INQUVO LEGAL & TRUST CENTRE

Security Policy

INQUVO uses layered technical and organisational controls designed for sensitive interior project, rate-card, supplier quotation, cost and margin data.

Last updated: 24 August 2026Version 1.1

1. Our Commitment to Security

INQUVO, operated by Cabinetkart, is designed to handle commercially sensitive information for interior contractors, fit-out firms and design-build companies. Security is integrated across authentication, tenant isolation, private file storage, server-side AI processing, billing and privileged administration.

INQUVO does not claim an independent SOC 2, ISO 27001, HIPAA or similar certification unless expressly confirmed in a current written statement. Infrastructure providers may maintain their own certifications, which do not automatically certify INQUVO.

2. Infrastructure, Network and Encryption

Managed cloud infrastructure

The platform uses managed cloud, database, authentication, storage and edge-deployment services. Provider-level network protection, availability controls and compliance programs support the application environment.

Data in transit

Supported production traffic between browsers, application endpoints and provider APIs is protected using HTTPS and current TLS protocols.

Data at rest

Database and stored-file protection relies on the encryption and security controls of configured managed infrastructure providers. Sensitive provider credentials and service keys are retained server-side and are not intentionally exposed to the browser.

Application perimeter

Production configuration includes security response headers, framework protections, platform-level traffic filtering and provider-level denial-of-service mitigations.

3. Data Isolation and Access Control

PostgreSQL Row Level Security

Company records are associated with tenant identifiers and protected using PostgreSQL Row Level Security policies. Application requests are authenticated and authorised before access to tenant data is allowed.

Private file access

Project files are stored in private locations and accessed through controlled or signed requests. Customers should not publish private project URLs or share authorised sessions.

Authentication and sessions

Authentication is provided through cryptographically protected session mechanisms. Password credentials are handled by the configured authentication provider and are not stored by INQUVO in plain text.

Privileged access

Platform-administrator access is separated from customer company roles, verified on the server and intended to follow least-privilege principles. Privileged mutations are recorded in append-only audit records where implemented.

4. Backup, Resilience and Recovery

INQUVO relies on configured infrastructure-provider backup, replication and recovery capabilities together with application-level deployment and data-integrity controls. Available retention and point-in-time recovery capabilities depend on the active provider plan and production configuration.

Customers remain responsible for retaining source drawings, supplier documents and exported commercial records needed for their own business-continuity requirements.

5. AI and Intellectual Property Security

Server-side provider access

AI credentials remain on the server. The platform sends only relevant input and context required for the user-requested operation through authenticated provider APIs.

No public AI training

INQUVO does not use private floor plans, BOQs, rate cards, supplier quotations or internal costing data to train public foundational AI models.

Review and deterministic controls

AI results remain reviewable. Deterministic rules and company-approved commercial data perform final calculations, reducing the risk of an AI interpretation silently changing a quotation.

6. Vulnerability and Incident Management

Engineering controls include dependency and code analysis, production health checks, restricted secrets, validated inputs, logging and controlled deployment workflows. Confirmed issues are assessed and remediated according to severity and available evidence.

If a verified incident affects customer information, we will investigate, contain and remediate it and provide notifications where required by applicable law or contractual obligation.

7. Responsible Disclosure

Report suspected vulnerabilities privately to security@inquvo.app. Include the affected endpoint or feature, reproduction steps and potential impact. Do not access, modify, download or disclose another customer's data while testing.

Entity: Cabinetkart, operating as INQUVO
Address: Building No. 48, BHIVE Platinum Church Street, Shanthala Nagar, Bengaluru, Karnataka 560001, India