Legal · Security
Security at Invenzo Labs
How we protect the data, the platform and the workloads that run on top of it — the practices, the controls and the trust boundaries.
- Last update
- September 2026
Invenzo Labs India Private Limited (“Invenzo”, “We”, “Us”) builds the commerce platforms Izoleap, Izoware and Izowhiz used by retailers, distributors and brands to run their online storefronts, warehouses and last-mile operations. Their data is business-critical, and so is ours. This page describes how we protect it.
This page is a plain description of the practices we follow. It is not a substitute for the security addenda in a signed enterprise contract. If your organisation needs a specific control mapping (SOC 2, ISO 27001, DPDP Act, GDPR, PCI DSS scope statements), please write to us and we will share what is available.
1. Data encryption
All data in transit between your browser, our platforms and the services we integrate with is encrypted using TLS 1.2 or higher, with modern cipher suites and HTTP Strict Transport Security (HSTS) enabled at the edge. Public endpoints are served exclusively over HTTPS.
Data at rest — customer records, order and inventory data, backups, logs, and platform configuration — is stored on managed cloud services with disk-level and volume-level encryption enabled by default. Secrets, tokens and integration credentials are held in dedicated key-management stores rather than alongside application data or in source control.
2. Access controls
- Role-based access control across every platform. Roles are defined per tenant, and permissions are granted on the principle of least privilege — a user sees only the data the role needs to see.
- Multi-factor authentication is available on customer accounts and enforced on every Invenzo employee account that touches production systems.
- Session management uses signed, short-lived tokens. Concurrent sessions can be reviewed and revoked by an account administrator.
- Privileged access to production is restricted to a named group, granted just-in-time, and logged. Every production action is attributable to a person.
3. Infrastructure & network posture
Our platforms run on a major cloud provider inside India-region data centres. The production network is segmented: application, database and cache tiers each sit in their own subnets, and only the workloads that need to reach a tier are permitted to. Public exposure is limited to the load balancer and the API gateway.
Automated, encrypted backups run at least daily and are retained for a defined recovery window. We test restore procedures on a scheduled cadence, so a backup that cannot be restored is a backup we know about.
4. Application security
- Secure software development lifecycle. Code changes go through peer review, automated static analysis and unit / integration tests before they can be merged.
- Dependency management. We track third-party libraries continuously, apply security patches promptly and remove packages we no longer use.
- Environment separation. Development, staging and production run in separate environments with separate credentials. No production data flows into development or staging.
- Logging and monitoring. Application and infrastructure telemetry is centralised and reviewed. Anomalies — unusual login patterns, error spikes, unexpected data access — are flagged for investigation.
5. Incident response
We maintain a documented incident-response process covering detection, containment, investigation, remediation and post-incident review. In the event of a security incident that impacts your data, we will notify affected customers without undue delay in accordance with the notice obligations set out in your service agreement and applicable law.
Every incident is reviewed after the fact, and the remediations feed back into our practices so the same class of issue does not recur.
6. Compliance & standards
Our security programme is aligned with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Personal data handling is described in our Privacy Policy.
SOC 2. We are actively working towards SOC 2 compliance. When our audit is complete, the report type, effective date and issuing auditor will be stated here. Until then, please do not treat this page as a SOC 2 attestation. If your procurement process needs a security questionnaire, an NDA-scoped roadmap or a bridge letter, please contact us.
7. Shared responsibility
Security of a commerce platform is shared between us and you. We are responsible for the security of the platform itself — the code, the infrastructure and the operations. You are responsible for how the platform is used inside your organisation: keeping user credentials confidential, granting the right roles to the right people, revoking access when a user leaves, and configuring your integrations to send only the data those integrations need.
We recommend enabling multi-factor authentication for every user with administrative privileges, and reviewing your role assignments at least once a quarter.
8. Reporting a vulnerability
Security researchers and customers who believe they have found a vulnerability in our products or infrastructure are encouraged to report it privately, so we can investigate and address it before the details become public. Send a description of the issue, reproduction steps and any supporting material to info@invenzolabs.com with the subject line “Security report”. We will acknowledge receipt within two working days and keep you informed as the investigation progresses.
Please act in good faith: do not degrade the service for other users, do not access more data than is necessary to demonstrate the issue, and do not disclose the issue publicly until we have released a fix or thirty days have passed, whichever is earlier.
9. Contact
For questions about this page, requests for a security questionnaire, or to reach our security team, please contact info@invenzolabs.com. Our Grievance Officer, Ms. Jyothsna Iyengar, is the addressee for privacy and data-protection matters.
This page will be updated as our practices evolve — check back periodically, or write to us if you would like to be notified of material changes.
Questions?
Write to our Grievance Officer, Ms. Jyothsna Iyengar, at info@invenzolabs.com. We respond within seven working days.