Security at INVITE Networks

INVITE Networks manages IT and AI infrastructure for businesses that depend on it every day. This page summarizes how we protect the information in our own systems; the full description is in our Privacy Policy.

Our Security Program

We maintain an information security program aligned with SOC 2 requirements. It covers the people, systems, and vendors that handle customer and company information within INVITE’s own systems.

Data Protection

  • Confidential data is encrypted at rest and in transit, in accordance with our Cryptography Policy.
  • Personal information is retained only as long as reasonably necessary to deliver services and meet contractual and legal obligations.
  • When information is no longer needed, we securely delete or de-identify it in accordance with our Data Management Policy.

Access Control

Access to systems and data is restricted on a least-privilege, role-based basis, with periodic access reviews. Multi-factor authentication is required for remote and privileged access to production systems.

Monitoring and Testing

  • Ongoing security monitoring
  • Vulnerability scanning
  • Periodic independent penetration testing

Incident Response

We follow a documented incident response process for identifying, containing, and communicating about security incidents. If an incident affects your personal information, we notify affected individuals and any applicable regulators in accordance with our Incident Response Plan and applicable law.

People and Vendors

  • Employee background checks, where legally permitted
  • Confidentiality agreements
  • Annual security awareness training
  • Vendors and subprocessors that perform services on our behalf work under agreements that require them to protect the information they handle

Responsible Disclosure

If you believe you have found a security vulnerability in an INVITE system or service, email security@invitenetworks.com with enough detail for us to reproduce the issue. We will review your report and follow up with you while we investigate. Do not access, modify, or retain data that is not yours, and give us reasonable time to address the issue before disclosing it publicly.

Questions

Questions about security at INVITE? Contact security@invitenetworks.com.