IP Library Granted Patent US 12,339,735
Granted Patent B2
US 12,339,735 · App. 18/234,833 · Granted Jun 24, 2025

Compliance tracking and remediation across a data sharing platform

Inventors: Chintan Mehta (San Ramon, CA); Jason Strle (San Francisco, CA)
Assignee: Wells Fargo Bank, N.A.
G06F11/0793G06F11/327G06F21/53H04L63/0272H04L67/133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,339,735
App. No.
18/234,833
Granted
Jun 24, 2025
Kind
B2
Abstract

A system, method, and computer-readable media for compliance tracking and remediation across a data sharing platform is provided. One method includes enabling a security tool and monitoring, via the security tool using at least one API, a website of an experience provider accessed by one or more user devices. Further the method includes detecting, via the security tool, a noncompliance event based on content accessed by the one or more user devices and served by the experience provider that is noncompliant with at least one data sharing preference and providing, using the at least one API, a pop-up on a graphical user interface (GUI) of a client application. Further the method includes receiving a remediation selection and remediating, via the security tool using the at least one API, the detected noncompliance event according to the remediation selection based on executing an API call.

Claims (45)

1. A method comprising:

enabling, by a computing system, a security tool;

monitoring, by the computing system via the security tool using at least one API, a website of an experience provider accessed by one or more user devices;

detecting, by the computing system and via the security tool, a noncompliance event based on content accessed by the one or more user devices and served by the experience provider that is noncompliant with at least one data sharing preference of the one or more user devices;

in response to detecting the noncompliance event, providing, by the computing system using the at least one API, a pop-up on a graphical user interface (GUI) of a client application, wherein the pop-up comprises at least one selectable points structured to receive at least one input of the one or more user devices responsive to at least one option associated with the detected noncompliance event;

receiving, by the computing system responsive to the at least one option using the at least one API, a remediation selection; and

remediating, by the computing system and via the security tool using the at least one API, the detected noncompliance event according to the remediation selection based on executing an API call with the experience provider.

2. The method of claim 1 , wherein the security tool is packaged with the client application, and wherein monitoring comprises determining categorical information of source code of the experience provider based on analyzing the source code in a sandboxed environment of a platform provider.

3. The method of claim 1 , wherein the security tool is provided to the one or more user devices as a download prompt, the download prompt configured to download a standalone application or a web browser extension, and wherein the at least one data sharing preference of the one or more user devices comprises rules regarding how user data is utilized or shared by the experience provider.

4. The method of claim 1 , wherein the security tool includes a virtual private network (VPN) application, the VPN application configured to route network communications of the one or more user devices to a platform provider.

5. The method of claim 4 , wherein the security tool executes scripts and source code contained in the routed network communications of the one or more user devices in a sandbox environment of the platform provider.

6. The method of claim 1 , wherein the at least one data sharing preference of the one or more user devices comprises a willingness to view advertisements from designated advertising categories, and wherein the noncompliance event comprises an advertisement served by the experience provider that does not comport with the designated advertising categories that the one or more user devices is willing to view.

7. The method of claim 1 , the method comprising:

generating, by the computing system, an alert for the one or more user devices, the alert structured to provide at least one remediation protocol suggestion;

transmitting, by the computing system, the alert to the one or more user devices; and

receiving, by the computing system, a selection from the one or more user devices, the selection designating a remediation protocol from the at least one remediation protocol suggestion.

8. The method of claim 1 , wherein the at least one option comprises a first option to warn the experience provider via the API call of the computing system and a second option to disconnect from a different computing system that is serving the content associated with the noncompliance event and that is associated with the experience provider.

9. The method of claim 1 , wherein remediating the noncompliance event comprises a punitive measure levied against the experience provider by a platform provider.

10. The method of claim 9 , wherein the punitive measure comprises at least one of a financial penalty, a service-access penalty, and a regulatory penalty.

11. A system, the system comprising:

a processing circuit having at least one processor coupled to at least one memory storing instructions that, when executed by the at least one processor, cause the processing circuit to:

enable a security tool;

monitor, via the security tool using at least one API, a website of an experience provider accessed by one or more user devices;

detect, via the security tool, a noncompliance event based on content accessed by the one or more user devices and served by the experience provider that is noncompliant with at least one data sharing preference of the one or more user devices;

in response to detecting the noncompliance event, provide, using the at least one API, a pop-up on a graphical user interface (GUI) of a client application, wherein the pop-up comprises at least one selectable points structured to receive at least one input of the one or more user devices responsive to at least one option associated with the detected noncompliance event;

receive, responsive to the at least one option using the at least one API, a remediation selection; and

remediate, via the security tool using the at least one API, the detected noncompliance event according to the remediation selection based on executing an API call with the experience provider.

12. The system of claim 11 , wherein the security tool is packaged with the client application, and wherein monitoring comprises determining categorical information of source code of the experience provider based on analyzing the source code in a sandboxed environment of a platform provider.

13. The system of claim 11 , wherein the security tool is provided to the one or more user devices as a download prompt, the download prompt configured to download a standalone application or a web browser extension, and wherein the at least one data sharing preference of the one or more user devices comprises rules regarding how user data is utilized or shared by the experience provider.

14. The system of claim 11 , wherein the security tool includes a virtual private network (VPN) application, the VPN application configured to route network communications of the one or more user devices to a platform provider.

15. The system of claim 14 , wherein the security tool executes scripts and source code contained in the routed network communications of the one or more user devices in a sandbox environment of the platform provider.

16. The system of claim 11 , wherein the at least one data sharing preference of the one or more user devices comprises a willingness to view advertisements from designated advertising categories, and wherein the noncompliance event comprises an advertisement served by the experience provider that does not comport with the designated advertising categories that the one or more user devices is willing to view.

17. The system of claim 11 , the instructions that, when executed by the at least one processor, cause the processing circuit to:

generate an alert for the one or more user devices, the alert structured to provide at least one remediation protocol suggestion;

transmit the alert to the one or more user devices; and

receive a selection from the one or more user devices, the selection designating a remediation protocol from the at least one remediation protocol suggestion.

18. The system of claim 11 , wherein the at least one option comprises a first option to warn the experience provider via the API call of the system and a second option to disconnect from a computing system that is serving the content associated with the noncompliance event and that is associated with the experience provider.

19. The system of claim 11 , wherein remediating the noncompliance event comprises a punitive measure levied against the experience provider by a platform provider, and wherein the punitive measure comprises at least one of a financial penalty, a service-access penalty, and a regulatory penalty.

20. A non-transitory computer-readable medium having computer-executable instructions embodied therein that, when executed by a server system, causes the server system to perform operations comprising:

enable a security tool;

monitor, via the security tool using at least one API, a website of an experience provider accessed by one or more user devices;

detect, via the security tool, a noncompliance event based on content accessed by the one or more user devices and served by the experience provider that is noncompliant with at least one data sharing preference of the one or more user devices;

in response to detecting the noncompliance event, provide, using the at least one API, a pop-up on a graphical user interface (GUI) of a client application, wherein the pop-up comprises at least one selectable points structured to receive at least one input of the one or more user devices responsive to at least one option associated with the detected noncompliance event;

receive, responsive to the at least one option using the at least one API, a remediation selection; and

remediate, via the security tool using the at least one API, the detected noncompliance event according to the remediation selection based on executing an API call with the experience provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2025
From: MEHTA, CHINTAN; STRLE, JASON
To: WELLS FARGO BANK, N.A.
Reel/Frame 070885/0882 →
Continuity (2)
Continuation 17316524 · May 10, 2021
Related Publication 20230393928A1 · Dec 7, 2023
References Cited (65)
US 8370952B1 · Wieder · 2013 [cited by applicant]
US 8656043B1 · Wieder · 2014 [cited by applicant]
US 9053299B2 · Wieder · 2015 [cited by applicant]
US 9356918B2 · Tsui et al. · 2016 [cited by applicant]
US 9405930B2 · Vestevich · 2016 [cited by applicant]
US 9712542B1 · Brandwine · 2017 [cited by applicant]
US 10402549B1 · Newstadt et al. · 2019 [cited by applicant]
US 11063952B2 · Boland · 2021 [cited by applicant]
US 11140240B1 · Brown et al. · 2021 [cited by applicant]
US 11232187B2 · Bruno et al. · 2022 [cited by applicant]
US 11386223B1 · Fakhraie et al. · 2022 [cited by applicant]
US 11457079B1 · Mehta et al. · 2022 [cited by applicant]
US 11625758B1 · Mehta et al. · 2023 [cited by applicant]
US 11657180B1 · Mehta et al. · 2023 [cited by applicant]
US 11748189B1 · Mehta et al. · 2023 [cited by applicant]
US 11973870B1 · Mehta et al. · 2024 [cited by applicant]
US 20040260948A1 · Miyata et al. · 2004 [cited by applicant]
US 20070198870A1 · Cheng et al. · 2007 [cited by applicant]
US 20080040249A1 · Re et al. · 2008 [cited by applicant]
US 20090265733A1 · McKelvey · 2009 [cited by applicant]
US 20110022681A1 · Simeonov · 2011 [cited by applicant]
US 20110137946A1 · Siress et al. · 2011 [cited by applicant]
US 20130211925A1 · Holland · 2013 [cited by applicant]
US 20130268357A1 · Heath · 2013 [cited by applicant]
US 20130290110A1 · Luvogt et al. · 2013 [cited by applicant]
US 20130297422A1 · Hunter et al. · 2013 [cited by applicant]
US 20150348024A1 · Asokan et al. · 2015 [cited by applicant]
US 20160012465A1 · Sharp · 2016 [cited by applicant]
US 20160034935A1 · Neb · 2016 [cited by applicant]
US 20160255139A1 · Rathod · 2016 [cited by applicant]
US 20160300231A1 · Shavell et al. · 2016 [cited by applicant]
US 20170034176A1 · Qi et al. · 2017 [cited by applicant]
US 20170048285A1 · Pearl et al. · 2017 [cited by applicant]
US 20170140174A1 · Lacey et al. · 2017 [cited by applicant]
US 20170344384A1 · Wadley et al. · 2017 [cited by applicant]
US 20170344745A1 · Wadley et al. · 2017 [cited by applicant]
US 20170346823A1 · Wadley et al. · 2017 [cited by applicant]
US 20180167373A1 · Anderson et al. · 2018 [cited by applicant]
US 20180248973A1 · Cook et al. · 2018 [cited by applicant]
US 20180350144A1 · Rathod · 2018 [cited by applicant]
US 20190222560A1 · Ford et al. · 2019 [cited by applicant]
US 20200145225A1 · Faye et al. · 2020 [cited by applicant]
US 20200184278A1 · Zadeh et al. · 2020 [cited by applicant]
US 20210192651A1 · Groth et al. · 2021 [cited by applicant]
US 20210266326A1 · Chen et al. · 2021 [cited by applicant]
US 20210350488A1 · Hossain · 2021 [cited by applicant]
US 20210352064A1 · Tsarfati et al. · 2021 [cited by applicant]
US 20210352088A1 · Adams et al. · 2021 [cited by applicant]
US 20210397987A1 · Dixit et al. · 2021 [cited by applicant]
US 20220019629A1 · Kavuri · 2022 [cited by applicant]
US 20220066796A1 · Koren et al. · 2022 [cited by applicant]
US 20220164470A1 · Obaidi · 2022 [cited by applicant]
US 20220173891A1 · Kim et al. · 2022 [cited by applicant]
US 20220191026A1 · Perpetua et al. · 2022 [cited by applicant]
CA 3126123A1 · 2020 [cited by applicant]
CN 112751821A · 2021 [cited by applicant]
KR 20100045633A · 2010 [cited by applicant]
WO WO2008112214A1 · 2008 [cited by applicant]
WO WO2013163333A2 · 2013 [cited by applicant]
WO WO2018187727A1 · 2018 [cited by applicant]
IP.com, article titled “Inefficiencies in Digital Advertising Markets” by Gordon et al. Feb. 18, 219, pp. 1-2. [cited by applicant]
Komanduri et al., Ad Choices? Compliance with Online Behavioral Advertising Notice and Choice Requirements, Oct. 7, 2011, https:// www.cylab.cmu.edu, 28 pages (Year: 2011). [cited by applicant]
SignNow, eSignature API: Developer Center, Guides and Support, Jan. 10, 2018, https://www.signnow.com, 8 pages (Year: 2018). [cited by applicant]
Suzic et al., “Rethinking Authorization Management of Web-AP Is”, Mar. 1, 2020, IEEE, 2020 IEEE International Conference on Pervasive Computing and Communications (PerCom) (pp. 1-10) (Year: 2020). [cited by applicant]
Tuecke et al., “Globus auth: A research identity and access management platform”, 2016, IEEE, 2016 IEEE 12th International Conference one-Science (e-Science), pp. 203-212 [cited by applicant]