Navaa← All legal documents
Navaa legal

Security

Last updated: October 7, 2026

Navaa holds your team's work. Here is exactly how we protect it.

No passwords

There is no password to steal, phish or reuse. You sign in with a six-digit code sent to your email, a single-use link, or your Google account. Codes expire after 10 minutes and are cancelled after five wrong attempts. Links are single use and expire after 24 hours. We rate-limit code requests and verification by IP address to block guessing attacks.

Sessions you control

Access tokens last 15 minutes. Refresh tokens last 7 days and are replaced every time they are used. Both live in HTTP-only cookies that page scripts cannot read. You can see every device signed in to your account and revoke any of them instantly.

Separation between workspaces

Your workspace is resolved on our server from your authenticated session, never from anything your browser sends. Permissions are enforced server-side, not hidden in the interface. One workspace cannot reach another's data.

Verified integrations

Every WhatsApp message is checked against Meta's cryptographic signature before we act on it. Every Razorpay payment notification is verified by signature before we change your subscription. A phone number is trusted only after code verification, and belongs to one account.

Payments we never see

Card details are entered directly into Razorpay Checkout. Full card numbers, CVV and UPI PINs never reach our servers. Razorpay is PCI DSS compliant.

Data handling

Encrypted in transit with TLS, and encrypted at rest by our database provider. All input validated. Uploaded screenshots checked by actual file content and size, stored privately, and accessible to our team only through links that expire after one hour. Text escaped before insertion into emails. API keys and database credentials never leave our servers. Security headers on every response; cross-origin requests rejected.

Backups

[BACKUP FREQUENCY, RETENTION AND RESTORE TESTING]

Internal access

Our admin console has its own separate authentication, a hashed credential and eight-hour sessions. Access is limited to authorised team members, used only to operate Navaa and support you, and logged. Access and security logs are retained for 12 months.

No tracking

Navaa runs no analytics, advertising or tracking scripts. We set only the cookies required to sign you in. We do not use localStorage or sessionStorage. We do not sell data, and we do not share it for advertising.

Where your data lives

Our database is in Tokyo, Japan. A full list of providers and their locations is at navaa.app/subprocessors.

Reporting a vulnerability

Email security@navaa.app. We acknowledge reports within 2 business days and will keep you updated. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosure.

If something goes wrong

No system is completely secure. If a breach affects your data we will tell you without undue delay, report it to the Data Protection Board of India within 72 hours, and notify the relevant EU or UK supervisory authority within 72 hours where that applies.

← All legal documentsContact →
© 2026 Navaa · Stencil Design Private Limitedhello@navaa.app