inventMAP
Security as an architectural principle

Built for confidential engineering data

inventMAP processes your most valuable knowledge — inventions, before they are protected. That is why security is built in from the start. Here we explain in plain language what that means for you, no IT background required.

Encryption – in transit & at restEU-sovereign – no US hyperscalerTwo-factor sign-in (mandatory)Tenant separation down to the databaseReviewed against OWASP Top 10 – web, API & AIRestore-tested backupsContinuous automated security scanningRegular external penetration testsGDPR-compliant · DPA available
The core: data sovereignty

Your data stays European — genuinely European

Many providers advertise “hosting in the EU”. The catch: it often runs in the data centre of a US corporation (Amazon, Microsoft, Google). Such providers are subject to US law — US authorities could in theory demand access, even to data stored in Europe.

With inventMAP the entire chain is European: application, database and storage (Scaleway, France), sign-in (Cloud IAM, France), AI optionally fully European (Mistral, France) and an internet search we operate ourselves. No US hyperscaler.

Sovereignty means: the provider itself is European —
not merely a data centre in an “EU region”.
How your data is protected

Several layers — each with a clear purpose

Strict tenant separation — down to the data row

What this means for you: The separation of your data from that of other customers sits in the database itself, not just in the interface. Even in the event of a software error, access by others remains technically impossible.

Trade-secret projects — sealed to those in the circle

What this means for you: Particularly sensitive topics can be locked to a small circle of confidants. Even other employees of your own company cannot see them — the separation reaches into the database.

Encryption — in transit and at rest

What this means for you: Your data is encrypted in transit (as in online banking) and at rest. Intercepted or stolen data is unreadable without the key.

Mandatory two-factor sign-in

What this means for you: A stolen password alone is not enough — your device is also required (authenticator app or passkey). This prevents account takeovers.

Protected against the typical attacks

An answer for every known threat

The most common attack routes against web applications — and how inventMAP defends against them:

Intercepted data transfer (man-in-the-middle)
End-to-end encryption (HTTPS) — nobody can read along the way.
Database attacks (SQL injection)
All database queries are technically built so that injected commands have no effect.
Account takeover with stolen credentials
Mandatory two-factor sign-in — the password alone is not enough.
Automated password guessing (brute force)
After several failed attempts the account is temporarily locked — mass guessing runs into a wall.
Unauthorised access to the database
Every request runs under a verified identity; the database is reachable only for our application and defined addresses.
Manipulating the AI with hidden instructions (prompt injection)
Uploaded documents and web content are presented to the AI as data material only — instructions hidden inside remain without effect.
Malicious file uploads
Uploaded files are checked for type and size and delivered as downloads — they cannot execute malicious code in the browser.
Abuse of costly AI functions at someone else's expense
Every AI call is tied to your account, metered and safeguarded — nobody can trigger unlimited analyses on another party's bill.
Your content and the AI

AI analysis without giving your data away

You choose the AI provider per account — fully EU-sovereign (open models on European infrastructure, or Mistral) or Claude for maximum analytical depth. Your content is processed exclusively for your analysis and is never used to train AI models or passed on. Internet research runs through our own search on EU infrastructure — nothing is passed to commercial search services.

Because AI brings risks of its own, we review specifically against the recognised catalogue for AI applications (OWASP Top 10 for LLM): instructions hidden in content remain without effect, AI responses are never executed as program code unchecked, and AI usage is capped and traceable per account.

Speech & dictation (in preparation)

Dictation and read-back stay in-house

Voice control for inventMAP is in preparation — and its design is settled: when you dictate something or have an answer read back to you, your voice will not leave our own European infrastructure. Speech recognition (listening) and speech output (reading back) run on our own server — not at Google, Amazon, OpenAI or any other speech service. The recording is transcribed and discarded immediately, never stored. That way even the spoken word stays confidential.

Reliable operation

So your data is still there tomorrow

Restore-tested backups

What this means for you: Daily backups — and we check regularly that a restore genuinely works from them. A backup that has never been tested is only a hope.

Traceable administration

What this means for you: Security-relevant administrative actions (for example releases or permission changes) are logged.

Checked continuously, not once

Continuous security testing

Security is a process, not a state. Our code and our building blocks are continuously and automatically checked for vulnerabilities — not just on a single reference date.

Automated code analysis on every change

Every code change is examined for typical vulnerabilities with an established security tool (GitHub CodeQL) before it goes live.

Regular penetration tests by external specialists

Beyond our own review, we have the application continuously attacked by an independent security firm — at short intervals and additionally after every major rebuild, following recognised standards (including OWASP, NIST, BSI). Any findings are addressed promptly. An outside view finds what your own overlooks.

Structured reviews against recognised standards

In addition to the automation, we review regularly against the established security catalogues — OWASP Top 10 (web), OWASP API Security Top 10 and OWASP Top 10 for AI applications — using a maintained checklist. That way nothing slips through when new functions are added either.

Monitored software components

All components in use are continuously checked against known vulnerability databases and updated promptly. We also prevent credentials from accidentally ending up in the code.

Protected sign-in area

The login is secured against automated password guessing: after several failed attempts the account is temporarily locked. Signed-in sessions are time-limited.

Openly stated

What comes next

We build transparently. Some things are already available on request, others are what we build next — we state both openly instead of hiding them. That openness is part of our security promise:

Corporate sign-in (single sign-on / SAML)
Sign-in through your corporate login, for example Microsoft Entra. Our identity service (Keycloak) already supports it — we set it up per customer.
on request
High availability (failover cluster)
A second database node takes over automatically in the event of a failure — for high availability.
available at short notice
External security assessment (penetration test)
A specialised team is paid to try to break in and reports the weaknesses we then close.
in preparation
Certification (ISO 27001 / TISAX)
An independently audited information security management system — for automotive customers in the form of TISAX.
planned

Documents for your IT & procurement

For pilots and procurement we provide the formal summary of data processing as well as a data processing agreement (DPA) including technical and organisational measures. We are happy to hold a technical security call with your IT department.

Compliance overviewRequest DPA / security call

Questions about security? gregor@inventissimo.de