← Home

Trust & Security

Your statements are privileged. We treat them that way.

This page is maintained by Inverse to answer common security and privacy questions about how we handle your royalty statements, contracts, and account data. It describes the controls in place today — not a third-party certification.

Data protection

How your data is protected

All traffic between you and Inverse is encrypted in transit over HTTPS/TLS. The statements, contracts, and findings you send us are stored in a managed cloud database and object storage that encrypt data at rest.

Inverse runs on SOC 2 Type II compliant cloud infrastructure — managed database, authentication, storage, and compute. The underlying platform is independently audited to SOC 2 Type II and hosted in facilities that also carry ISO 27001 and PCI DSS certifications. Payments are processed by Stripe (PCI DSS Level 1).

Access is scoped to your account at the database level. Row-level security means no other customer — and no unauthenticated request — can read your statements or findings. Every query runs as you, against only your rows.

We treat uploaded statements as privileged and confidential. They are used only to perform your royalty analysis, and are never sold, shared for advertising, or used to train third-party AI models — model calls run under enterprise API terms that contractually exclude your data from training.

Access

Authentication

You sign in with email and password or with Google. Passwords are checked against known breach databases (Have I Been Pwned) at sign-up and password change, so a compromised password can't be used to protect your account.

Sign in and analysis screens are gated — you must be authenticated to reach them.

Collection

What we collect and why

We collect the statements and contracts you upload, the findings we generate from them, and basic account information (name, email, company). That's it. Each piece exists to run and deliver your analysis.

Retention & deletion

You stay in control

You can export a complete copy of your data, or permanently delete your account and everything tied to it, at any time — no email ticket required. Both live on your account & support screen once you're signed in.

Deleting your account removes your statements, findings, analysis runs, and stored files, and closes your login.

GDPR / CCPA

Your privacy rights

We honor data-subject rights under GDPR and CCPA, including the right to access, correct, export, and delete your personal data. The self-service export and deletion tools above cover access and erasure directly; for corrections or any other request, contact us and we'll act on it.

Contracts

Data Processing Agreement

A Data Processing Agreement (DPA) is available to customers on request. If your organization requires a signed DPA before sending statements, reach out and we'll provide one.

Subprocessors

Who we rely on

We keep our subprocessor list short and purposeful:

  • A managed cloud platform that hosts our database, authentication, storage, and compute.
  • Stripe, which processes payments. Inverse never stores your full card details.

Contact

Security & privacy contact

To report a vulnerability, ask a privacy question, or request a DPA, use our support form. A dedicated security contact address will be published here shortly.

This page reflects our current practices and is updated as they evolve. SOC 2 Type II, ISO 27001, and PCI DSS certifications referenced above apply to the underlying cloud infrastructure and payment processor Inverse relies on; Inverse is not itself independently certified at this time. Where a company-level audit matters to your organization, we're happy to discuss our roadmap.