IT Sovereignty & Security

Confidential engineering knowledgeshould remain under your control.

inventMAP holds more than documents. It contains problems, ideas, patents, decisions, technology strategies and future development directions.

That is why security is not an add-on. It is a prerequisite for use in R&D.

  • EU operation
  • Strict tenant separation
  • Two-factor authentication
  • No AI training on your data

Why security counts differently here

The more valuable the context,the more sensitive the knowledge.

A single document usually reveals only a fragment.

Exactly this context is what makes inventMAP valuable – and exactly why it must be protected.

A technical network, by contrast, can make visible:

  • which problems a product has
  • which solutions have already been tried
  • which patents are relevant
  • which ideas were rejected
  • which technologies are being watched
  • which strategic directions are being prepared

It is not only the files that are confidential.The connections between them are too.

Four anchors of trust

  1. 01

    Operated in the EU

    inventMAP is operated in the EU: application, database and file storage at Scaleway in France, sign-in through a hosted Keycloak at Cloud-IAM in France. The technical operating environment stays within a European legal and data-protection context. For AI analyses each account chooses between fully European processing and – only by explicit choice – Claude by Anthropic in the USA; in that case the content required for the requested analysis is sent to that processor.

  2. 02

    Tenant separation

    Every organisation works in its own tenant. The separation reaches down into the database: every row carries its account, and database-level access rules let only members of that account reach its data.

  3. 03

    Access control

    Two-factor authentication adds a further layer of protection – mandatory for every seat of an account from the first booking. Account roles and project memberships control who may see or edit confidential content.

  4. 04

    No AI training on customer data

    Your engineering data is not used to train AI models. We use AI providers only through their business interfaces, where customer content is contractually excluded from training; the providers, processing locations and retention rules that apply to your account are listed on the compliance page. What you develop in inventMAP remains your knowledge.

    This assurance is part of our data processing agreement.

AI with clear roles

AI may suggest.Your team decides.

Gee and the analysis functions support research, structuring, interpretation and solution finding.

They can make relationships visible, propose options and raise questions.

The decision about what is adopted, developed further or rejected stays with people.

  1. 01SuggestAI generates options and pointers.
  2. 02TraceResults are connected to origin, context or evidence wherever possible.
  3. 03DecidePeople adopt, change or reject.

Assistance, not autopilot.

Data flow

What happens to my data?

A plain overview of the processing steps – not a marketing graphic, but the way your IT team can check it.

Show data flow in detail5 steps
  1. Your browser, your account

    Encrypted connection, sign-in with two-factor authentication

    Connection
    TLS-encrypted end to end (HTTPS enforced)
    Sign-in
    hosted Keycloak at Cloud-IAM, France; 2FA mandatory from booking
    Access
    only signed-in members of your account
  2. inventMAP application

    Scaleway, France

    Processing
    on dedicated instances at Scaleway in France
    Separation
    tenant separation down to the row (access rules in the database)
    Monitoring
    operational monitoring with alerting, independent of the production system
  3. Storage

    Database and file storage at Scaleway, France

    Storage
    database (Postgres) and object storage, encrypted at rest
    Backup
    automated backups by the hosting provider, recovery concept in place
    Access
    only your account; operator access solely for incident handling
  4. AI service, when needed

    Provider selectable per account

    Transmitted
    only the content needed for the specific analysis
    Provider
    EU provider in France (Scaleway infrastructure, Mistral) or – only if your account explicitly chooses it – Anthropic in the USA
    Training
    your data is not used to train AI models
  5. Result back in inventMAP

    In your account, with origin and context

    Storage
    results land in your tenant and stay linked to source and context
    Control
    your team adopts, changes or rejects

Not every piece of knowledgebelongs with everyone.

Technology strategies, early concepts, patent ideas or decisions not yet released need different visibility. inventMAP maps this with roles, project memberships and visibility levels.

Account roles

Owner, admin and member – administration, booking and invitations stay with the entitled roles.

Project memberships

Those who work in a project see its content. Those who are not members do not.

Private or team

Searches, minutes and tasks can be kept private or made visible to the team.

Private first stage

Patent ideas start in a private space and move deliberately into the project, the team and the network – never the other way round.

Share when it helps.Restrict when it matters.

Transparency over superlatives

Security does not become more crediblejust because it is stated in absolutes.

No digital system is “secure” simply because a marketing claim says so.

That is why we prefer to describe concretely which measures are in place, who is responsible for what, and which questions we need to work through together with your IT team.

If your organisation has additional requirements, we go through them together before a pilot.

For IT teams

Technical details

What is actually in place – with nothing added from the usual SaaS checklist. Every item is backed internally by its source.

Show technical details7 areas
Authentication3 items
  • Sign-in through a hosted Keycloak at Cloud-IAM (France); sessions via Auth.js with Keycloak as identity provider.
  • Two-factor authentication (TOTP), mandatory for every seat of an account from the first booking.
  • Operator access to customer accounts only through a logged function the customer can switch off at any time.
Data separation3 items
  • One tenant per organisation; every database row carries its account.
  • Row level security in the database: access rules let only members of the respective account reach its data.
  • Administrative functions additionally bound server-side to account roles (owner, admin).
Infrastructure4 items
  • Application on dedicated instances at Scaleway (France), database as managed Postgres and file storage as object storage with the same provider.
  • Transport encrypted (TLS 1.2+), HTTP redirected to HTTPS.
  • Encryption at rest for database and object storage.
  • Builds run on a separate operations instance; container images stay in a private registry with the same provider.
AI services4 items
  • Provider selectable per account: EU provider in France (Scaleway infrastructure, Mistral) or – only by explicit choice – Anthropic in the USA.
  • Only the content needed for the specific analysis is transmitted.
  • Your data is not used to train AI models.
  • Speech recognition and OCR on a dedicated GPU instance at Scaleway, started only when used.
Research sources2 items
  • Internet research runs through our own search instance (SearXNG) on our infrastructure; an external search service only supplements results when they are too thin. Only search terms are transmitted, never customer documents.
  • Patent data comes from Questel or from public sources (European Patent Office, DPMA). Those receive search queries only, no personal customer data.
Operations3 items
  • Automated database backups by the hosting provider; recovery concept in place.
  • Availability and resource monitoring with e-mail alerting, operated outside the production system.
  • Incident runbook for operations; deployments only after checking for running customer analyses.
Development & testing4 items
  • Changes only via pull requests; automated type and UI tests before every deployment.
  • Dependency scanning (Dependabot) and weekly static code analysis (CodeQL).
  • Weekly penetration tests against the running application (automated, OWASP ZAP); additional in-depth checks after major rebuilds.
  • Living security register with audit history in the operator desk.

No ISO 27001 or TISAX certification. If you need one, we will talk openly about what is covered today.

Secure technologyalso needs secure use.

inventMAP protects the platform. At the same time, organisations control who gets access, which information is entered and how internal releases are organised.

Responsibilities in detail8 items

inventMAP is responsible for

  • platform and infrastructure
  • technical protective measures
  • tenant separation and access protection
  • operations, backup and monitoring

Your organisation controls

  • users and access assignment
  • which content is entered
  • internal classification and releases
  • the choice of AI provider

You do not have to take our word for it

Let your IT teamask the right questions.

For a pilot or rollout, technical, data-protection and organisational requirements can be clarified together in advance.

Arrange a security call Send technical questions

On request, we compile the technical information available for your review in a structured form.

For IT, procurement and data protection: See the compliance facts →

Sovereignty is not only aboutwhere data is stored.

It also means that technical knowledge stays traceable, decisions stay with the team, and engineering context does not disappear into an opaque AI chat.

Does inventMAP meet yoursecurity requirements?

Bring your IT, data-protection or information-security questions with you. Before any deployment we clarify what your organisation needs and what inventMAP actually covers today.