Privacy Policy
Effective Date: August 2026 • Version 2.0 • Navira Security
1. Core Privacy & AI Stewardship Commitment
Navira Security operates under the principle that client data must be protected as if it were part of our own digital waters. We provide specialist professional AI security services and do not license, sell, or commercialize customer data.
2. Strict Zero External AI Ingestion Policy
Under our non-negotiable Security Baseline, client source code, configuration files, system prompts, API keys, and test payloads are strictly prohibited from being submitted to, stored by, or processed through public consumer AI models (e.g., ChatGPT, Claude web, or third-party unverified cloud tools). All analysis is conducted in isolated, client-specific encrypted environments.
3. Information Collected
We collect and process only the minimum information necessary to execute security assessments:
- Contact Information: Name, work email address, company name, and role provided during intake or scoping.
- Assessment Telemetry: Technical architecture details, endpoint URLs, and authorization tokens provided under a signed Mutual Non-Disclosure Agreement (NDA).
- Website Interaction: Technical logs (IP address, browser user-agent) necessary to secure and operate our website. We do not use third-party behavioral advertising trackers.
4. Cryptographic Isolation & Data Deletion
All engagement findings, exploit reproduction scripts, and client configuration data are encrypted in transit (TLS 1.3) and at rest (AES-256-GCM). Client-specific cryptographic keys are rotated regularly, and all testing artifacts and staging credentials are cryptographically shredded within 60 days following the completion of the verification retest window.
5. Global Privacy Rights (GDPR / LGPD)
Regardless of your geography, you have the right to request access to, correction of, or permanent deletion of your contact data. For inquiries, contact our Data Protection Officer at [email protected].