Inverba for Enterprise — compliance, procurement, audit
JavaScript is off, so the interactive parts of this page (the in-browser verify demo, copy buttons) won't run. Everything that matters is still readable below — and the same applies to Inverba itself: verification is plain SHA-256 and Ed25519, checkable with about thirty lines in any language.
Compliance · procurement · audit

When the regulator asks where your data came from, "our scraper" is not an answer.

Inverba turns web-sourced data into evidence: every fetch cryptographically signed, every record independently verifiable — offline, by anyone. A tamper-evident transparency log for anchoring records is designed and coming. Built for teams whose data pipeline is subject to audit.

audit trail · dataset web-corpus-2026q2 · illustrative
Apr 03 09:1214,208 records signed · key inv_k1_7f3a
Apr 03 10:0014,208 / 14,208 records re-verified offline · 0 failures
Jun 18 15:41C2PA manifests exported · 14,208 / 14,208
Jul 12 08:00external auditor re-verified · 0 failures
verification performed by the auditor's own tooling — no Inverba access required
Compliance

Provenance in the formats your obligations name.

EU AI Act training-data documentation

General-purpose AI providers must document training-data provenance. Inverba records establish what content was collected, from where, when, and by which key — exportable as C2PA Content Credentials manifests your documentation can reference directly.

Dispute & takedown response

When a rightsholder or counterparty challenges what you collected, you respond with signed records anyone can independently verify, instead of log files and assurances. Evidence a third party can check is evidence that ends conversations early.

Regulatory & market monitoring

Monitoring competitor pricing, disclosures, or terms for compliance purposes requires proof of what was published, not a screenshot. Signed change records show what changed, when it changed, and that your copy is faithful.

Internal audit & data governance

Every dataset built on Inverba carries a verifiable chain from URL to signed record. Your governance team can re-verify any subset at any time, independently, with open tooling.

Security posture

Sovereign by architecture, not by policy.

The engine runs entirely inside your perimeter. Keys are generated and held on your infrastructure; content never has to leave it. There is no phone-home, no mandatory cloud dependency — the managed tier is a convenience, not a requirement.

Security & threat model — including what we don't claim →

Inverba is at v0.1.0. The core is public and auditable at github.com/Inverba-Systems/inverba; hosted services have not launched — status lists exactly what has shipped.

deployment

Runs entirely on your infrastructure — self-hosted, VPC, or air-gapped — because it has no cloud dependency to begin with. Signed releases with SBOM are planned.

key management

Local Ed25519 keys, generated and held by you; rotation with continuity of verification. HSM and KMS backends are planned.

accessplanned

SSO/SAML, SCIM provisioning, role-based access, and append-only operator audit logging belong to the hosted tier, which has not launched.

assurance

A published threat model and disclosure policy, plus an Apache-2.0 core open to your review today. Third-party penetration testing is planned before hosted services launch.

Procurement

What we can hand you today, and what we cannot.

01 Security questionnaire We answer CAIQ & SIG Lite on request. Pre-filled versions come with the hosted launch.
02 Data residency Content stays in your infrastructure — that is architectural, not policy. A DPA applies once there is hosted processing to cover.
03 Pen test summaryplanned No third-party test has been run at v0.1.0. Scheduled before hosted services launch; we will publish the summary then.
04 Support SLA Response-time commitments with a named escalation path, agreed per contract.

Talk to us about compliance.

A 30-minute call with an engineer — not a sales deck. Bring your audit requirements; we'll show you exactly what a Inverba evidence chain looks like for your use case, and tell you plainly if it isn't a fit.

enterprise@inverba.dev