How best to obtain IP Protection in a post SaaS-as-you know-it world.
“SaaS is dead” an investor friend said to me the other day, after I mentioned I was ‘a bit bored’ of receiving a recent raft of new enquiries from ‘inventors’ who appeared to have quickly developed a new SaaS platform and/or a mobile app and were looking to protect their valuable IP.
The statement resonated with me, as shall be explained, as I have been increasingly noticing that new AI tools and vibing coding applications are allowing people to rapidly spin up a seemingly endless array of tailored and bespoke innovations to meet more and more niche applications.
Then, the second they reach out to understand what ‘comes next’, quite rightly (as we’ve done a good job of educating people), they are advised to “protect the IP” or “define and build a defensive moat”.
Hence the enquiries.
To be honest, I wasn’t bored of them at all, I was just feeling like I could be doing more to help and so was struggling, frustrated even, with my own lack of ability to put my finger on the “what comes next” part.
First, we need to see if my assumption even tests – is SaaS dead? Well, I guess with anything it depends on how you define the term. If one means an application delivered to an end user device and which takes data, passes it over a telecommunications network, analyses that data either locally (or not) and then delivers some value back to the user, then no, SaaS is not dead. In fact, it’s very much alive and kicking and will probably be as long as we have the Internet (IMHO). Indeed, so said Microsoft CEO Satya Nadella even as far back as December 2024 in a podcast.
If one means that the value of such applications still lies in the application itself – as one could argue it did when such applications took immense engineering skill and development cycles to produce – then yes, SaaS (as we know it) is dead. As that value has now been diminished (one may argue wholly gutted) due to the skill of AI generation and automation tools.
Fear not, however, the value of the IP has itself also shifted as have the skills required to make this type of product successful have also shifted. (indeed, one could also argue that the landscape has now been democratised such that anyone can develop an application, with the future being, via the use of Agentic AI, we will all be given the tools to link together features and functions and thus develop any interface for any data we care to manage in any way we want). Thus, the old techniques of protecting such innovations via patents, copyright and in some cases, designs, are now replaced by new ones, including brand, market analysis, rapid product development in line with customer requirements, and of course the new oil, data.
It should also be said that there is and will be an inordinate amount of IP not only in the tools used to quickly develop such applications but also in the telecom systems, cloud services, cybersecurity infrastructure, and back-end developments that will allow such quickly developed AI-wrapper solutions to provide long term value to an end customer, or customers. What WordPress did for ‘easy’ website developments, new vendors will emerge that will allow the same to be done for end user applications.
The focus of this paper, however, is to provide some practical information, tips and recommendations as to how best protect the IP and build your defensive moat, should you be emerging as one of those service providers. It is not to be taken as full legal advice, as every situation is different and as the reader will come to understand, the devil is definitely in the detail.
Business ideas and market concepts
First off, I need to tackle a common misnomer: IP rights cannot usually be used to stop others from pursuing the same commercial idea or addressing the same customer need. Uber, for example, could not stop other taxi or private-hire businesses offering a taxi booking app simply by being early to market[1].
The protectable value is more likely to sit in the specific service and delivery technology, confidential implementation details, data (there’s that word again), user experience, brand (have written this one in bold), customer relationships and operational know-how supporting the service.
Moreover, there’s IP that has been created by Uber and is now locked into how they stratify services, lock in partners such as Deliveroo, have added new features and functions such as “I’m in a hurry so find me a car now and I’ll pay more”, none of which was in the original, simpler, “book me a taxi” app launched on day one.
Therefore, most of the time, you cannot protect the basic concept of “an app that does x, y and z”.
IP rights do not provide a shortcut to putting in the hard work, having good product market fit, solid enterprise-ready code and app development, finding lead customers, marketing, managing support services and ultimately, generating revenue.
Indeed, according to my very brief research on the topic, a minimum viable product (MVP) typically only accounts for 10% to 20% of a SaaS application’s total enterprise value. The remaining 80% to 90% of the value is built later through enterprise-grade architecture, integrations, security compliance, advanced automation, and scalability[2].
Using the Uber example again, a significant proportion of their tech stack is in the ‘boring stuff’ such as the underlying tech and tech enabled operations, identity management, maps, payments, fraud detection, ordering, dispatching, pricing and more[3].
However, there are IP tools you can use to create and maintain that defensive moat, and IP tools that will just sink your money, the difference between which I will now aim to describe.
Let’s start with the basics first.
Patent protection: key features
A granted patent can prevent others from carrying out the claimed invention in the relevant territory. Protection can last up to 20 years from the filing date, subject to renewal fees. The trade-off is disclosure: the application is normally published in full around 18 months from first filing, at which point the technical disclosure becomes publicly available.
The specification must also describe the invention clearly and completely enough for a skilled person to put it into effect, which means disclosing the enabling technical details, not just the commercial idea or desired outcome.
Patent examination (the period from filing to grant) can also be slow. Depending on the jurisdiction, complexity and objections raised, grant can take several years and, in some cases, around five to six years, or more.
These duration points are important. Not only are patents useless if required to protect features that will come and go in less than 5 or 6 years, but patents offer a time-limited monopoly of up to 20 years.
Wherein, other IP rights such as Trade marks, Trade secrets and confidential know-how can last indefinitely, but only while the information remains secret, reasonable steps are taken to preserve confidentiality and in case of trade marks, while renewal fees are paid and the mark is used correctly.
Software patentability
Because the products and services we are talking about in this paper are software-based, software patentability is also a key issue. In the UK, a computer program “as such” is excluded from patentability. A patent application directed merely to the code itself is therefore unlikely to proceed.
However, software-implemented inventions may be patentable where they make a technical contribution. Relevant examples include software that:
- solves a technical problem or provides a technical solution; a good example here is most software either embedded onto a semiconductor chip or in a telecommunications network is patentable.
- controls a physical process or machine; such as software used in manufacturing control systems, or
- produces a new technical effect or technical advantage over existing solutions, a good example here is software that make the computer itself work better (think more efficient, higher power, quicker etc etc).
Patent protection should not be completely ruled out for SAAS implementations, but a broad filing strategy is unlikely to be the best ‘first step’. However, patents are most useful where there is a clearly defined technical invention that is new, inventive, commercially valuable and detectable in a competitor’s implementation.
If the value lies mainly in internal configuration choices, architecture, workflows, data-handling logic or implementation techniques that are not visible externally, infringement may be difficult to detect and prove, even with a granted patent.
They are also expensive, and patents need to be obtained in every jurisdiction the product can be accessed in, so for a global app, the costs will mount up quickly.
This does not mean patents should be ruled out, as I’ve said. If there is a discrete technical innovation within the platform, such as a new technical method for processing data or improving system performance, security, scalability or interoperability, then it should be assessed for patentability before any public disclosure.
In the UK, the Patent Box regime may also affect the commercial analysis. Where a qualifying patent protects profit-generating features of the platform, relevant patent-derived profits may be taxed at an effective 10% corporation tax rate. That possible tax advantage may support a focused filing – even where a broad patent strategy is not appropriate.
Trade secrets and know-how
Trade secret and know-how protection may be more commercially effective however, provided the relevant information is kept confidential and reasonable steps are taken to protect it. This may include restricting access to source code, architecture documents, deployment processes, algorithms, configuration logic, customer-specific workflows, pricing models, product roadmaps and operational know-how. Unlike a published patent, this approach prevents competitors from learning how you do what you do.
In practical terms, this means treating know-how as an asset that needs to be identified, recorded and managed, rather than simply left in the heads of founders, developers or product teams. A defensible trade secret strategy should therefore include clear internal ownership of key confidential information, controlled access on a need-to-know basis, sensible labelling and storage practices, employee and contractor confidentiality obligations, and a process for deciding what should be kept secret rather than disclosed in a patent filing or marketing material.
Contractual controls
Contracts are also central tenet to an IP strategy in a SaaS world. Solid protections can be built into customer terms, SaaS subscription agreements, NDAs, employee and contractor agreements, development agreements, end user licence terms (EULAs) and supplier arrangements.
It is common to add terms that prevent customers and end users from activities such as:
-reverse engineering the code
-using your code to build a competing solution
-taking screenshots of your GUIs
-using underlying data
-keeping your features and functions confidential.
The key point is that these contractual protections should not be treated as boilerplate or left until the final stages of a deal. They need to map onto the actual IP assets and commercial risks in the business: who owns newly developed functionality, what data can be used for training or analytics, what confidentiality obligations survive termination, whether customers can benchmark or publicise the service, and how quickly access must be switched off if there is misuse. In that sense, contracts become part of the moat itself, translating the IP strategy into enforceable day-to-day controls.
Brand, trade marks and market position
A solid trade mark strategy is also important. This should include clearance of key brand names, logos and product names, a filing plan for the principal territories, and monitoring and enforcement to preserve the distinctiveness and value of the brand assets, but first, some basics.
A registered trade mark is infringed if the same or similar goods or services are offered under a trade mark comprising a sign that is the same or confusingly similar to that which is registered.
Registration is granted for marks which are distinctive and not descriptive of specific goods and services for which registration is sought. Various different types of “signs” can be registered as trade marks. A word mark generally provides the broadest scope of protection, as it covers the use of that word in different formats. Logos can also be registered and should be protected if they form an important or distinctive part of your brand.
Trade mark registration is geographical in nature, and registration can be obtained for the United Kingdom by filing an application at the UK Intellectual Property Office (UKIPO).
If trade marks are renewed and used correctly, then they can last indefinitely. The world’s oldest trade mark is “BASS” for beer (alcohological beverages) and this year it is at least[4] 150 years old.
Bang for buck, it’s my view that trade marks are the first place to assign any external budget for protecting your IP. As we’ll see later, there are other areas I’d advise investment is made in also.
Data, data, data
Data is not, strictly speaking, a form of intellectual property in the same way as a patent, trade mark, design or copyright work. However, it is so closely related to the value of many software and AI-enabled businesses, it should be treated with similar discipline.
The “new oil” analogy is overused, but still useful: raw data may be messy, unrefined and difficult to exploit, but when it is [lawfully] collected, cleaned, structured, labelled, enriched and combined with domain know-how, it can become an extremely valuable business asset.
Again, the Uber case study[5] is a good case in point.
For that reason, data should be identified, protected and managed as part of an overarching IP strategy, including by controlling access, documenting provenance and usage rights, maintaining confidentiality where appropriate, complying with data protection obligations, and making it clear in contracts who can use the data, for what purpose, including after termination.
Hence why I said upfront that the devil will be in the detail.
Recommendations
Having said all of the above, what I am not saying (for the avoidance of all doubt) that there is no IP in a SaaS platform, far from it – there can be a significant amount of high value IP. What I am saying is where it is can change over the lifecycle of a product and how a product architecture changes and it can be very distributed.
It can also be not easy to find and so my main recommendation if you are thinking over moving into this space (or have just made the move), is that good investment into understanding, highlighting and managing your IP can reap vast rewards. Obtain protection where it fits but do all you can to avoid IP leaks also.
When I do speak to clients, I always recommend a focused IP review to:
- identify and record your key IP assets;
- put the right documentation and control points in place;
- review relevant processes regarding legals, compliance, data, product launches, marketing etc etc;
- review your key contracts; and
- create an IP risk register to manage the main risks.
If you are interested in any of the above or wish to engage our services to help you protect your business value, then do reach out. I promise I won’t be, and will never be, bored of the topic!
[1] Hence now we have good competition in the market with the likes of Bolt and Lyft.
[2] https://www.aprio.com/insights-events/how-saas-companies-can-increase-gross-margins-or-valuations-ins-article-tech/
[3] https://www.constellationr.com/insights/news/how-ubers-tech-stack-datasets-drive-ai-experience-growth
[4] It was registered as the TM registry came into effect in 1876 but is likely to have been around before that date. Ref : https://ipo.blog.gov.uk/2025/06/26/putting-the-ip-in-ipa/
[5] https://www.constellationr.com/insights/news/how-ubers-tech-stack-datasets-drive-ai-experience-growth
