← Naviio
Trust & Security

Your financial data, protected.

Naviio ingests sensitive business financial data — bank transactions, revenue, and accounting records. Security isn’t a feature here; it’s the foundation. Here’s exactly how we protect it.

Encryption

  • In transit — all traffic is served over TLS (HTTPS). Nothing moves in the clear.
  • At rest — our database (Neon Postgres) encrypts all data at rest with AES-256. On top of that, stored bank and payment access tokens are wrapped in an additional application-layer AES-256-GCM envelope, so even a database leak never exposes usable provider credentials.

Authentication & access

  • Multi-factor authentication — authenticator apps (TOTP) and passkeys (WebAuthn). MFA is required before any bank account can be connected.
  • Least-privilege roles — team and advisor roles only get the access they need. A fractional-CFO advisor can review and categorize a client’s financials but cannot touch billing, disconnect integrations, manage members, or delete the organization.
  • Client-owned access — clients always own their own login. A firm works on a client’s books only after the client explicitly grants access, and that grant is recorded.

Bank connections are read-only

Bank data is connected through Plaid, a bank-grade aggregator trusted by thousands of fintechs. Access is read-only— Naviio can see transactions and balances to build your P&L, cash flow, and runway, but can never move money. Your banking credentials are entered with Plaid and are never shared with or stored by Naviio.

Audit logs & data retention

  • Audit logs — access to client organizations is logged: who, what, and when.
  • Retention & deletion — you can delete your account and data at any time. Deletion disables access immediately and purges data after a short grace window via an automated nightly job.
  • Token revocation — disconnecting an integration revokes and clears its tokens; signing out denylists the session.

AI governance

Naviio’s numbers are computed deterministically from your ledger — we don’t fabricate figures. Where Navi offers AI-generated narrative or suggestions, it carries a clear notice: AI-generated insights are informational and should be reviewed by a qualified financial professional.

SOC 2 roadmap

We’re pursuing SOC 2 — the standard CFO firms ask for. Our controls (encryption, MFA, least-privilege access, audit logging, retention) are already in place; we’re formalizing the evidence and audit:

  • SOC 2 Type I — controls designed correctly (in progress).
  • SOC 2 Type II — controls operating effectively over time (to follow).

Evaluating Naviio for your firm and need our security details or a subprocessor list? Email security@naviio.com.