nvena
TrustHelpFAQContactOpen app

Security overview

Invena Labs Limited (trading as invena)
167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom
Company number 17237229
Registered in England and Wales

Last updated: 19 July 2026

Invena is in private beta. This page summarises our security posture at a high level. It is not a certification or audit report.

For privacy and data handling, see our Privacy Policy. For third-party providers, see our Subprocessor register.


Service scope

During private beta, Invena provides:

  • A beta web application at app.invena.app (invitation-only) for organising and sharing household information within Spaces
  • A governed API for authentication, permissions, and data access
  • Legal and trust pages on this website

Access to new accounts is invitation-only. Public self-service sign-up is disabled.


Infrastructure

AreaApproach
Data storageSupabase (PostgreSQL and private object storage) in West Europe (London)
AuthenticationSupabase Auth; email confirmation required
API hostingRailway
Product appVercel (Next.js)
WebsiteVercel (static Next.js pages)

Data protection

LayerWhat we do today
In transitHTTPS/TLS between your browser, our app, and our API
At restEncryption at rest through our cloud providers (Supabase, object storage)
Access controlSpace-scoped roles (owner, editor, viewer); API enforces membership on every request
DocumentsPrivate buckets; short-lived signed URLs; backend-mediated access only
SessionsConfigurable inactivity auto-lock; single-session option; JWT-based auth

We do not currently offer end-to-end or client-side encryption — our service must read your data to organise entries, run intake, and generate exports. See our FAQ for the same limitation in plain language.


Technical controls (beta)

ControlStatus
Private storage bucketsDocument storage is not public-by-default
Permission modelSpace-scoped roles enforced by the API
Audit eventsOperational audit trail; sensitive content excluded from logs where configured
Error monitoringSentry on the API with scrubbing configured
Uptime monitoringExternal health checks on /health (when configured)
Malware scanning (uploads)ClamAV sidecar on the API upload path
Dependency monitoringGitHub Dependabot on the repository

Reporting a security concern

If you believe your account has been compromised or you have found a security issue:

Report: Security contact

Please include enough detail for us to investigate. Do not include passwords or full document contents unless we ask you to.


Roadmap (honest)

We are exploring application-level encryption for certain sensitive Entry fields so those values are not casually readable in the database without our application key. This is a work-in-progress roadmap item during beta, not a claim that every field or legacy value is protected that way today. We do not claim end-to-end encryption. The service must be able to decrypt data to organise Entries, run intake, and generate exports. Any implementation, assurance work, and related disclosures will be updated if and when the feature is shipped.


Limitations (beta)

This is an early-access service. No online service can guarantee absolute security. We design for least privilege, auditability, and clear user control over who can access each Space.

nvena

Product

  • Trust centre
  • Help centre
  • FAQ
  • Security
  • Open app

Company

  • About
  • Contact
  • Beta access

Resources

  • Legal
  • Privacy Policy
  • AI Policy
  • Terms of Service
  • Acceptable Use
  • Content & Use
  • Accessibility
  • Cookies
  • Copyright
  • Subprocessors
  • Open Source

Built in Chichester, England. Privacy-first by design. Designed for life's important moments.

Invena Labs Limited trading as invena. Company number 17237229. Registered office: 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom. Registered in England and Wales.

© 2026 Invena Labs Limited