Where your files, rates and quotes are kept, and who can see them
VenturusEQ holds your RFQ packages, quotes, rates and price lists in Azure East US 2, in PostgreSQL 16 and blob storage. It is delivered as SaaS, and an on-premises option runs the same product in your own Azure tenant or on your own hardware. Controlled files never reach the cloud blob tier. Every read is fenced to your company, every controlled open is written to a ledger nobody can edit, and your data comes back in open formats on request.
What VenturusEQ holds for you
Your work
RFQ package files with their hashes, roles, lineage and scan state. Quotes, revisions, acceptances and outcomes. Your rates, material price lists, templates and lookup tables, entered by you, because the product ships none.
The audit records
An audit log of before-and-after values that never stores a password, a secret or a file's bytes. The controlled-access ledger. Buyer engagement as salted hashes. Users, roles and their switches.
Where it is stored
Azure East US 2
Records in PostgreSQL 16. Ordinary files in blob storage. One region, and backups stay in that region today.
Storage tiers
A file is routed by its classification: cloud blob for ordinary files, a local vault or an in-boundary volume for controlled files, a separate tier for anonymous uploads. Controlled bytes never reach cloud blob.
The on-premises option
Delivered as SaaS; the on-premises option runs the same product, one container plus PostgreSQL, in your own Azure tenant or on your own hardware. Blob storage and telemetry are optional, and mail goes through Microsoft 365.
Who can see what
The company fence
Each deployment serves one company by default, and every read is also fenced to your company and site in the application layer.
Roles and switches
Four roles, an estimating write tier, and three switches per person: finalize quotes, download files, controlled data. Changes are audited and take effect on the next request.
Two-factor and sessions
An authenticator app with ten one-time recovery codes, requirable per role and enforced on every request. Sessions are revalidated on every request; a password, role or two-factor change ends them all. Passwords are hashed with Argon2id.
Controlled-data classes
A class on every file and every package, from none up to export-controlled. A class only ratchets up, and a controlled package never gets a public quote link.
The controlled-access ledger
Every controlled open is written to a hash-chained ledger before any byte is served, with a US-person attestation on record. Verify it in one pass, export it as CSV, get alerts on refusals and bursts, and review who can see what.
Watermarks
Every page of a controlled PDF carries the person, the UTC instant and the file's SHA-256. If a file cannot be stamped, it is not served.
How files are handled
Files are hashed, scanned where a scanner is deployed, and never deleted
Every file is hashed with SHA-256 on arrival. Where a scanner is deployed for your instance a file is held until it is clean, a flagged file is refused everywhere, and an unscanned file says so. A file uploaded by mistake is withdrawn with a reason and can be restored; nothing is deleted from the record.
The one step that leaves the product
The PDF drawing sheet goes to Anthropic, a named subprocessor, for the drawing read. Where the export-control boundary is switched on for your deployment, a controlled file is refused before it leaves, and so is text derived from one. Geometry is measured inside the container. Customer data is not used for training.
Your data comes back in open formats
Ask, and your data is returned in open formats and deleted from our systems.
A ledger nobody can edit
Each entry in the controlled-access ledger carries the hash of the entry before it, so the chain is only valid while every link is untouched. Change or remove one entry and every hash after it stops matching, which the verify step shows in one pass.
Controlled access ledger · example company
Edit any cell. The row's hash changes, so the next row's stored "previous hash" no longer matches, and the verify pass stops at the first bad row.
| # | When (UTC, µs) | Who | Action | File · SHA-256 | Outcome | Prev hash | Row hash |
|---|---|---|---|---|---|---|---|
| 1 | 2026-09-17 13:02:11.483201 | BR-2210-C.pdf · 9f3a…c1e2 | 0000…0000 | … | |||
| 2 | 2026-09-17 13:02:40.017774 | BR-2210-C.pdf · 9f3a…c1e2 | … | … | |||
| 3 | 2026-09-17 13:05:02.902316 | HS-118.step · 41b7…88d0 | … | … | |||
| 4 | 2026-09-17 13:09:57.115880 | HS-118.step · 41b7…88d0 | … | … | |||
| 5 | 2026-09-17 13:11:19.640022 | BR-2210-C.pdf · 9f3a…c1e2 | … | … |
In the product the rows are appended under a database lock, a refused open is written too, and an administrator can verify and export the whole chain from the Controlled access page.
Common questions
Where is my data stored, and can it stay in-house?
As SaaS, in Azure East US 2: records in PostgreSQL 16, ordinary files in blob storage. Files classed as controlled are routed to a local vault or an in-boundary volume and never reach cloud blob storage. The on-premises option runs the same product, one container plus PostgreSQL, in your own Azure tenant or on your own hardware; blob storage and telemetry are optional, and mail goes through Microsoft 365.
Who in my company can open an export-controlled file?
Only a person with the controlled-data switch on their account, granted by an administrator and audited. Each open is written to a hash-chained ledger before any byte is served, with a US-person attestation on record, and every page of a controlled PDF is watermarked with the person, the instant and the file hash. Refusals and bursts raise alerts.
Is my data used to train AI?
No. Customer data is not used to train models. The one AI step, reading a PDF drawing sheet, goes to Anthropic as a named subprocessor, and where the export-control boundary is switched on for your deployment a controlled file is refused before it leaves. Geometry never leaves the container.
Can I get my data out if we leave?
Yes. Your data is returned in open formats on request and deleted on request. Day to day, the quote log exports to CSV or XLSX and signed webhooks carry events out as they happen. There is no self-serve "export everything" button yet; you ask, and it is done.
See it on one of your own RFQs
Send us a drawing and a model you have already quoted and we will walk through it with you in the product, in your rates. If you would rather look first, the interactive demo is open, with no form in front of it.