Your most sensitive
documents,
protected accordingly.
Inverba is built for law firms, insurance companies, and medical institutions - industries where document confidentiality is not optional. Every layer of our infrastructure is designed around that responsibility.
Five principles, uncompromised.
Every architectural decision at Inverba is measured against five guiding principles. Each principle is enforced by specific controls, audited continuously.
Encryption everywhere
Documents are encrypted from the moment they leave your network until they return as answers. Keys are managed in AWS KMS hardware security modules, never in application memory.
- AES-256-GCM for data at rest
- TLS 1.2+ enforced on all connections
- A dedicated KMS key per client, with automatic annual rotation
Least-privilege access
Every user, role, and service in Inverba operates with the minimum permissions required. Tenant isolation is enforced at the database level with row-level security, not just in application code.
- Role-based access control (RBAC)
- Multi-factor authentication (TOTP) supported
- Database-enforced tenant isolation (PostgreSQL row-level security)
Auditable by design
Every query, every document access, every administrative action is logged and tamper-evident. Logs are exportable for compliance reviews and court submissions.
- Append-only, time-stamped audit logs
- Retained for the term of your contract
- Exportable on request (CSV / JSON)
Data residency & sovereignty
Your data stays where it should: AWS eu-central-1 (Frankfurt), inside the EU. Enterprise clients can run the entire stack in their own AWS account. Sub-processors are limited and disclosed.
- EU data residency - AWS Frankfurt (eu-central-1)
- Storage, database, and AI inference all in-region
- Dedicated AWS account option for enterprise clients
Your data is not training data
We do not train models on customer documents. Ever. Your queries, your documents, and the answers Inverba produces are yours alone - used only to serve your queries and stored according to your retention policy.
- Contractually guaranteed - written into every DPA
- Customer documents and queries are not used to improve models
- Right to erasure honored within 30 days
How a query actually flows.
Every query passes through five distinct security boundaries. At no point does a document leave your selected region, and at no point is sensitive content shipped to a third-party model provider in plain text.
Two ways to run Inverba.
The more sensitive your documents, the more isolated the deployment. Choose the option that matches your data classification and regulatory posture.
Multi-tenant cloud
Shared infrastructure in AWS eu-central-1 (Frankfurt). Tenant data isolated with database row-level security, a dedicated KMS encryption key, and dedicated document storage and vector index per client.
Dedicated AWS account
For enterprise clients: the entire stack deployed via Terraform into an AWS account dedicated to you - your infrastructure, your keys, your logs. Account-level isolation, not just a permission flag.
What isolated per client
actually means.
Hover or tap any layer to see how it is separated between clients.
No client shares an encryption key, a document bucket, a vector index, or database rows with any other client. Pick a layer above to see the details.
From ingestion to erasure.
Every document passes through a deterministic lifecycle. You control retention, residency, and erasure at each stage.
Encrypted upload
Documents are uploaded securely from the browser over TLS, straight into your tenant's encrypted bucket.
Parsing & OCR
Text extracted, chunked, and prepared for embedding - all within your data region.
Vector storage
Embeddings stored encrypted at rest. Original documents remain in your tenant's dedicated bucket.
Retrieval & response
Authenticated queries surface relevant chunks; cited responses delivered back over TLS.
Retention & erasure
Retention follows your policy; erasure requests are honoured within 30 days, GDPR-compliant.
Frameworks we operate under.
Inverba meets the security and privacy standards required by regulated industries across Southeast Europe. Documentation available under NDA.
GDPR (EU 2016/679)
Data residency & isolation
Encryption & key management
Industry-specific
Our sub-processors, disclosed.
We keep our supply chain short and disclose every third-party that touches your data. You are notified 30 days before any change.
| Sub-processor | Purpose | Data type | Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage & database (S3, RDS, KMS, Lambda) | Encrypted documents, metadata, audit logs | EU (Frankfurt) |
| AWS Bedrock | AI model inference (private VPC endpoint) | Query + retrieved passages · not used for training | EU (Frankfurt) |
| AWS Cognito | Authentication & user management | Account e-mail, credentials (hashed) | EU (Frankfurt) |
| AWS SES | Transactional e-mail delivery | Recipient e-mail addresses | EU |
| AWS CloudFront + WAF | Content delivery & DDoS protection | Network metadata only | Global edge · EU origin |
When something goes wrong,
you'll know fast.
Automated monitoring watches the platform around the clock. Every incident follows a documented playbook with clear timelines and direct customer communication.
Built on managed
AWS resilience.
Everything your
procurement team
needs to ask.
One signed NDA gets you our full security pack - architecture and data-flow diagrams, our DPA template, and GDPR documentation. We answer your security questionnaires within five business days.