Security & Trust

Your most sensitive
documents,
protected accordingly.

Inverba is built for law firms, insurance companies, and medical institutions - industries where document confidentiality is not optional. Every layer of our infrastructure is designed around that responsibility.

AES-256 encryption
At rest and in transit
Enforced
EU data residency
AWS Frankfurt · eu-central-1
Active
GDPR Compliant
EU data protection regulation
By design
Serbian Data Protection Law
Local regulatory compliance
By design

Five principles, uncompromised.

Every architectural decision at Inverba is measured against five guiding principles. Each principle is enforced by specific controls, audited continuously.

01

Encryption everywhere

Documents are encrypted from the moment they leave your network until they return as answers. Keys are managed in AWS KMS hardware security modules, never in application memory.

  • AES-256-GCM for data at rest
  • TLS 1.2+ enforced on all connections
  • A dedicated KMS key per client, with automatic annual rotation
02

Least-privilege access

Every user, role, and service in Inverba operates with the minimum permissions required. Tenant isolation is enforced at the database level with row-level security, not just in application code.

  • Role-based access control (RBAC)
  • Multi-factor authentication (TOTP) supported
  • Database-enforced tenant isolation (PostgreSQL row-level security)
03

Auditable by design

Every query, every document access, every administrative action is logged and tamper-evident. Logs are exportable for compliance reviews and court submissions.

  • Append-only, time-stamped audit logs
  • Retained for the term of your contract
  • Exportable on request (CSV / JSON)
04

Data residency & sovereignty

Your data stays where it should: AWS eu-central-1 (Frankfurt), inside the EU. Enterprise clients can run the entire stack in their own AWS account. Sub-processors are limited and disclosed.

  • EU data residency - AWS Frankfurt (eu-central-1)
  • Storage, database, and AI inference all in-region
  • Dedicated AWS account option for enterprise clients
05

Your data is not training data

We do not train models on customer documents. Ever. Your queries, your documents, and the answers Inverba produces are yours alone - used only to serve your queries and stored according to your retention policy.

  • Contractually guaranteed - written into every DPA
  • Customer documents and queries are not used to improve models
  • Right to erasure honored within 30 days

How a query actually flows.

Every query passes through five distinct security boundaries. At no point does a document leave your selected region, and at no point is sensitive content shipped to a third-party model provider in plain text.

Layer 1
Client request
Authenticated user, MFA verified, RBAC permissions checked at edge
TLS 1.3
Layer 2
API gateway & WAF
Rate limits, request signing, schema validation, prompt-injection filtering
DDoS · WAF · IP allow-list
Layer 3
Retrieval (RAG)
Encrypted vector search over your indexed documents in your region
In-region only
Layer 4
Inference
AWS Bedrock in eu-central-1, reached over a private VPC endpoint. Never used for model training.
No training · In-region
Layer 5
Audit & response
Every query, source, and response written to tamper-evident audit log
Immutable · Append-only

Two ways to run Inverba.

The more sensitive your documents, the more isolated the deployment. Choose the option that matches your data classification and regulatory posture.

Multi-tenant cloud

Shared infrastructure in AWS eu-central-1 (Frankfurt). Tenant data isolated with database row-level security, a dedicated KMS encryption key, and dedicated document storage and vector index per client.

SetupDays
RegionEU (Frankfurt)
IsolationPer-tenant keys + RLS

What isolated per client
actually means.

Hover or tap any layer to see how it is separated between clients.

AWS eu-central-1 · Frankfurt
Client A
Client B
Every layer, separated

No client shares an encryption key, a document bucket, a vector index, or database rows with any other client. Pick a layer above to see the details.

From ingestion to erasure.

Every document passes through a deterministic lifecycle. You control retention, residency, and erasure at each stage.

1
Ingest

Encrypted upload

Documents are uploaded securely from the browser over TLS, straight into your tenant's encrypted bucket.

2
Process

Parsing & OCR

Text extracted, chunked, and prepared for embedding - all within your data region.

3
Index

Vector storage

Embeddings stored encrypted at rest. Original documents remain in your tenant's dedicated bucket.

4
Query

Retrieval & response

Authenticated queries surface relevant chunks; cited responses delivered back over TLS.

5
Retain

Retention & erasure

Retention follows your policy; erasure requests are honoured within 30 days, GDPR-compliant.

Frameworks we operate under.

Inverba meets the security and privacy standards required by regulated industries across Southeast Europe. Documentation available under NDA.

GDPR (EU 2016/679)

EU General Data Protection Regulation
Compliant
Data Processing Agreement (DPA) signed with every customer
Right to access, rectify, erase honored within 30 days
Named privacy contact for all data-protection inquiries
Breach notification within 72 hours per Article 33

Data residency & isolation

Where your data lives
Active
AWS eu-central-1 (Frankfurt) - all data stays in the EU
Dedicated AWS account per enterprise client
Private VPC - no public network exposure
Your documents remain in your designated bucket

Encryption & key management

Keys you control
Enforced
AES-256-GCM for data at rest
TLS 1.2+ enforced on all connections
Per-client KMS keys in hardware security modules
Automatic annual key rotation managed by AWS KMS

Industry-specific

Sector regulations & local laws
In scope
Zakon o zaštiti podataka o ličnosti (RS) - Serbian DPA
Attorney-client confidentiality supported by design - access control + audit trail
Special-category data (e.g. medical) onboarded only after a joint DPIA

Our sub-processors, disclosed.

We keep our supply chain short and disclose every third-party that touches your data. You are notified 30 days before any change.

Sub-processor Purpose Data type Region
Amazon Web Services (AWS) Hosting, storage & database (S3, RDS, KMS, Lambda) Encrypted documents, metadata, audit logs EU (Frankfurt)
AWS Bedrock AI model inference (private VPC endpoint) Query + retrieved passages · not used for training EU (Frankfurt)
AWS Cognito Authentication & user management Account e-mail, credentials (hashed) EU (Frankfurt)
AWS SES Transactional e-mail delivery Recipient e-mail addresses EU
AWS CloudFront + WAF Content delivery & DDoS protection Network metadata only Global edge · EU origin

When something goes wrong,
you'll know fast.

Automated monitoring watches the platform around the clock. Every incident follows a documented playbook with clear timelines and direct customer communication.

T+0
Detection
CloudWatch alarms or an external report page the on-call engineer immediately.
T+15min
Triage & containment
Severity assessed. If customer data is at risk, containment begins immediately.
T+1h
Customer notification (Sev 1)
Affected customers notified directly by e-mail and their dedicated contact channel.
T+72h
GDPR breach notification
If a personal-data breach is confirmed, supervisory authorities notified per Article 33.
T+7d
Post-mortem published
Detailed report shared with affected customers, including remediation steps and timelines.
Service levels

Built on managed
AWS resilience.

Uptime target 99.5% monthly
Database recovery Point-in-time (RDS)
Backups Continuous + daily snapshots
Backup retention 7 days
Monitoring & alarms 24 / 7 automated
Breach notification ≤ 72 h (Art. 33)
Trust Pack

Everything your
procurement team
needs to ask.

One signed NDA gets you our full security pack - architecture and data-flow diagrams, our DPA template, and GDPR documentation. We answer your security questionnaires within five business days.

GDPR compliance overview
Encryption & key-management overview
Network & data flow diagrams
Master DPA template
Security questionnaire support
inverba-trust-pack.zip
Last updated · May 2026
gdpr-compliance-overview.pdf 410 KB
dpa-template.pdf 320 KB
architecture-diagrams.pdf 3.4 MB
data-flow-overview.pdf 312 KB