What happens to your network's data
We see a network's turnover, its suppliers and its purchase prices. This is one page about who can do what with that data, where it is stored, and where to write if you have found a hole.
We hold no certifications and will not draw badges. Below is only what you can verify inside your own tenant: access settings, the action log, and keys you revoke yourself.
What we commit to doing with data
We do not sell it, do not fold it into a market data product and do not use it for other clients' analytics — anonymised extracts included. Anonymised turnover by category still names the size of the network.
We connect to the accounting system read-only. Write-back is a separate client decision, a separate setting and a separate conversation — not a side effect of onboarding.
A read key and file exports exist from day one: data marts as CSV, orders as XLSX. Leaving us must not depend on our willingness to export something.
How long backups live and what happens to data after termination is fixed in the contract with the specific network. We are not going to invent a tidy number for a web page.
Roles and access
One rule: anything that can leave the tenant is switched on by the network owner, not by us during onboarding.
Its own database, keys and schedules. One client's request cannot technically reach another's data — this is separated storage, not a permission checkbox.
Automatic order sending, write-back to accounting, a public read key — the network owner switches each of these on and off. Large orders can stay on mandatory confirmation.
A public key is scoped to its client's data and works read-only. It is revoked by the owner at any moment, without asking us.
Who edited an order, who sent it, to whom and when. A log you can tidy up with a button proves nothing — so there is no such button.
The team is small, and the people who write the calculation are the ones who investigate failures. We do not hide it: during an incident an engineer works with the network's data, and actions in the interface land in the same log as the client's own.
How to report a vulnerability
If you have found a vulnerability, write to komron@invent.sale. A description of the steps and what you got is enough: a screenshot, the request, the server response.
The message is read by someone who can change the code. We confirm receipt and say whether we reproduced it — even when the report turns out to be a false alarm.
A network owner hears about a problem affecting their data from us, not through someone else's retelling. What was possible and what we did — with no softened wording.
Behind the data are working pharmacies and stores: an order that goes out to a supplier during your test arrives on a truck. If you need an environment, ask and we will arrange one.
Who we share data with
With nobody except those the network itself addresses, and only within the limits it sets.
One network's data never enters another's calculation, report or training set. That is not a future policy but a consequence of separated tenants.
A supplier sees the order addressed to them and its history. Not the network's stock, not other suppliers' prices, not what the network orders elsewhere.
If a network wants to hand data to its integrator or consultant, it issues a read key itself. We are not a middleman and do not grant access on its behalf.
When an order reaches a supplier through a messenger, the contents of that order pass through the messenger. We say so before launch: the alternative is a file by email, which is slower and read less often.
Where data is stored
Data sits on the platform's rented servers. We do not forward a network's exports into third-party analytics services or wire trackers into them.
The specific data centre and country are named when the contract is signed, along with retention terms. On a website it would be a promise that is hard to verify.
The nightly export lands in that client's directory and feeds the calculation from there. There is no shared directory holding every network's files.
In more detail
Data access and responsible AI in detail
What we do with shopper data
How we report failures
What changed in the platform, and why
Read key, webhooks, exports
How effect is measured, and when we refuse
Show us one critical process. We will show how it runs here.
We look at your cycle: how an order is assembled today, who decides, where time leaks and what the system takes over.