Security & governance
Security & data governance
NavHub is built on a simple principle — AI comes to your data. Your data never goes to public AI.
Your intellectual property stays yours
The conventional AI risk: employees paste financial data, client information and strategic plans into public chat tools. Data leaves the organisation. No audit trail. No governance.
NavHub is different. Everything runs inside your workspace.
- Financial data stays in NavHub’s database — only structured query results are passed to AI, never raw data dumps
- Documents are only accessible to agents with explicit permission
- Outputs default to Draft — human review required before publishing
- Nothing leaves your workspace unless a human explicitly exports it
Data handling at a glance
| What we protect | How |
|---|---|
| Financial data | Stays in database — AI receives only query results |
| Documents | Folder-level access control per agent |
| AI outputs | Draft by default — human publishes |
| API keys | AES-256-GCM encrypted at rest |
| Conversation history | Per-user isolation, never shared |
| Auth tokens | Encrypted, time-limited signed URLs |
Anthropic API — not the consumer product
NavHub uses the Anthropic API, not Claude.ai. Under Anthropic's API terms:
- ✓Your data is not used to train AI models
- ✓Data is not retained after each API call
- ✓No persistent memory of your organisation between sessions
Use your approved AI provider
NavHub supports any AI provider — Anthropic, OpenAI, Google, Mistral or custom endpoints. Bring your own API key and use models already approved under your organisation's AI policy.
Built for enterprise compliance
- Role-based access control (Admin, Manager, Viewer)
- Feature-level permissions per user per company
- Full audit log — every agent action logged with user, timestamp, data accessed
- Support access is read-only — writes blocked during impersonation
- Row-level security enforced at database layer, not just application layer
Want a deeper review?
We're happy to walk your IT and compliance teams through the full architecture.