Built for legal confidentiality
Client privilege, legal professional privilege, and confidentiality are cornerstones of legal practice. Navionra is engineered from the ground up to protect the most sensitive professional data there is.
AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
99.5%
Uptime target
72 hrs
Breach notification SLA
Security in depth
Encryption everywhere
- TLS 1.2+ for all data in transit — no unencrypted connections accepted.
- AES-256 encryption at rest for all documents, database backups, and blob storage.
- Database passwords and API keys stored as hashed secrets, never in plaintext.
Access control
- Role-based access control (RBAC): Admin, Lawyer, Paralegal, Client Portal roles.
- Multi-factor authentication (TOTP) available for all accounts.
- Per-matter permissions — restrict who can view or edit sensitive cases.
- SSO via Azure AD / Google Workspace (Professional+).
- Sessions expire after 30 minutes of inactivity (maximum 8-hour session).
Audit trail
- Every user action — document access, downloads, edits, exports — is logged.
- Logs include user ID, IP address, timestamp, and action type.
- Immutable audit logs retained for 2 years.
- Export audit logs to CSV for external review or regulator submission.
Data residency
- UK firms: documents and AI processing are hosted in the UK on Microsoft Azure (UK South).
- Your data is not transferred outside the UK.
- Your clients see your brand: add your logo and colours to the client portal and client emails — standard on every plan.
- Enterprise: dedicated storage account in a specified region, plus full white-label on your own domain.
- We never use your data to train AI models.
AI data protection
- We never use your client documents to train AI models.
- Anthropic API is operated under a zero-data-retention policy — inputs are not stored by Anthropic.
- AI features can be disabled per-organisation if required by your firm's data policies.
- All AI-generated outputs are logged and attributable to specific user actions.
Vulnerability management
- Annual third-party penetration tests — reports available to Enterprise customers on request.
- Automated dependency scanning (GitHub Dependabot) with immediate patching for critical CVEs.
- Responsible disclosure — report vulnerabilities to security@navionra.com and we will acknowledge and investigate.
- Security patches applied within 24 hours for critical severity.
Compliance & certifications
Designed for UK-regulated law firms with the regulatory obligations that come with it.
UK GDPR
Full compliance with UK GDPR and the Data Protection Act 2018. DPA available for all plans.
SRA
Designed for UK law firms regulated by the SRA. Audit trails support compliance with SRA record-keeping requirements.
ISO 27001
We follow ISO 27001 principles. Formal certification in progress.
Cyber Essentials
Cyber Essentials certified (UK government-backed scheme).
SOC 2 Type II
Enterprise customers may request our SOC 2 Type II audit report. In progress for 2026.
Legal Hold
Built-in legal hold capability preserves documents from deletion for litigation and regulatory requirements.
Responsible disclosure
Found a security vulnerability? We want to know. Email security@navionra.com with a description of the issue, steps to reproduce, and your contact details. We will acknowledge within 24 hours and aim to patch within 5 business days. We do not take legal action against researchers who report vulnerabilities in good faith.