Inaya is building a business software layer that makes decentralized infrastructure simple and invisible to Web2 users.
The underlying DePIN infrastructure remains the foundation. The SaaS layer on top is what businesses actually see and use.
Architecture
A secure workspace where businesses can organize teams, projects and documents while using Inaya's privacy-first storage infrastructure underneath.
Transform business documents from simple stored files into controlled business records with approval workflows and traceable history.
Give businesses granular control over who can access, edit, manage and share business information.
Ask questions about your business workspace using natural language. The AI operates only on information the authenticated user is already authorized to access.
AI permissions never exceed the user's permissions.
Implemented AI tools
list_documentslist_departmentslist_projectslist_taskslist_contactslist_dealslist_supplierslist_purchase_orderslist_purchase_requestslist_productslist_invoiceslist_expenseslist_employeeslist_leave_requestsfind_employee_documentget_activityget_document_accessget_business_insightsget_business_briefLive today in both the web and mobile Business Workspace, powered by the exact same permission-scoped tools on the backend. Read-only here — for the AI's ability to propose real changes (never execute them directly), see Stage 9.
The Business Workspace as a real installed application — its own icon, tray presence, native notifications and auto-updates, not just a browser tab.
Same Business Workspace, same permissions and encryption, running in its own window instead of a browser tab. macOS is not available yet.
Manage projects, tasks, customers, purchasing, and inventory from the same secure workspace as your documents.
Projects & Tasks
CRM
Procurement
Inventory
All four modules are real and shipped: task status workflows, a unified Lead/Customer CRM with a sales pipeline, purchase requests/orders with a real approval chain, and inventory with real stock movements — including purchase orders that actually move inventory when received. Every record is department-scoped and queryable by the AI assistant. See BUSINESS_OPERATIONS_TASKS.md, _CRM.md, _PROCUREMENT.md, and _INVENTORY.md for what's covered and what's explicitly not yet (e.g. warehouse-to-warehouse transfer UI, PO line-item editing after creation).
Secure financial and people-management capabilities built directly into the Business Workspace.
Finance
HR
Both modules are real and shipped: invoices with a cron-driven overdue status, expense approval workflows, payment recording/approval, and CSV financial reporting; employee lifecycle management, computed leave balances, leave approval, and Department Manager assignment. A testnet demonstration/validation layer, not regulated banking, tax filing, or payroll processing — every Finance/HR screen carries a visible "Testnet / Beta" badge. See BUSINESS_OPERATIONS_FINANCE.md and _HR.md for what's covered and what's explicitly not yet (e.g. no PDF invoice generation, no multi-currency conversion).
Inaya Business Insights & KPI Dashboard — business activity turned into live dashboards and AI-generated insight.
Real and shipped: KPI cards, period-over-period comparison, trend charts, and business alerts all compute from the same permission-scoped data every other Business Workspace module already reads — no separate, weaker-scoped path. The AI Business Assistant answers KPI/trend/alert questions directly via a dedicated get_business_insights tool. The Business Brief (new 2026-09-01) is a periodic recap on the same real data — deterministic highlight bullets plus a best-effort AI narrative paragraph on top, available as its own Workspace view and conversationally via get_business_brief. See BUSINESS_OPERATIONS_INSIGHTS.md for what's covered and what's explicitly not yet (no custom date-range picker, no trend charts on mobile yet).
The AI Business Assistant can propose real changes across 9 business domains — it never executes anything itself. A human with the exact same real authority the underlying action would require must approve; the server independently re-validates that authority; a mandatory 36-hour delay passes; only then does the change execute — and every step is recorded in a tamper-evident, cryptographically verifiable audit trail.
AI recommends. Humans authorize. The server validates. The system executes. The audit trail remembers.
Real and shipped across 9 domains, covered by 19 automated tests including 11 adversarial security scenarios (forged approval, cross-tenant access, replay, expired-proposal execution, prompt injection, and more — all fail safely). Explicitly not yet covered: AI-driven record creation (a new task/contact/etc.), task reassignment, transaction categorization, and drafting/sending customer communications — none of these exist anywhere in the app yet, gated or not, so there's nothing yet to guard. See docs/ai-controlled-actions.md for the full phase-by-phase breakdown.
Two vertical specializations of the Business Workspace — Health OS and Legal OS — for organizations handling patient or client/matter data, picked at company signup or changed later in Settings.
Patient and matter visibility is assignment-based, not department-based — being in the right department is never enough on its own.
Every domain module for both verticals now has a real, working screen in Business Workspace — not just Patients and Matters — live-verified end-to-end against the running app, including the trust ledger's server-side overdraft rejection. Mobile now has real screens for both verticals too (Health OS, Legal OS, and their patient/matter detail screens), built against the exact same vertical-locked API routes as web; these are written and syntax-verified but not yet exercised on a live device/simulator, which is the one thing still holding this at IN_PROGRESS rather than LIVE. FHIR/HL7/e-filing/e-signature/SSO and every other third-party integration are documented adapter interfaces with an honest not-configured stub, not live integrations. No HIPAA/ABA/eDiscovery compliance certification exists or is claimed.
A third and fourth vertical specialization of the Business Workspace — Financial Services OS (hedge funds/asset managers), Private Capital OS (PE/VC), and Regulated Enterprise OS (cross-industry compliance for banks, insurers, pharma, and other regulated organizations) — sharing one platform core with Health OS and Legal OS. All ten phases of the SOW are now built.
A framework or control mapping is never presented as a compliance certification — and a control with no test on file shows as "unknown," never as passing.
Live-verified end-to-end against the running app across every phase: control creation and activation, a failing test auto-opening a finding and walking its full state machine to closed, the dashboard's unknown/failing/passing distinction, the full policy lifecycle including the immutability guard and amend-creates-a-new-version behavior, an examiner magic-link's issue/exchange/one-time-use cycle, entity-scoped fund/deal visibility, and the board-report/export-package immutability guards. Not yet built: mobile screens for these verticals (Financial Services OS/Private Capital OS/Regulated Enterprise OS have zero mobile presence today — web only), and real third-party integrations (every adapter is a documented, honest not-configured stub). No compliance certification of any kind exists or is claimed.
A fifth vertical specialization of the Business Workspace, for government departments and agencies handling citizen, legal, financial, procurement, health, and operational data — sharing the same platform core as every other vertical above.
Citizen-record visibility is assignment-based, not department-based — being in the right department, or even holding staff-level government access, is never enough on its own to see a specific person's record.
Live-verified: the Government OS vertical option renders correctly in the org-creation flow, and every new API route is statically confirmed to lock to the government vertical. 51 new automated tests cover the two load-bearing properties (citizen-record access requires an actual assignment; a published policy knowledge base entry can never be mutated in place) plus case-workflow transition legality, dashboard honesty (unknown is never shown as passing), and AI tool need-to-know enforcement. Not yet built: mobile screens (Government OS has zero mobile presence today, same gap as Financial/Private Capital/Regulated Enterprise OS), a real pilot-agency onboarding, and any government-specific procurement rule beyond an explicitly informational, non-binding competitive-bid threshold flag. No government certification, accreditation, FedRAMP authorization, or jurisdiction-specific compliance claim exists or is claimed — that requires separate authorities entirely outside this codebase.
Inaya's long-term goal is to make decentralized infrastructure invisible to everyday business users.
Businesses should experience a familiar SaaS platform for documents, projects, teams, workflows, operations and business intelligence.
Underneath that experience, Inaya provides privacy-focused decentralized infrastructure, encrypted storage and verifiable data integrity.
Make decentralized infrastructure as easy to use as traditional cloud software.