Cloud SaaS
Fully managed. First report in an afternoon.
Navigara operates every component and processes your data under a data processing agreement.
Quickstart →Three deployment models: fully managed cloud, a collector inside your network, or fully on-premises and air-gapped. Pick the one that matches your security policy.
SOC 2 Type IIGDPRAnnual penetration testDPA on request
Run by banks, a cybersecurity vendor, and regulated fintechs




Fully managed. First report in an afternoon.
Navigara operates every component and processes your data under a data processing agreement.
Quickstart →Analysis inside your perimeter, dashboard in the cloud.
The collector clones and analyzes locally, and holds one outbound stream. Source code never crosses.
On-prem collector →Complete data sovereignty, air-gap included.
Every component runs on your side. The licence is verified offline and there is no telemetry.
Full on-premises →| Destination | Component | Purpose |
|---|---|---|
| Your Git host | Collector | Cloning and pull request data |
| Your LLM endpoint | Collector, backend | Commit analysis and summaries |
| Your issue tracker | Collector | Alignment scoring |
| Your identity provider | Backend | Single sign-on |
| app.navigara.com:443 | Collector | Work assignment. Hybrid only, never on-prem |
Analysis sends commit messages and changed lines to the endpoint you configure, under your own account, never to Navigara. If code must not leave the network, host the model inside it: any OpenAI-compatible endpoint works.
| Operated by | Cloud SaaS | Collector on-prem | Full on-premises |
|---|---|---|---|
| Collector host and network | Navigara | You | You |
| LLM endpoint and residency | Navigara | You | You |
| Proxy, TLS and headers | Navigara | Navigara | You |
| Database and backups | Navigara | Navigara | You |
| Root admin key custody | Navigara | Navigara | You |
| Credentials, SSO and tokens | You | You | You |
Read-only, always
Navigara never writes to your repositories or trackers. Minimum scopes, on a service account you own.
Git tokens we cannot read
Encrypt each token against your collector’s key. We store the ciphertext; the collector decrypts it in memory.
Docs →No inbound ports
Every component dials out. Only your own reverse proxy publishes a port.
SSO, SCIM, four roles
SAML and OIDC through Okta, Entra or Google. Passwords off by default. SCIM 2.0 syncs the directory.
Audit log for your SIEM
One structured record per privileged operation: who, what, which resource, outcome, client address.
Signed images, with an SBOM
Every release is cosign-signed with build provenance. Verify it, then pin by digest.
Hardened by default
Non-root, read-only filesystem, no Linux capabilities, and segmented container networks.
One VM to operate
A full deployment is Docker Compose on a single Linux VM, plus managed PostgreSQL with pgvector.
Docs →An hour on your architecture review now beats a blocker in procurement. Come with the questionnaire. SOC 2 Type II report, policy set and DPA on request.