Security
Control is built into every decision.
Permissions, evidence, approvals and auditability remain attached from source to action.
Request
Identity
Permission
Boundary
Human Control
Audit
Maya Chen requests access
Resource: Lease Schedule.pdf · Action: Review source evidence
Permission check · Investment Analyst
Audit event
Actor Maya Chen
Evidence Lease Schedule.pdf
Outcome Permitted
Reviewer Daniel Reed
Time 09:41:12
State Pending approval
Access granted · action pending human approval · audit event recorded
Enterprise Assurance
Building toward recognised enterprise standards.
Security, governance and auditability are being built into the platform while formal assurance readiness develops alongside customer implementation.
SOC 2
Controls, evidence collection and operating processes are being developed toward a future SOC 2 audit.
ISO 27001
Information-security management practices are being structured toward ISO 27001 readiness.
AI governance
Human oversight, traceability and governed AI operation are built into the product architecture.
GDPR & data handling
Data-processing, access, retention and deployment requirements are agreed for the customer environment.
Current assurance and certification status is provided during the security review.
Request a security reviewSecurity by Architecture
Protection across the full decision path.
Security is applied to the user, workspace, source, workflow and resulting decision record.
Identity
Authenticated user and role context
Workspace
Tenant and workspace boundary
Evidence
Permissioned source access
Action
Policy and human approval gate
Audit
Durable, traceable audit record
Identity
Authenticated user and role context
Workspace
Tenant and workspace boundary
Evidence
Permissioned source access
Action
Policy and human approval gate
Audit
Durable, traceable audit record
One connected security layer — identity to audit.
Access Control
The right access. The right authority.
Users can be permitted to view, review, propose or approve according to their role and workflow.
Roles & permissions
Analyst
Deal Lead
Investment Committee
Administrator
Restricted action
Analyst attempts: Approve submission
Blocked — routed to Investment Committee
Audit event recorded
Access does not equal authority.
Material decisions remain subject to the configured human approval path.
Data Control
Evidence stays inside the governed workspace.
Sources, extracted values and generated outputs remain linked to their permitted workspace and review context.
Workspace Isolation
A user assigned to one workspace cannot see another.
Project Meridian
Permitted
Project Northstar
Not permitted
Workspace boundaries enforced automatically.
Source Provenance
Every extracted value stays linked to where it came from.
Purchase price
€24.6m
Investment Memorandum.pdf · p.4
Reviewed
Retention & Export
Requirements are agreed for your environment, not fixed globally.
Auditability
Reconstruct how every material decision was reached.
Evidence, assumptions, findings, rationale, reviewers and actions remain connected in one decision record.
Source evidence reviewed
Maya Chen · Lease Schedule.pdf · Evidence linked
Assumption conflict detected
Maya Chen · Lease Schedule.pdf §4.3 · Conflict flagged
Finding assigned to Deal Lead
Daniel Reed · Under review
Rationale added
Daniel Reed · Rationale recorded
IC submission prepared
Daniel Reed · Ready for IC
Traceable event history — every step above stays linked to its actor, source and outcome.
AI Governance
AI proposes. Rules and people control.
Inversiq separates generated signals from governed decisions, with review requirements attached to material actions.
Featured
Evidence before output
Generated conclusions remain connected to their supporting source material.
Supported statement
Lease break conflicts with the occupancy assumption.
Unsupported statement
Market rents in the submarket are trending upward.
Unsupported statements are never surfaced as decisions.
Governance
Configurable approval gates
Material findings follow the required human review path.
Material finding
Lease break conflicts with the occupancy assumption.
Routed to Daniel Reed
Governance
Recorded rationale
Rules, recommendations and overrides remain visible in the decision record.
Governance
Controlled execution
Only approved actions are routed to connected workflows.
Proposed action queued
Approved by reviewer
Routed to connected workflow
Enterprise Assurance
Security requirements are part of implementation.
Deployment, identity, access, data handling, integrations and review controls are agreed for the customer environment.
Controlled production rollout
Current platform direction
Assurance roadmap
FAQ
Security FAQ
Answers to common questions from enterprise, security and IT teams.
Encryption approach, key management and configuration are part of the platform's security architecture. Detailed architecture and control information is available during the security review.
Access is based on role, workspace and workflow responsibility, and workspace boundaries are enforced so a user assigned to one project cannot see evidence, findings or records from another.
Material outputs remain connected to the source evidence behind them. The rules applied, findings raised, reviews performed and approvals given can remain visible alongside the output, and human reviewers retain responsibility for material judgment — nothing material is treated as final without that trail attached.
Customer data is used to operate Inversiq and, where authorised, to evaluate and improve customer-specific models, rules and workflows within that customer's scoped environment. Customer data and learning signals are not pooled across customers or used to improve models for other organisations. Any use for shared model training requires explicit agreement, and external AI providers may only process data under approved contractual and technical controls.
Exact hosting, access and retention requirements are agreed for the customer environment during implementation.
Retention, export and deletion requirements are agreed contractually, and handling follows the customer environment and applicable requirements at the time.
Each material event — an approval, override or resolved finding — records the actor, the action, the evidence involved, the permission outcome, the reviewer and the resulting state, so rationale stays visible in the decision record rather than only the final outcome.
Yes. Inversiq is designed to connect with existing identity, document and workflow systems rather than requiring a full replacement. Specific integrations are configured per deployment.
Model-provider selection and configuration are assessed as part of the platform architecture. Specific providers and data-use terms are documented during implementation and available during the security review.
Architecture documentation, current assurance status and applicable control information are shared during the security review, alongside the implementation and deployment requirements relevant to procurement.
Review security with the Inversiq team.
Discuss your access, deployment, data-handling and assurance requirements.