Built for confidential engineering data
inventMAP processes your most valuable knowledge — inventions, before they are protected. That is why security is built in from the start. Here we explain in plain language what that means for you, no IT background required.
Your data stays European — genuinely European
Many providers advertise “hosting in the EU”. The catch: it often runs in the data centre of a US corporation (Amazon, Microsoft, Google). Such providers are subject to US law — US authorities could in theory demand access, even to data stored in Europe.
With inventMAP the entire chain is European: application, database and storage (Scaleway, France), sign-in (Cloud IAM, France), AI optionally fully European (Mistral, France) and an internet search we operate ourselves. No US hyperscaler.
Several layers — each with a clear purpose
Strict tenant separation — down to the data row
What this means for you: The separation of your data from that of other customers sits in the database itself, not just in the interface. Even in the event of a software error, access by others remains technically impossible.
Trade-secret projects — sealed to those in the circle
What this means for you: Particularly sensitive topics can be locked to a small circle of confidants. Even other employees of your own company cannot see them — the separation reaches into the database.
Encryption — in transit and at rest
What this means for you: Your data is encrypted in transit (as in online banking) and at rest. Intercepted or stolen data is unreadable without the key.
Mandatory two-factor sign-in
What this means for you: A stolen password alone is not enough — your device is also required (authenticator app or passkey). This prevents account takeovers.
An answer for every known threat
The most common attack routes against web applications — and how inventMAP defends against them:
AI analysis without giving your data away
You choose the AI provider per account — fully EU-sovereign (open models on European infrastructure, or Mistral) or Claude for maximum analytical depth. Your content is processed exclusively for your analysis and is never used to train AI models or passed on. Internet research runs through our own search on EU infrastructure — nothing is passed to commercial search services.
Because AI brings risks of its own, we review specifically against the recognised catalogue for AI applications (OWASP Top 10 for LLM): instructions hidden in content remain without effect, AI responses are never executed as program code unchecked, and AI usage is capped and traceable per account.
Dictation and read-back stay in-house
Voice control for inventMAP is in preparation — and its design is settled: when you dictate something or have an answer read back to you, your voice will not leave our own European infrastructure. Speech recognition (listening) and speech output (reading back) run on our own server — not at Google, Amazon, OpenAI or any other speech service. The recording is transcribed and discarded immediately, never stored. That way even the spoken word stays confidential.
So your data is still there tomorrow
Restore-tested backups
What this means for you: Daily backups — and we check regularly that a restore genuinely works from them. A backup that has never been tested is only a hope.
Traceable administration
What this means for you: Security-relevant administrative actions (for example releases or permission changes) are logged.
Continuous security testing
Security is a process, not a state. Our code and our building blocks are continuously and automatically checked for vulnerabilities — not just on a single reference date.
Automated code analysis on every change
Every code change is examined for typical vulnerabilities with an established security tool (GitHub CodeQL) before it goes live.
Regular penetration tests by external specialists
Beyond our own review, we have the application continuously attacked by an independent security firm — at short intervals and additionally after every major rebuild, following recognised standards (including OWASP, NIST, BSI). Any findings are addressed promptly. An outside view finds what your own overlooks.
Structured reviews against recognised standards
In addition to the automation, we review regularly against the established security catalogues — OWASP Top 10 (web), OWASP API Security Top 10 and OWASP Top 10 for AI applications — using a maintained checklist. That way nothing slips through when new functions are added either.
Monitored software components
All components in use are continuously checked against known vulnerability databases and updated promptly. We also prevent credentials from accidentally ending up in the code.
Protected sign-in area
The login is secured against automated password guessing: after several failed attempts the account is temporarily locked. Signed-in sessions are time-limited.
What comes next
We build transparently. Some things are already available on request, others are what we build next — we state both openly instead of hiding them. That openness is part of our security promise:
Documents for your IT & procurement
For pilots and procurement we provide the formal summary of data processing as well as a data processing agreement (DPA) including technical and organisational measures. We are happy to hold a technical security call with your IT department.
Questions about security? gregor@inventissimo.de