InventDB
The InventDB blog

How InventDB works.

Technical articles from the team that builds InventDB: the database engine, its security model, and the business engine that runs on top of it.

Subscribe with the Atom feed
Architecture

Inside InventDB: one engine from the disk to the AI

The layers of one InventDB instance, from the encrypted storage engine to the business engine, and the path one request takes through them.

Storage

How a single instance holds 250 million records

Every InventDB table is a list of 100,000-record segments. One segment takes the writes, the others are sealed, and reads skip the segments that cannot match.

Storage

Concurrent B-link trees and one shared page cache

Readers walk InventDB's B-link trees without latches, a writer latches only the leaf it changes, and one page cache shared by every tree holds the live pages.

Query engine

How a SQL query runs in InventDB

One SELECT followed through InventDB's parser, rule-based planner and four execution paths, and how much each path reads.

Query engine

Columnar aggregates inside a JSON document database

InventDB keeps records as JSON but answers aggregates from totals in its indexes and from dense, encrypted column files built for every sealed segment.

Query engine

Reading less: zone maps, Bloom filters and the ORDER BY LIMIT walk

Bloom filters, zone maps and a k-way merge over sorted indexes let InventDB skip segments that cannot match and stop a top-N query after N rows.

Transactions

Transactions and commits that survive a crash

How an InventDB commit becomes all-or-nothing, conflict-checked and durable, and exactly which anomalies it prevents.

Reliability

What happens to your data when the power goes out

The first start after a crash, step by step: how InventDB detects it, replays committed writes and repairs only what a crash can damage.

Reliability

Hot backups and recovery while writes continue

InventDB backs up a live instance file by file to object storage in the same region, proves each backup complete, and checks it again before a restore.

Security

Encryption at rest that cannot be switched off

Every InventDB instance encrypts records, indexes, files and its log with AES-256-GCM, and the engine has no mode that stores data in plaintext.

Security

Sign-in, roles and grants for people, apps and agents

An InventDB instance is its own authorization server: password sign-in for people, OAuth 2.1 with PKCE for AI agents, and one grant check for every caller.

Security

Row-level security inside the database engine

The InventDB engine applies each person's row rules to every SQL query and every write, whichever interface the request came through.

Search

Four kinds of search, from exact match to meaning

Exact, fuzzy, full-text and semantic search run inside the InventDB engine, over the same records and under the same permissions.

Search

Embeddings computed inside the database, in pure Rust

A MiniLM sentence model written out by hand in Rust runs inside the InventDB engine, with caches and HNSW graphs that make its vectors searchable.

Search

Files on every record, read by OCR and searchable by meaning

InventDB stores files with the records they belong to, reads them with local OCR, and searches inside them by words and by meaning under each person's access rules.

API

One HTTP API: REST, SQL and a live OpenAPI spec

Every InventDB instance answers HTTP itself: records over REST, reads as SQL, bulk writes, transactions, and an OpenAPI 3.1 spec it serves about itself.

API

Importing CSV, JSON and spreadsheets into a live database

One parser infers column types, a preview shows what will be stored, and permissions, row rules and foreign keys are checked as records go in.

API

Webhooks and a change feed from the database itself

InventDB records every committed write where all writes pass, then serves the changes as a cursor feed and as signed webhooks that carry no record data.

AI

An MCP server inside the database, signed in with OAuth

An AI client signs in to InventDB as a person, works through 51 typed tools under that person's grants, and stages record changes until a commit.

AI

How the InventDB SOAR AI answers with SQL you can check

The InventDB SOAR agent answers questions by writing SQL, running it as you under your row rules, and showing the query beside the answer.

AI

Safe AI changes: change sets, approval and an audit log

A multi-step AI change in InventDB applies as one transaction after a person approves it; MCP proposals wait for a commit that the audit log records.

AI

The AI gateway between your instance and the model

Every AI call from InventDB SOAR passes one gateway that checks the account, enforces the monthly AI allowance, routes to Claude on Amazon Bedrock and meters tokens.

Business engine

Event-driven workflows with a person in the loop

A workflow in InventDB SOAR is a fixed plan of typed steps that a trigger starts, that acts on your records, and that parks until a person decides.

Business engine

Reports and views with SQL behind every figure

An InventDB SOAR report stores no numbers: its HTML template runs SQL under the reader's row rules every time it renders, on screen, on paper or in an email.

Operations

Idle instances that sleep, and the energy we measure

An idle InventDB instance stops, keeps every byte of its storage and wakes on the next request. Here is the order of events and how we measure the energy.