Skip to content
New: managed cloud and dedicated servers — with dedicated support on every plan.See plans
Inventure Technologies
Trust & security

How we protect your systems and data

Plain-language answers to the questions security reviewers and privacy officers ask us — including the ones about what we are not.

Practices

Security practices we follow

Access control

Named accounts, least privilege, MFA and access reviews.

Encryption

TLS in transit; encrypted backups and disks where supported.

Patching

Automatic security updates and scheduled maintenance.

Backups

Off-server copies and restore tests on Managed plans.

Monitoring

Uptime, resources and security events watched continuously.

Secure development

Code review, dependency scanning and OWASP Top 10 checks.

These practices are aligned with the Essential Eight and the OWASP Top 10. Inventure does not currently hold ISO 27001, SOC 2 or IRAP certification.

What we are — and what we aren't#

Inventure Technologies is a software and managed-services company in Lalitpur, Nepal. We build software, and we set up, secure, monitor and support the servers it runs on.

We do not own data centres, hardware or networks. Servers run on infrastructure operated by OVHcloud, in the region you choose, and — when available — by local partners in Nepal. Certifications that apply to data centres (such as ISO/IEC 27001) belong to the infrastructure provider, not to Inventure. Inventure itself does not currently hold ISO 27001, SOC 2 or IRAP certification.

Where your data is stored#

You choose the region for every server: Sydney, Singapore, Mumbai, Frankfurt, London or Beauharnois (Canada). Servers inside Nepal through local partners are coming soon. Backups are kept in a location we agree with you — for example, keeping Australian data in Australia.

You can also keep everything in your own cloud account (AWS, Azure, Google Cloud or OVHcloud) and have us manage it.

Who can access it#

Our engineers work from Nepal. Access to client systems is limited to named engineers who need it, protected by multi-factor authentication, and logged. For sensitive data such as health information, access is granted just in time for a specific task, and development uses de-identified or synthetic data rather than real records.

Sub-processors#

These providers may process data on our behalf, depending on the service you use:

Provider

Purpose

Location

OVHcloud

Infrastructure: servers and storage

The region you choose

Resend or Google Workspace

Email delivery for our own communications

Global

Google Analytics

Website analytics (with consent where required)

Global

We will update this list when it changes.

Incidents and data breaches#

We follow a documented incident response process: contain, assess, notify and review. If an incident may affect personal information you are responsible for, we tell you promptly and help you assess it — including whether it is an eligible data breach under Australia's Notifiable Data Breaches scheme — so you can meet your obligations.

Vulnerability disclosure#

If you believe you have found a security vulnerability in our website or services, email info@inventuretech.com.np with the details and steps to reproduce. Please give us reasonable time to fix it before sharing it publicly, and don't access or change data that isn't yours. We will not take action against good-faith research that follows these guidelines. Our security.txt file has the same details.

Contracts and documents#

Our Cloud services terms, Service level agreement, Acceptable use policy and Privacy policy describe our commitments. We can also sign a data processing agreement with you — just ask.

FAQ

Questions, answered

Can’t find what you need? Ask us — a real engineer will reply.

Who owns the code and data?

You do. Code, designs, documentation and data belong to you, and we hand everything over whenever you ask. We don’t hold your systems hostage.

Where are your servers?

We run servers on OVHcloud’s infrastructure in Sydney, Singapore, Mumbai, Frankfurt, London and Canada, and servers inside Nepal through local partners are coming soon. You choose the region; your data stays there.

Is there a contract or lock-in?

Cloud servers are month to month. Dedicated servers have a setup fee that we waive on a 12-month term. You can export your data and we’ll help you move out if you ever leave.

Where is health data stored?

In the Sydney region for Australian clients who need data to stay in Australia — or inside your own cloud account if you prefer. We agree the location in writing before any data is loaded.

Your engineers are in Nepal — who can access our data?

Only named engineers who need it, only when they need it, with multi-factor authentication, and every access is logged. Development uses de-identified or synthetic data, and we support your own APP 8 assessment.

Are you compliant with the Privacy Act?

Compliance is an obligation on your organisation. We build and run software with controls designed to support your obligations under the Privacy Act 1988 and the Australian Privacy Principles, and we give you the documentation to show it.

What happens if there is a data breach?

We follow a documented incident response process, contain the issue, preserve evidence and help you assess whether it is an eligible data breach under the Notifiable Data Breaches scheme — quickly, because the clock matters.

Do you hold security certifications?

Inventure itself does not currently hold ISO 27001 or similar certifications. Our infrastructure provider’s data centres are certified, and we follow practices aligned with the Essential Eight and the OWASP Top 10.

How do I report a security issue?

Email info@inventuretech.com.np with the details. We acknowledge reports quickly and never take action against good-faith researchers.

Need more detail for a security review?

We’ll answer your questionnaire and share our security and privacy overview.