Security

Built for legal confidentiality

Client privilege, legal professional privilege, and confidentiality are cornerstones of legal practice. Navionra is engineered from the ground up to protect the most sensitive professional data there is.

AES-256

Encryption at rest

TLS 1.2+

Encryption in transit

99.5%

Uptime target

72 hrs

Breach notification SLA

Security in depth

Encryption everywhere

  • TLS 1.2+ for all data in transit — no unencrypted connections accepted.
  • AES-256 encryption at rest for all documents, database backups, and blob storage.
  • Database passwords and API keys stored as hashed secrets, never in plaintext.

Access control

  • Role-based access control (RBAC): Admin, Lawyer, Paralegal, Client Portal roles.
  • Multi-factor authentication (TOTP) available for all accounts.
  • Per-matter permissions — restrict who can view or edit sensitive cases.
  • SSO via Azure AD / Google Workspace (Professional+).
  • Sessions expire after 30 minutes of inactivity (maximum 8-hour session).

Audit trail

  • Every user action — document access, downloads, edits, exports — is logged.
  • Logs include user ID, IP address, timestamp, and action type.
  • Immutable audit logs retained for 2 years.
  • Export audit logs to CSV for external review or regulator submission.

Data residency

  • UK firms: documents and AI processing are hosted in the UK on Microsoft Azure (UK South).
  • Your data is not transferred outside the UK.
  • Your clients see your brand: add your logo and colours to the client portal and client emails — standard on every plan.
  • Enterprise: dedicated storage account in a specified region, plus full white-label on your own domain.
  • We never use your data to train AI models.

AI data protection

  • We never use your client documents to train AI models.
  • Anthropic API is operated under a zero-data-retention policy — inputs are not stored by Anthropic.
  • AI features can be disabled per-organisation if required by your firm's data policies.
  • All AI-generated outputs are logged and attributable to specific user actions.

Vulnerability management

  • Annual third-party penetration tests — reports available to Enterprise customers on request.
  • Automated dependency scanning (GitHub Dependabot) with immediate patching for critical CVEs.
  • Responsible disclosure — report vulnerabilities to security@navionra.com and we will acknowledge and investigate.
  • Security patches applied within 24 hours for critical severity.

Compliance & certifications

Designed for UK-regulated law firms with the regulatory obligations that come with it.

UK GDPR

Full compliance with UK GDPR and the Data Protection Act 2018. DPA available for all plans.

SRA

Designed for UK law firms regulated by the SRA. Audit trails support compliance with SRA record-keeping requirements.

ISO 27001

We follow ISO 27001 principles. Formal certification in progress.

Cyber Essentials

Cyber Essentials certified (UK government-backed scheme).

SOC 2 Type II

Enterprise customers may request our SOC 2 Type II audit report. In progress for 2026.

Legal Hold

Built-in legal hold capability preserves documents from deletion for litigation and regulatory requirements.

Responsible disclosure

Found a security vulnerability? We want to know. Email security@navionra.com with a description of the issue, steps to reproduce, and your contact details. We will acknowledge within 24 hours and aim to patch within 5 business days. We do not take legal action against researchers who report vulnerabilities in good faith.