Your financial data, protected.
Naviio ingests sensitive business financial data — bank transactions, revenue, and accounting records. Security isn’t a feature here; it’s the foundation. Here’s exactly how we protect it.
Encryption
- In transit — all traffic is served over TLS (HTTPS). Nothing moves in the clear.
- At rest — our database (Neon Postgres) encrypts all data at rest with AES-256. On top of that, stored bank and payment access tokens are wrapped in an additional application-layer AES-256-GCM envelope, so even a database leak never exposes usable provider credentials.
Authentication & access
- Multi-factor authentication — authenticator apps (TOTP) and passkeys (WebAuthn). MFA is required before any bank account can be connected.
- Least-privilege roles — team and advisor roles only get the access they need. A fractional-CFO advisor can review and categorize a client’s financials but cannot touch billing, disconnect integrations, manage members, or delete the organization.
- Client-owned access — clients always own their own login. A firm works on a client’s books only after the client explicitly grants access, and that grant is recorded.
Bank connections are read-only
Bank data is connected through Plaid, a bank-grade aggregator trusted by thousands of fintechs. Access is read-only— Naviio can see transactions and balances to build your P&L, cash flow, and runway, but can never move money. Your banking credentials are entered with Plaid and are never shared with or stored by Naviio.
Audit logs & data retention
- Audit logs — access to client organizations is logged: who, what, and when.
- Retention & deletion — you can delete your account and data at any time. Deletion disables access immediately and purges data after a short grace window via an automated nightly job.
- Token revocation — disconnecting an integration revokes and clears its tokens; signing out denylists the session.
AI governance
Naviio’s numbers are computed deterministically from your ledger — we don’t fabricate figures. Where Navi offers AI-generated narrative or suggestions, it carries a clear notice: AI-generated insights are informational and should be reviewed by a qualified financial professional.
SOC 2 roadmap
We’re pursuing SOC 2 — the standard CFO firms ask for. Our controls (encryption, MFA, least-privilege access, audit logging, retention) are already in place; we’re formalizing the evidence and audit:
- SOC 2 Type I — controls designed correctly (in progress).
- SOC 2 Type II — controls operating effectively over time (to follow).
Evaluating Naviio for your firm and need our security details or a subprocessor list? Email security@naviio.com.