Invistant
Security
Last updated July 17, 2026
Your company’s knowledge is the product. Protecting it is not a marketing slogan for us—it is how Invistant is built.
This page explains the practices we take seriously today. We only describe controls that exist in the product. We do not claim certifications we have not earned.
Private by workspace
Every customer operates in an isolated workspace (tenant). Application requests are authenticated, and data access is scoped to that workspace. One organization’s notes, files, and search results are not intended to be visible to another.
Your knowledge stays yours
You bring the content. You own it. We process workspace content to provide the service you signed up for—not to sell it, and not to use it as a public training corpus for unrelated products.
Evidence stays intact
Source files are stored as immutable evidence objects (content-addressed). Derived results (such as extractions or search indexes) are kept separately so the originals are not rewritten in place when the product analyzes them.
Actions you can audit
Important product actions are recorded in an audit trail associated with your workspace, so administrators can understand what happened and when.
Transport and authentication
- HTTPS — the marketing site and product app are served over TLS.
- Passwords — stored using one-way hashing, not plain text.
- Sessions — the product uses signed tokens for authenticated API access.
Payments
Card payments are handled by Stripe. We do not store full payment card numbers on Invistant servers.
Transactional email (for example password reset) is sent through our email provider when configured. We use it for account and security-related messages, not for selling your inbox.
What we are careful not to over-claim
We will not list logos or attestations we do not have. If you need a formal security questionnaire, DPA, or compliance discussion for procurement, contact us and we will be direct about what we can support today.
Report a concern
If you believe you have found a security issue, email security@invistant.com. Please include enough detail for us to reproduce and prioritize the report.
For how we handle personal information generally, see our Privacy Policy.