Security
Security at InventX
This page describes what the product does today — not a roadmap and not a certification. InventX is pre-release and we're expanding these controls as we go.
Accounts and sessions
- Passwords are hashed with bcrypt. We never store or log them in plain text.
- Sessions use an httpOnly cookie with a short sliding expiry of 45 minutes of inactivity.
- Each user has a single active session — signing in on a new device signs out the previous one.
Access control inside the product
- 60 granular permissions, set per user, each of which can be scoped per location.
- Sensitive actions can require a one-time code (OTP) emailed to an approving manager before they go through.
- A business-wide lockdown switch signs out every user at once.
- An activity log records who did what, and when.
Infrastructure
- All traffic is served over HTTPS through Cloudflare.
- The API sends HSTS and other hardening headers.
- Error monitoring runs on Sentry, hosted in the EU.
- Transactional email (including OTP codes) is sent via Microsoft 365.
- Data is stored in MongoDB on infrastructure operated by InventX.
Report a vulnerability
If you believe you’ve found a security issue in InventX, email legal@pos.inventx.app with steps to reproduce. We’ll acknowledge your report within 3 business days and keep you informed while we work on a fix.
Please don’t access, modify or retain data that belongs to other customers while testing, and give us reasonable time to address the issue before sharing it publicly.
For how we handle personal data, see the Privacy Policy and Terms & Conditions.