence be sufficient to support a finding of willful infringement should liability be established?