Trust & Security
Your statements are privileged. We treat them that way.
This page is maintained by Inverse to answer common security and privacy questions about how we handle your royalty statements, contracts, and account data. It describes the controls in place today — not a third-party certification.
Data protection
How your data is protected
All traffic between you and Inverse is encrypted in transit over HTTPS/TLS. The statements, contracts, and findings you send us are stored in a managed cloud database and object storage that encrypt data at rest.
Inverse runs on SOC 2 Type II compliant cloud infrastructure — managed database, authentication, storage, and compute. The underlying platform is independently audited to SOC 2 Type II and hosted in facilities that also carry ISO 27001 and PCI DSS certifications. Payments are processed by Stripe (PCI DSS Level 1).
Access is scoped to your account at the database level. Row-level security means no other customer — and no unauthenticated request — can read your statements or findings. Every query runs as you, against only your rows.
We treat uploaded statements as privileged and confidential. They are used only to perform your royalty analysis, and are never sold, shared for advertising, or used to train third-party AI models — model calls run under enterprise API terms that contractually exclude your data from training.
Access
Authentication
You sign in with email and password or with Google. Passwords are checked against known breach databases (Have I Been Pwned) at sign-up and password change, so a compromised password can't be used to protect your account.
Sign in and analysis screens are gated — you must be authenticated to reach them.
Collection
What we collect and why
We collect the statements and contracts you upload, the findings we generate from them, and basic account information (name, email, company). That's it. Each piece exists to run and deliver your analysis.
Retention & deletion
You stay in control
You can export a complete copy of your data, or permanently delete your account and everything tied to it, at any time — no email ticket required. Both live on your account & support screen once you're signed in.
Deleting your account removes your statements, findings, analysis runs, and stored files, and closes your login.
GDPR / CCPA
Your privacy rights
We honor data-subject rights under GDPR and CCPA, including the right to access, correct, export, and delete your personal data. The self-service export and deletion tools above cover access and erasure directly; for corrections or any other request, contact us and we'll act on it.
Contracts
Data Processing Agreement
A Data Processing Agreement (DPA) is available to customers on request. If your organization requires a signed DPA before sending statements, reach out and we'll provide one.
Subprocessors
Who we rely on
We keep our subprocessor list short and purposeful:
- A managed cloud platform that hosts our database, authentication, storage, and compute.
- Stripe, which processes payments. Inverse never stores your full card details.
Contact
Security & privacy contact
To report a vulnerability, ask a privacy question, or request a DPA, use our support form. A dedicated security contact address will be published here shortly.
This page reflects our current practices and is updated as they evolve. SOC 2 Type II, ISO 27001, and PCI DSS certifications referenced above apply to the underlying cloud infrastructure and payment processor Inverse relies on; Inverse is not itself independently certified at this time. Where a company-level audit matters to your organization, we're happy to discuss our roadmap.