Inverba turns web-sourced data into evidence: every fetch cryptographically signed, every record independently verifiable — offline, by anyone. A tamper-evident transparency log for anchoring records is designed and coming. Built for teams whose data pipeline is subject to audit.
General-purpose AI providers must document training-data provenance. Inverba records establish what content was collected, from where, when, and by which key — exportable as C2PA Content Credentials manifests your documentation can reference directly.
When a rightsholder or counterparty challenges what you collected, you respond with signed records anyone can independently verify, instead of log files and assurances. Evidence a third party can check is evidence that ends conversations early.
Monitoring competitor pricing, disclosures, or terms for compliance purposes requires proof of what was published, not a screenshot. Signed change records show what changed, when it changed, and that your copy is faithful.
Every dataset built on Inverba carries a verifiable chain from URL to signed record. Your governance team can re-verify any subset at any time, independently, with open tooling.
The engine runs entirely inside your perimeter. Keys are generated and held on your infrastructure; content never has to leave it. There is no phone-home, no mandatory cloud dependency — the managed tier is a convenience, not a requirement.
Security & threat model — including what we don't claim →Inverba is at v0.1.0. The core is public and auditable at github.com/Inverba-Systems/inverba; hosted services have not launched — status lists exactly what has shipped.
Runs entirely on your infrastructure — self-hosted, VPC, or air-gapped — because it has no cloud dependency to begin with. Signed releases with SBOM are planned.
Local Ed25519 keys, generated and held by you; rotation with continuity of verification. HSM and KMS backends are planned.
SSO/SAML, SCIM provisioning, role-based access, and append-only operator audit logging belong to the hosted tier, which has not launched.
A published threat model and disclosure policy, plus an Apache-2.0 core open to your review today. Third-party penetration testing is planned before hosted services launch.
A 30-minute call with an engineer — not a sales deck. Bring your audit requirements; we'll show you exactly what a Inverba evidence chain looks like for your use case, and tell you plainly if it isn't a fit.