Security
Information Security Policies and Practices
Because Navigate AIF is a hosted Software-as-a-Service product, we recognize that security is crucial. Keeping customer data safe and secure is a top priority.
The Company is engaged in providing AI-powered navigation and content management solutions through its product (hereinafter referred to as "Navigate AIF"). We work hard to protect our customers from the latest threats. Your input and feedback on our security is always appreciated. This page outlines our information security policies and practices.
1. Data security practices
1.1 Access to all Navigate AIF servers is secure
- Firewalls on all servers are set to default-deny all incoming network connections.
- Database connections are only accepted from other Navigate AIF servers on the internal private subnet.
- All communication with servers (outside of public HTTP/HTTPS access) is over encrypted secure shell (SSH) and password authentication is disabled. SSH authentication is available only via public/private key authentication.
1.2 Software versions and security patches
We strive to keep all server software on the latest version; however, when that is not possible, we do ensure that the latest security patches are installed and up-to-date.
1.3 Data is stored securely
Data is hosted on AWS, DigitalOcean, Google Compute Cloud with encryption enabled wherever feasible, both at the infrastructure layer, as well as the application layer, sometimes both.
1.4 Access to Navigate AIF is secure
All access to Navigate AIF and its APIs is over a secure (SSL encrypted) connection.
1.5 Access is logged
All requests are logged and logs are maintained in the system for a meaningful duration of time.
1.6 Employee security
All employees are required to sign a confidentiality agreement. Employees are not allowed to access unencrypted email content, unless it is shared by users in the form of screenshots or other medium for debugging purposes.
1.7 Backup policy
Backups are stored offsite. Navigate AIF performs daily, weekly, and monthly backups of the entire system.
1.8 Cookies
Information about what we collect is outlined in our privacy policy at: https://navigateaif.com/privacy-policy/. Cookies are required for normal operation of Navigate AIF.
1.9 Terms of use and privacy policy
Terms of Use that is agreed to between our users and the Company are defined at: https://navigateaif.com/terms-and-conditions/. Information about what we collect and how we handle data is outlined in our privacy policy at: https://navigateaif.com/privacy-policy/.
2. Vulnerability detection and disclosure
2.1 Reporting security problems
Send urgent or sensitive reports directly to support@navigateaif.com. We'll get back to you as soon as we can, usually within 24 hours. Please follow up if you don't hear back.
2.2 Tracking and disclosing security issues
We keep ourselves up to date on developments in security research to keep up with the state-of-the-art in web security. Have you discovered a web security flaw that might impact our products? Please let us know. If you submit a report, here's what will happen:
- We'll acknowledge your report and tell you the best way to track the status of your issue.
- We'll investigate the issue and determine how it impacts our products. We won't disclose issues until our investigation is finished, but we'll work with you to ensure we fully understand the issue.
- Once the issue is resolved, we'll get back to you with thanks and credit for the discovery.
3. Incident response practices
An "incident" is any unplanned disruption or degradation of service that is actively affecting customers' ability to use Navigate AIF. We follow an organized approach to addressing and managing an incident. The goal isn't just to solve the incident, but to handle the situation in a way that limits damage and reduces recovery time and costs. Our incident response process will be initiated for any major incident. It provides a framework for effectively responding and reaching a fast resolution time. Our incident response process can be triggered one of two ways, either via automated monitoring and alerting, or via human actions.
3.1 Automated monitoring
Throughout our system, we monitor various metrics to determine if our system is functioning according to parameters. Any deviation is reported back to the development team as an alert.
3.2 Response to an incident
If you want to know more, write to us at admin@navigateaif.com.
