Back to home

Navodyx IP

Manufacturing Operations OS

SECURITY OVERVIEW

Security you can inspect, control by control

Your production rates, costs, drawings and customer terms are the most sensitive information in your factory. We keep a written control register mapped to the standards your auditors and customers already recognise — and we publish the status of every control, including the ones still in progress.

Last updated: 4 September 2026

Where we stand today

Our register holds 44 controls. Today 37 are live and 7 are in progress, with the remainder scheduled for completion. We map controls to ISO/IEC 27001:2022, ISO/IEC 27701, the SOC 2 Trust Services Criteria, OWASP ASVS 4.0, the OWASP API and LLM Top 10, NIST SSDF, the NIST AI Risk Management Framework, India's Digital Personal Data Protection Act 2023 and the CERT-In 2022 directions.

We describe these as mappings and self-assessments. We do not claim any certification we have not completed. Where an independent audit is required for your own customers, we will support it and share our register and evidence.

Control register by area

Company isolation

5/5 live

Every record carries the owning company and is filtered by the database on each read and write.

Permissions and approvals

5/5 live

Roles, department scope and approval limits per document type; privilege never stored on the user profile.

Sign-in

4/6 live

Passwordless invites, session limits and password rules. Two-factor for admins and device trust are in progress.

Encryption

3/4 live

TLS in transit, encryption at rest for data and backups, secrets held outside the application. Customer-managed keys in progress.

Audit trail

3/4 live

Immutable log of who did what and when, exportable. Extended log retention in progress.

Administrator access

2/2 live

Support access is time-bound, purpose-logged and visible to you as an on-screen banner while active.

Interface and API security

4/4 live

Input validation on every write, rate limits, signature checks on external callbacks, no public write paths.

Privacy and retention

3/4 live

Purpose limits, retention schedules per data category, deletion and export on request. Formal grievance workflow in progress.

AI governance

4/4 live

Answers are grounded in your own data with sources shown, actions require human approval, prompts and data are never used to train models.

Resilience and recovery

2/4 live

Daily backups with point-in-time recovery and incident response. Documented restore drills and multi-region failover in progress.

File storage

2/2 live

Attachments and drawings are private by default and served only through short-lived, permission-checked links.

Your data stays in your hands

  • One factory can never see another. Isolation is enforced by database policies, not by application code that a bug could bypass.
  • Your accounting machine is never opened to the internet. The Tally connector runs on your own computer and reaches outward only.
  • Data is hosted in managed cloud infrastructure with encryption at rest; you may request India-region hosting.
  • You can export your entire data set at any time, in open formats, without asking us for permission.
  • On termination we delete or return your data on your instruction, within the agreed period.

How the AI layer is kept safe

  • The assistant answers from your own transactions and your own documents. It does not answer from the open internet.
  • Every answer carries the figures and source records behind it, so you can check it.
  • It cannot create, change or approve anything on its own — it prepares a draft and a named person approves it.
  • Your data and questions are not used to train any model, ours or a vendor's.
  • Every question, answer and action is recorded with the user, time and data touched.

Reporting a problem

If you believe you have found a vulnerability, write to security@navodyx.com. We acknowledge reports within two working days and will keep you informed until it is resolved. Please do not test against another customer's data.