Security
Trust is a design constraint,
not a page.
Operating constraints
Four commitments the architecture enforces.
Read-only, granted by your administrator
NavisLabs connects through OAuth scopes your administrator explicitly grants, and which can be revoked at any time. It reads; it does not write to your systems or act on your accounts.
A person approves anything that acts
NavisLabs prepares, drafts and recommends. Nothing leaves the system without human approval. There is no autonomous mode to turn on.
Every conclusion shows its work
Each item traces to the specific signals that produced it — which thread, which meeting, which document. If NavisLabs cannot show why, it does not surface the claim.
Your data stays yours
Your organization's data is never used to train shared or foundation models. Every recommendation and approved action writes to an audit log you can export.
Deployment
What your security team will ask.
- Access model
- Least-privilege OAuth. No endpoint agents, no browser extensions, no inbox rules.
- Data in transit
- TLS 1.2+ on every connection to your identity provider and source systems.
- Revocation
- Scopes are revocable from your admin console at any time; ingestion stops immediately.
- Audit
- Every surfaced conclusion and approved action is logged with its source signals.
- Retention
- Configurable per deployment, including full deletion on request.
Honest posture
What we do not claim.
NavisLabs is early. We do not claim certifications we do not hold, logos we have not earned, or correctness that no probabilistic system can guarantee. What we do claim: least privilege, your approval on anything that acts, isolation of your data, and a traceable path behind every conclusion. If your security review needs something specific, ask us directly and we will answer plainly.
Security questions are answered by an engineer, not a form.