Navigara · Trust·Security

Your data, your environment, your rules.

Three deployment models: fully managed cloud, a collector inside your network, or fully on-premises and air-gapped. Pick the one that matches your security policy.

Security documentation →

SOC 2 Type IIGDPRAnnual penetration testDPA on request

Run by banks, a cybersecurity vendor, and regulated fintechs

Kiwi.comFinshapePartners BankaPurple TechnologyGreysonItrinityESETFTMOKeggSecond Foundation
01

Cloud SaaS

Fully managed. First report in an afternoon.

Your network
Git
repository content
Navigara cloud
CollectorAPIDashboardPostgreSQL

Navigara operates every component and processes your data under a data processing agreement.

Quickstart
02Most common

Collector in your network

Analysis inside your perimeter, dashboard in the cloud.

Your network
GitCollectorLLM endpoint
structured results only
Navigara cloud
APIDashboard

The collector clones and analyzes locally, and holds one outbound stream. Source code never crosses.

On-prem collector
03

Full on-premises

Complete data sovereignty, air-gap included.

Your network
GitCollectorLLM endpointBackendDashboardPostgreSQL
nothing crosses
Navigara cloudnot connected

Every component runs on your side. The licence is verified offline and there is no telemetry.

Full on-premises
01The exact list

A fixed list of outbound connections. No inbound ones.

Outbound destinations and the component that opens them
DestinationComponentPurpose
Your Git hostCollectorCloning and pull request data
Your LLM endpointCollector, backendCommit analysis and summaries
Your issue trackerCollectorAlignment scoring
Your identity providerBackendSingle sign-on
app.navigara.com:443CollectorWork assignment. Hybrid only, never on-prem
# on-prem collector · what crosses the boundary
commit.metadata shape, author, timestamps
review.activity approvals, comments, timings
analysis.scores ETV per developer
knowledge.graph features, layers, dependencies
tracker.linkage issue keys, objective mapping
source.code cloned and deleted in your network
secrets / .env never read
git.credentials decrypted in memory, on your host
→ residency: your VPC / your region
The LLM endpoint is your processor

Analysis sends commit messages and changed lines to the endpoint you configure, under your own account, never to Navigara. If code must not leave the network, host the model inside it: any OpenAI-compatible endpoint works.

Which party operates each control, per deployment model
Operated byCloud SaaSCollector on-premFull on-premises
Collector host and networkNavigaraYouYou
LLM endpoint and residencyNavigaraYouYou
Proxy, TLS and headersNavigaraNavigaraYou
Database and backupsNavigaraNavigaraYou
Root admin key custodyNavigaraNavigaraYou
Credentials, SSO and tokensYouYouYou
02Controls

Every mode ships the same controls, switched on.

Read-only, always

Navigara never writes to your repositories or trackers. Minimum scopes, on a service account you own.

Git tokens we cannot read

Encrypt each token against your collector’s key. We store the ciphertext; the collector decrypts it in memory.

Docs →

No inbound ports

Every component dials out. Only your own reverse proxy publishes a port.

SSO, SCIM, four roles

SAML and OIDC through Okta, Entra or Google. Passwords off by default. SCIM 2.0 syncs the directory.

Audit log for your SIEM

One structured record per privileged operation: who, what, which resource, outcome, client address.

Signed images, with an SBOM

Every release is cosign-signed with build provenance. Verify it, then pin by digest.

Hardened by default

Non-root, read-only filesystem, no Linux capabilities, and segmented container networks.

One VM to operate

A full deployment is Docker Compose on a single Linux VM, plus managed PostgreSQL with pgvector.

Docs →
03Before every rollout

What your security team asks first.

Does our source code leave our network?
Not with a collector inside your perimeter or a full on-premises install: cloning and analysis run locally and only structured results cross the boundary. The one path for code content is the LLM endpoint you configure, under your own provider account. Host the model yourself and nothing leaves at all.
Do we have to open inbound ports?
No. Every component dials out, and the collector opens no listening port. In a full on-premises deployment the only published port belongs to your own reverse proxy.
Can we run it air-gapped?
Yes. A full on-premises deployment makes no connection to Navigara, because the licence key is verified offline, and analysis runs against any OpenAI-compatible endpoint you host, such as vLLM or Ollama.
Can Navigara staff reach our instance?
Every build trusts a Navigara key at the root login endpoint, which we use to verify changes on instances we operate. It is bound to your hostname, needs network access to you, and every use lands in your own audit log. One flag removes it.
Do you train models on our code?
No. Analysis runs against the LLM endpoint you configure, under your own account, so choose one with zero data retention and record it as a sub-processor.
What personal data is involved, and who is the controller?
Data about your engineers: identities, commit activity, tracker content, AI tool usage and derived metrics. Never your own customers’ data. Self-hosted, you are the controller and Navigara is not a processor at all. In cloud, we are a processor under a DPA.
How long is data retained?
Per data class, and you set it. AI tool usage records default to 14 days and raw webhook payloads to 90 days. Capture of AI prompt content is off by default.
Can we get a DPA, your policy set, or a pen test summary?
Yes, from your account representative. Navigara holds SOC 2 Type II; our management system is designed to conform to ISO/IEC 27001:2022 and aligned to SOC 2 and DORA, and an independent penetration test runs at least annually.
Start here

Bring your security team
to the first call.

An hour on your architecture review now beats a blocker in procurement. Come with the questionnaire. SOC 2 Type II report, policy set and DPA on request.

Deployment docs →