A short, honest page. Customer-managed encryption keys, audit log on every action, multi-AZ AWS hosting, no model training on your data, full export and deletion on demand. We also tell you what we don't have today (SOC 2 in progress, no HIPAA BAA, no on-prem) so you can decide before you sign.
Every instance has its own AES-256-GCM master encryption key. The key is generated at provisioning, optionally passphrase-derived via Argon2id, and you can rotate it from the admin console. Revoking the key locks the data. We don't claim "we can't read it" — the running InventDB process must use the key to serve queries — we claim that every key access is audit-logged and that you control rotation. On the roadmap for Business plans: AWS KMS-backed customer-managed keys (CMEK) for centralised rotation, revocation, and key-access audit on AWS-native tooling. Today the key lives in your instance's config; KMS will move it to your AWS account.
Every change — from the AI Canvas, from MCP, from the REST API, from the SDKs — is recorded with the actor, timestamp, the prompt or payload that triggered it, and the records changed. Pull the log from inside the Canvas, or via the audit_log MCP tool for your SIEM.
The AI assistant inherits the logged-in user's exact permissions and cannot exceed them. Inference is Anthropic Claude Opus 4.7 with the no-training opt-out applied at the API level — your data never enters any model-training pipeline. For the production launch, inference will route through the InventDB AI Gateway to Anthropic Claude on AWS Bedrock; pre-launch it routes through the Gateway to the Anthropic API directly. Either path preserves the same no-training guarantee.
Daily automated snapshots, multi-AZ replication, 30-day retention. On cancellation: full export of records + attachments + saved templates within 7 days, complete deletion of instance and key 30 days after cancellation, with written confirmation.
Each Business Subscriber gets a dedicated InventDB Instance — a dedicated InventDB process running as an ECS task on managed AWS infrastructure, in your chosen region (US-East by default; EU-West and AP on request). Personal subscriptions share the underlying compute pool with strong per-user isolation. In both cases, the underlying EC2 hosts and storage volumes may be shared with other Subscribers; isolation is enforced at the application, encryption, and identity layers. Same model as AWS RDS, Snowflake, or Atlassian Cloud — logical isolation, shared physical hardware, cost-efficient buying power passed to you.
Personal subscriptions share an ECS task with other Personal users for cost efficiency. Each user's records and files are encrypted with their own key and stored under their own folder/prefix — cross-user access is impossible regardless of co-residence. Revoking your key locks your data even from us.
A short, technical answer for the IT lead, the auditor, and the procurement reviewer who are about to ask. We run shared physical infrastructure (the same way AWS RDS, Snowflake, Atlassian Cloud, and most modern SaaS does); isolation is enforced at four layers above it.
A short, complete list. We use AWS for hosting and Anthropic for AI inference; nothing else processes your data. We update this list when it changes — existing customers are notified by email at least 30 days before any new subprocessor is added.
| Subprocessor | Purpose | Region | Data accessed |
|---|---|---|---|
| Amazon Web Services Compute, storage, networking, monitoring (KMS planned) | Hosting your InventDB instance | US-East-1 (default); other regions on request | Encrypted records, encrypted files, encrypted backups |
| Anthropic Claude Opus 4.7 inference via the InventDB AI Gateway | AI Canvas + agent inference | Anthropic API today; AWS Bedrock (same region as your instance) at production launch | Your prompt + the rows the AI was asked to operate on (no training, no retention beyond the request) |
| Razorpay Payment processing · PCI-DSS Level 1, RBI-licensed | Subscription billing — cards from US, Europe / UK, India, and worldwide | India (with global card acquiring) | Billing email, card token, plan and invoice data — never any of your record content |
| Postmark / SES Transactional email | Sign-in links, invoices, scheduled report delivery | US | Email address, the report HTML you scheduled |
We're early. Here's what InventDB has now, what's in flight, and what's not on the roadmap. If a missing item is a blocker for your use case, tell us — we'll be straight about whether it's coming.
audit_log MCP tool)status.inventdb.comWe're a small team and we're honest about what that means. We don't have a 24×7 NOC, we don't have a paid on-call rotation, and we don't run a follow-the-sun support model. What we do have: AWS-native alerting on the basic infrastructure signals, a single committed response window, and a written post-mortem for every confirmed incident that touched customer data.
CloudWatch alarms on error rate, latency, and disk pressure page the team (KMS-access alerting joins the list once KMS integration ships). Customers can also email support@inventdb.com — treated the same as an alert.
Any customer-reported issue — critical or not — gets a human acknowledgement within 48 hours. That window is the same regardless of severity right now; we'd rather promise what we can keep than tier-segment a window we can't yet hold.
Any incident with potential customer-data impact: email to your designated contact within 72 hours of confirmation, with what we know, what we're doing, and what you should do. This window is set by what the law expects (GDPR Article 33) and we hold ourselves to it.
A written post-mortem follows for every confirmed customer-data incident: timeline, root cause, blast radius, remediation, and the change we're making so it doesn't happen again. Customers get this in writing.
Coming as we grow the team: 24×7 on-call rotation, tier-segmented response windows (15 min for sev-1), and a public status page at status.inventdb.com. We'll publish a date when we can hold it, not before.
Coming as we grow the team: a formal uptime SLA with service credits, tier-segmented response windows (1 hour for sev-1 production incidents on Business plans), and a published RPO / RTO. The infrastructure is built to support it (Multi-AZ on AWS, daily cross-region snapshots) — we just won't commit on paper to numbers we can't yet defend 24×7. As the team grows, this section will get more specific.
Security contact: security@inventdb.com — acknowledged within 48 hours.
Vulnerability disclosure: We accept reports via email. Please include reproduction steps. We acknowledge within 48 hours, fix on a severity-driven timeline, and credit you in the release notes if you'd like.
Pen-test & assessment requests: Customers on Business plans can request our latest internal pen-test summary under NDA. Email security@inventdb.com.
Data-deletion request: Email privacy@inventdb.com from the registered owner email. Acknowledged within 48 hours; deletion completed within 30 days (the legal window).