DCT
7:26-cv-00229
Congruent Media Resourcing LLC v. Hiddenlayer Inc
Key Events
Amended Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Congruent Media Resourcing LLC (Texas)
- Defendant: HiddenLayer, Inc. (Delaware)
- Plaintiff’s Counsel: Direction IP
- Case Identification: 7:26-cv-00229, W.D. Tex., 09/11/2026
- Venue Allegations: Venue is alleged to be proper as Defendant maintains a place of business within the Western District of Texas.
- Core Dispute: Plaintiff alleges that Defendant’s AI Security Platform infringes a patent related to methods for creating secure applications by modifying their executable structure to intercept and override their native behavior at runtime.
- Technical Context: The technology resides in the field of application security, specifically addressing the challenge of enforcing security policies on software applications, such as AI agents, in environments where traditional perimeter-based defenses are insufficient.
- Key Procedural History: The filing is a First Amended Complaint, indicating it supersedes an Original Complaint previously filed in the matter. The complaint alleges Defendant became aware of the patent-in-suit at least as of the service date of the Original Complaint.
Case Timeline
| Date | Event |
|---|---|
| 2011-10-10 | U.S. Patent No. 9,135,418 Priority Date |
| 2015-09-15 | U.S. Patent No. 9,135,418 Issues |
| 2026-03-24 | Date of HiddenLayer article on "Securing AI Agents" |
| 2026-09-11 | First Amended Complaint for Patent Infringement is Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,135,418: System and Method for Creating Secure Applications (issued Sep. 15, 2015)
The Invention Explained
- Problem Addressed: The patent describes the security risks arising from corporate data being accessed on employees' personal devices (e.g., smartphones) (Compl. ¶13; ’418 Patent, col. 1:25-33). These devices may run untrusted applications containing malware, exposing corporate applications and data to security breaches in an environment where the traditional network "perimeter" is dissolved (’418 Patent, col. 1:28-41).
- The Patented Solution: The invention provides a method for transforming a "target application" into a "secure application" without needing access to the original source code (’418 Patent, abstract). This is achieved by identifying predictable instructions within the application and binding one or more "intercepts" to it (’418 Patent, col. 1:54-57). These intercepts modify the application's behavior at runtime to enforce security policies, such as redirecting API calls or preventing unsafe operations (Compl. ¶24; ’418 Patent, col. 1:57-61). The modified application is then "repackaged" so the intercepts become "physically inseparable," creating an "immutable deployable entity" that resists tampering while remaining compatible with its intended operating system (’418 Patent, col. 2:4-21).
- Technical Importance: The complaint asserts that at the time of the invention (2011-2012), this "app wrapping" technique addressed a technical deficiency, as commercial tools did not exist to safely decompile, modify, and repackage third-party applications to enforce fine-grained runtime control Compl. ¶16
Key Claims at a Glance
- The complaint asserts independent claims 1 and 9 Compl. ¶35
- Claim 1 (Method of operating a secure application):
- Receiving a request to activate a secure application, where the secure application was created from a target application with a first behavior and now has a second, imposed behavior.
- In response, forcing the secure application to override the first behavior with the second behavior, which takes priority.
- Performing the second application behavior via a processing unit.
- Claim 9 (Method of generating a secure application):
- Receiving a target application designed to interact with an operating system.
- Configuring the target by imposing intercepts, converting it into a secure application that maintains OS interaction.
- Repackaging the secure application so the intercepts are integrated and inseparable.
III. The Accused Instrumentality
Product Identification
The complaint identifies the "HiddenLayer AI Security Platform," which includes features such as "AI Runtime Security" and "AI Detection & Response ('AIDR')" Compl. ¶35 Compl. ¶36 Compl. ¶40
Functionality and Market Context
- The accused platform is a security solution designed to protect AI applications, including autonomous "agentic" AI, from threats like prompt injection, data leakage, and misuse Compl. ¶36 It is described as an "inseparable orchestration layer deeply integrated into the AI application" Compl. ¶22
- The platform allegedly operates by having its "guardrails actively intercept" system calls made by an AI agent (the "target application") Compl. ¶22 It then "physically override[s] the agent's native intent, forcing the application to adopt a secure alternative behavior" Compl. ¶22 The complaint alleges this process creates a "secure application" (an AI agent with the HiddenLayer solution applied) from the original AI agent Compl. ¶36 A screenshot from Defendant's website describes this as defining "deterministic controls, rules that make certain actions impossible regardless of the model's intent" Compl. ¶38 Compl. p. 17
- The complaint positions the accused platform at the "current apex of the cybersecurity evolution," addressing security needs for Non-Human Identities (NHI) where traditional security models are alleged to fail Compl. ¶¶21-22
IV. Analysis of Infringement Allegations
U.S. Patent No. 9,135,418 Infringement Allegations (Claim 1)
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| receiving a request to activate the secure application... wherein the secure application was created from a target application having a first set of functions associated with a first application behavior and the secure application has a second set of functions that are imposed... and that are associated with a second application behavior | The "target application" is an AI Agent, which has a "first set of functions" described as its native risk profile (e.g., interpreting goals, lacking context) Compl. ¶37 The "secure application" is the AI Agent combined with HiddenLayer's runtime enforcement layer Compl. ¶37 This secure application has a "second set of functions," which includes "specific detection at the input and context layer of agent execution," imposed on the AI Agent's functions Compl. ¶37 A visual in the complaint explicitly maps these claim terms to the accused functionality Compl. ¶37 Compl. p. 19 | ¶37 | col. 6:20-25 |
| in response to the receipt of the request, forcing the secure application to override the first application behavior with the second application behavior, wherein the second application behavior takes priority over the first application behavior | HiddenLayer's guardrails act as intercepts that take priority over the AI Agent's native functions, preventing the original behavior and substituting a secure one Compl. ¶38 An "Automated Response" feature detects and blocks malicious activity, which the complaint alleges constitutes this override Compl. ¶38 A screenshot shows the platform's detection model "classifies inputs prior to execution, operating outside the agent's reasoning process," which allows it to stop malicious instructions "before any action is taken" Compl. ¶38 Compl. p. 22 | ¶38 | col. 6:25-32 |
| via a processing unit, performing the second application behavior | The secure application (agent + guardrail layer) performs the second behavior by executing HiddenLayer's enforcement logic Compl. ¶39 This involves enforcing policies to stop unsafe actions, moving beyond simple alerts to take "action by performing a second application behavior" Compl. ¶39 An accompanying graphic shows "Agentic Detection & Enforcement" to "stop unsafe actions" Compl. ¶39 Compl. p. 23 | ¶39 | col. 6:32-34 |
U.S. Patent No. 9,135,418 Infringement Allegations (Claim 9)
| Claim Element (from Independent Claim 9) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| receiving a target application that is designed to interact with an operating system | The "target application" is identified as an "agentic AI model software" that interacts with other agents in an operating system Compl. ¶41 A graphic from Defendant's materials describes how "Agentic AI turns models into actors" Compl. ¶41 Compl. p. 28 | ¶41 | col. 4:22-24 |
| configuring the target application by imposing one or more intercepts on the target application, wherein the imposition of the intercepts converts the target application into a secure application... | HiddenLayer's platform allegedly imposes "intercepts" on the target application by embedding security practices, such as during pre-production or at runtime Compl. ¶42 A diagram shows that security checks ("intercepts") occur throughout development, CI/CD, and production phases to create a secure application Compl. ¶42 Compl. p. 29 The complaint points to a workflow diagram where "intercepts [are] embedded" into the process Compl. ¶42 Compl. p. 30 | ¶42 | col. 4:40-42 |
| and repackaging the secure application such that the intercepts are integrated with the secure application and are inseparable from the secure application | The complaint alleges that after a malicious pattern is detected, the HiddenLayer AIDR platform is "hardened, resulting in a secure application for which intercepts are integrated" Compl. ¶43 A screenshot describing "Continuous Defense" is annotated to map the function of feeding "insights back into defense tuning" to the claim language of "repackaging the secure application such that the intercepts are integrated... and are inseparable" Compl. ¶43 Compl. p. 31 | ¶43 | col. 2:4-10 |
- Identified Points of Contention:
- Scope Questions: A central question may be whether the patent's teachings on modifying compiled applications ("app wrapping") can be extended to cover the accused product's architecture, which is a dynamic, runtime security proxy for AI agents. Does the accused product's runtime interception and control of an AI agent constitute the creation of a new "secure application" as contemplated by the patent?
- Technical Questions: The analysis of Claim 9 will likely focus on the "repackaging... such that the intercepts are... inseparable" limitation. The patent specification describes this as creating an "immutable deployable entity" through modification of the application's files (’418 Patent, col. 2:7-10). The complaint’s allegation is that a continuous defense feedback loop makes the security integral and thus "inseparable" Compl. ¶43 The court may have to determine if this dynamic, behavior-based integration is technically equivalent to the static, file-based "repackaging" described in the patent.
V. Key Claim Terms for Construction
- The Term: "repackaging the secure application such that the intercepts are integrated with the secure application and are inseparable from the secure application" (Claim 9)
- Context and Importance: This term appears to be the fulcrum of the dispute for Claim 9. The patent was developed in the context of modifying compiled mobile applications. The accused product is a modern AI security platform. Practitioners may focus on this term because its construction will determine whether the patent's concept of a static, file-level modification can read on the accused product's dynamic, runtime security architecture.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent’s objective is to "prevent the secure application from having the intercepts removed by an unauthorized party" (’418 Patent, col. 2:10-11). A party could argue that any technical means that achieves this goal of tight, tamper-resistant integration, including a dynamic runtime system that is deeply intertwined with an application's execution, falls within the scope of "integrated and inseparable."
- Evidence for a Narrower Interpretation: The specification repeatedly describes the process in terms of modifying an application's files. It mentions a "disassembler" that deconstructs an application into files, followed by a "repackager" that creates a "modified application" (’418 Patent, Fig. 11; col. 22:58-24:21). This language suggests a specific process of creating a new, statically modified executable file, which could support a narrower definition that excludes dynamic, proxy-based runtime systems.
VI. Other Allegations
- Indirect Infringement: The complaint alleges both induced and contributory infringement Compl. ¶44 The basis for inducement is the allegation that Defendant advertises and provides its platform to customers with the specific intent that they use it in an infringing manner, citing marketing materials and instructional videos as evidence Compl. ¶44 Compl. ¶45 The contributory infringement claim alleges the platform is a material part of the invention and is not a staple article of commerce suitable for substantial non-infringing use Compl. ¶46
- Willful Infringement: The complaint alleges willful infringement based on Defendant's continued infringement after becoming aware of the ’418 patent, with knowledge alleged to have begun "at least as of the date of the service of the Original Complaint" Compl. ¶45
VII. Analyst’s Conclusion: Key Questions for the Case
- A core issue will be one of technological scope: can the term "repackaging... such that the intercepts are... inseparable," which is rooted in the patent's description of statically modifying compiled application files to create an "immutable" entity, be construed to cover the accused product's dynamic, runtime security proxy that continuously monitors and controls autonomous AI agents?
- A related central question will be one of definitional equivalence: does the combination of an AI agent and the accused runtime security platform constitute a single, new "secure application" that is "forced to override" its original behavior, as required by Claim 1? Or do they remain two separate entities, with one externally monitoring the other, creating a potential mismatch with the patent's description of an integrated, modified application?
Analysis metadata