Security

Control is built into every decision.

Permissions, evidence, approvals and auditability remain attached from source to action.

Access ReviewGoverned workspace

Maya Chen requests access

Resource: Lease Schedule.pdf · Action: Review source evidence

Identity verified
Maya Chen · Investment AnalystWorkspace: Project Meridian

Permission check · Investment Analyst

Allowed — View evidenceRestricted — Approve final decision
Workspace boundary enforced — Project Meridian only
Material model change requires Deal Lead approvalRouted to Daniel Reed

Audit event

Actor Maya Chen

Evidence Lease Schedule.pdf

Outcome Permitted

Reviewer Daniel Reed

Time 09:41:12

State Pending approval

Access granted · action pending human approval · audit event recorded

Enterprise Assurance

Building toward recognised enterprise standards.

Security, governance and auditability are being built into the platform while formal assurance readiness develops alongside customer implementation.

Readiness work

SOC 2

Controls, evidence collection and operating processes are being developed toward a future SOC 2 audit.

Readiness roadmap

ISO 27001

Information-security management practices are being structured toward ISO 27001 readiness.

Platform direction

AI governance

Human oversight, traceability and governed AI operation are built into the product architecture.

Implementation requirement

GDPR & data handling

Data-processing, access, retention and deployment requirements are agreed for the customer environment.

Current assurance and certification status is provided during the security review.

Request a security review

Security by Architecture

Protection across the full decision path.

Security is applied to the user, workspace, source, workflow and resulting decision record.

Identity

Authenticated user and role context

Workspace

Tenant and workspace boundary

Evidence

Permissioned source access

Action

Policy and human approval gate

Audit

Durable, traceable audit record

One connected security layer — identity to audit.

Access Control

The right access. The right authority.

Users can be permitted to view, review, propose or approve according to their role and workflow.

Access ControlGoverned workspace

Roles & permissions

Analyst

View evidenceEdit assumptions

Deal Lead

Resolve findingsEdit assumptions

Investment Committee

Approve submission

Administrator

Configure workflow

Restricted action

Analyst attempts: Approve submission

Blocked — routed to Investment Committee

Audit event recorded

Access does not equal authority.

Material decisions remain subject to the configured human approval path.

Data Control

Evidence stays inside the governed workspace.

Sources, extracted values and generated outputs remain linked to their permitted workspace and review context.

Workspace Isolation

A user assigned to one workspace cannot see another.

Project Meridian

Permitted

Project Northstar

Not permitted

Workspace boundaries enforced automatically.

Source Provenance

Every extracted value stays linked to where it came from.

Purchase price

€24.6m

Investment Memorandum.pdf · p.4

Reviewed

Retention & Export

Requirements are agreed for your environment, not fixed globally.

RetentionConfigured during implementation
ExportConfigured during implementation
DeletionConfigured during implementation

Auditability

Reconstruct how every material decision was reached.

Evidence, assumptions, findings, rationale, reviewers and actions remain connected in one decision record.

AuditabilityGoverned workspace

Source evidence reviewed

Maya Chen · Lease Schedule.pdf · Evidence linked

09:41

Assumption conflict detected

Maya Chen · Lease Schedule.pdf §4.3 · Conflict flagged

09:44

Finding assigned to Deal Lead

Daniel Reed · Under review

09:47

Rationale added

Daniel Reed · Rationale recorded

09:53

IC submission prepared

Daniel Reed · Ready for IC

10:02
Decision record complete for review

Traceable event history — every step above stays linked to its actor, source and outcome.

AI Governance

AI proposes. Rules and people control.

Inversiq separates generated signals from governed decisions, with review requirements attached to material actions.

AI GovernanceGoverned

Featured

Evidence before output

Generated conclusions remain connected to their supporting source material.

Supported statement

Lease break conflicts with the occupancy assumption.

Lease Schedule.pdf §4.3

Unsupported statement

Market rents in the submarket are trending upward.

No source — flagged for review

Unsupported statements are never surfaced as decisions.

Governance

Configurable approval gates

Material findings follow the required human review path.

Material finding

Lease break conflicts with the occupancy assumption.

Routed to Daniel Reed

Governance

Recorded rationale

Rules, recommendations and overrides remain visible in the decision record.

Rule applied
Recommendation logged
Override visibility

Governance

Controlled execution

Only approved actions are routed to connected workflows.

Proposed action queued

Approved by reviewer

Routed to connected workflow

Enterprise Assurance

Security requirements are part of implementation.

Deployment, identity, access, data handling, integrations and review controls are agreed for the customer environment.

Security requirements reviewed
Identity approach agreed
Roles and permissions configured
Approved sources connected
Logging and review validated
Production access approved

Controlled production rollout

Current platform direction

Permissioned access
Auditability
Human review
Workspace controls
Governed integrations

Assurance roadmap

SOC 2 readinessReadiness work
ISO 27001 readinessReadiness work
Independent security testingPlanned
Customer security reviewIn progress

FAQ

Security FAQ

Answers to common questions from enterprise, security and IT teams.

Encryption approach, key management and configuration are part of the platform's security architecture. Detailed architecture and control information is available during the security review.

Access is based on role, workspace and workflow responsibility, and workspace boundaries are enforced so a user assigned to one project cannot see evidence, findings or records from another.

Material outputs remain connected to the source evidence behind them. The rules applied, findings raised, reviews performed and approvals given can remain visible alongside the output, and human reviewers retain responsibility for material judgment — nothing material is treated as final without that trail attached.

Customer data is used to operate Inversiq and, where authorised, to evaluate and improve customer-specific models, rules and workflows within that customer's scoped environment. Customer data and learning signals are not pooled across customers or used to improve models for other organisations. Any use for shared model training requires explicit agreement, and external AI providers may only process data under approved contractual and technical controls.

Exact hosting, access and retention requirements are agreed for the customer environment during implementation.

Retention, export and deletion requirements are agreed contractually, and handling follows the customer environment and applicable requirements at the time.

Each material event — an approval, override or resolved finding — records the actor, the action, the evidence involved, the permission outcome, the reviewer and the resulting state, so rationale stays visible in the decision record rather than only the final outcome.

Yes. Inversiq is designed to connect with existing identity, document and workflow systems rather than requiring a full replacement. Specific integrations are configured per deployment.

Model-provider selection and configuration are assessed as part of the platform architecture. Specific providers and data-use terms are documented during implementation and available during the security review.

Architecture documentation, current assurance status and applicable control information are shared during the security review, alongside the implementation and deployment requirements relevant to procurement.

Review security with the Inversiq team.

Discuss your access, deployment, data-handling and assurance requirements.