Skip to main content
Menu
Product
Solutions
Integrations
Resources
Security

Your catalog is your business. We treat it that way.

The practices below describe how InventaCloud protects your data today — written plainly, with nothing claimed that isn't in place. Questions? Email support and a human will answer.

Tenant isolation

Every catalog, product row, image, and conversation is scoped to your company account. Cross-tenant access checks are part of our development standard for every feature we ship.

Email-code login

Sign-in uses a one-time 6-digit code delivered to your verified email — there's no stored password to leak, phish, or reuse. The same applies to reseller portal access.

Roles & permissions

Owner, admin, and member roles control what each teammate can do. Resellers only ever see the catalogs, products, and prices you've explicitly assigned to them.

Activity logging

Catalog publishes, rule changes, reseller approvals, and team-permission updates are recorded in an auditable activity log, so you can always see who did what.

Credential protection

Integration tokens and connection credentials are encrypted at rest. Sales-channel connections use scoped access — we ask for only the permissions the integration needs.

AWS infrastructure

Catalogs, images, and files are stored on Amazon Web Services infrastructure, with processing pipelines built on managed AWS services. All traffic to the platform is served over HTTPS.

Stripe-hosted billing

Payments run entirely through Stripe's hosted checkout and billing portal. Your card details never touch InventaCloud's servers.

You own your data

Everything you upload stays yours. We never sell or share your catalogs, pricing, or customer lists — and we never use your data to train AI models.

Export anytime

Every catalog, mapping, and image asset can be exported in CSV, XLS, or JSON at any time — directly from the app or via API. No lock-in, no export fees.

A note on certifications: InventaCloud does not currently hold formal security certifications (such as SOC 2 or ISO 27001). We describe only the practices actually in place, and this page is updated as our security program grows. If your organization has specific compliance requirements, talk to us — we'd rather answer honestly than badge-collect.

Questions about how we'd handle your data?

Ask us directly — a real person answers, typically within one business day.