SECURITY OVERVIEW
Security you can inspect, control by control
Your production rates, costs, drawings and customer terms are the most sensitive information in your factory. We keep a written control register mapped to the standards your auditors and customers already recognise — and we publish the status of every control, including the ones still in progress.
Last updated: 4 September 2026
Where we stand today
Our register holds 44 controls. Today 37 are live and 7 are in progress, with the remainder scheduled for completion. We map controls to ISO/IEC 27001:2022, ISO/IEC 27701, the SOC 2 Trust Services Criteria, OWASP ASVS 4.0, the OWASP API and LLM Top 10, NIST SSDF, the NIST AI Risk Management Framework, India's Digital Personal Data Protection Act 2023 and the CERT-In 2022 directions.
We describe these as mappings and self-assessments. We do not claim any certification we have not completed. Where an independent audit is required for your own customers, we will support it and share our register and evidence.
Control register by area
Company isolation
5/5 live
Every record carries the owning company and is filtered by the database on each read and write.
Permissions and approvals
5/5 live
Roles, department scope and approval limits per document type; privilege never stored on the user profile.
Sign-in
4/6 live
Passwordless invites, session limits and password rules. Two-factor for admins and device trust are in progress.
Encryption
3/4 live
TLS in transit, encryption at rest for data and backups, secrets held outside the application. Customer-managed keys in progress.
Audit trail
3/4 live
Immutable log of who did what and when, exportable. Extended log retention in progress.
Administrator access
2/2 live
Support access is time-bound, purpose-logged and visible to you as an on-screen banner while active.
Interface and API security
4/4 live
Input validation on every write, rate limits, signature checks on external callbacks, no public write paths.
Privacy and retention
3/4 live
Purpose limits, retention schedules per data category, deletion and export on request. Formal grievance workflow in progress.
AI governance
4/4 live
Answers are grounded in your own data with sources shown, actions require human approval, prompts and data are never used to train models.
Resilience and recovery
2/4 live
Daily backups with point-in-time recovery and incident response. Documented restore drills and multi-region failover in progress.
File storage
2/2 live
Attachments and drawings are private by default and served only through short-lived, permission-checked links.
Your data stays in your hands
- One factory can never see another. Isolation is enforced by database policies, not by application code that a bug could bypass.
- Your accounting machine is never opened to the internet. The Tally connector runs on your own computer and reaches outward only.
- Data is hosted in managed cloud infrastructure with encryption at rest; you may request India-region hosting.
- You can export your entire data set at any time, in open formats, without asking us for permission.
- On termination we delete or return your data on your instruction, within the agreed period.
How the AI layer is kept safe
- The assistant answers from your own transactions and your own documents. It does not answer from the open internet.
- Every answer carries the figures and source records behind it, so you can check it.
- It cannot create, change or approve anything on its own — it prepares a draft and a named person approves it.
- Your data and questions are not used to train any model, ours or a vendor's.
- Every question, answer and action is recorded with the user, time and data touched.
Reporting a problem
If you believe you have found a vulnerability, write to security@navodyx.com. We acknowledge reports within two working days and will keep you informed until it is resolved. Please do not test against another customer's data.