Information Security
This statement describes the controls Navitra Technologies Ltd applies to its internal systems and client delivery environments. It is written for enterprise buyers conducting supplier due diligence.
Scope
This statement covers the information security controls applied to Navitra Technologies Ltd's internal systems, development toolchain, and the shared services we operate on behalf of clients.
Client-hosted deployments — where Navitra builds or supplies software that runs entirely inside the client's own infrastructure — fall outside the scope of this statement. The security of those environments is governed by the client's own controls. Navitra's obligations in those engagements are defined in the relevant contract.
Access control
- Least privilege: access to systems and data is scoped to what is required for the role, enforced through role-based access control and per-project permissions.
- Access reviews: access rights are reviewed monthly. Unused or excess permissions are revoked.
- Multi-factor authentication: MFA is required for all access to the Navitra ERP, cloud console, code repositories, VPN, and all other internal systems.
- Leavers: access to all systems is revoked within 30 days of a member of staff or contractor leaving.
- Administrative access: 1 person holds administrative access to production systems. Administrative sessions are logged, time-limited, and require re-authentication.
Encryption
In transit
- All connections to client-facing services and this website use TLS. HTTP is redirected to HTTPS.
At rest
- Data stored on managed databases is encrypted at rest using AES-256.
- Endpoint storage: full-disk encryption is enforced on all company devices.
Key management
- Encryption keys are managed by the administrator. Key rotation frequency is not disclosed.
Devices and endpoints
- Device policy: work is performed on company devices and platforms only. Use of personal or non-approved devices requires prior approval in advance.
- Disk encryption: full-disk encryption is enabled on all devices used for work. The specific standard and storage location are not disclosed.
- Screen lock: automatic screen lock timeout is not disclosed.
- Malware protection: anti-virus software is installed on all company devices. Staff also receive security awareness training to mitigate social engineering and malware risks.
- Device management: no MDM is currently in place. Device management is handled through manual policy and device controls.
Infrastructure
- Hosting: Navitra's website and web infrastructure are hosted by Hostinger in the United Kingdom. AI compute infrastructure for model training and inference is provisioned from Google Cloud Platform, Microsoft Azure, Amazon Web Services, and Hetzner, with the specific region agreed per client engagement.
- Network isolation: services are configured to expose only the ports required for operation. Internal services are not publicly routable.
- Firewall and access rules: inbound access is restricted to required ports. Firewall rules are reviewed when infrastructure changes are made.
- Logging: server access logs are retained for 90 days in line with our Privacy Notice. Authentication events and key infrastructure changes are logged.
- Environment separation: development and production environments are separated and operated under separate credentials.
Note on cloud provider certifications: Hostinger, Google Cloud Platform, Microsoft Azure, Amazon Web Services, and Hetzner each hold their own security certifications including ISO 27001 and, where applicable, SOC 2. Those certifications apply to the cloud platform infrastructure and do not extend to Navitra's own configuration, code, processes, or data handling. Our certifications are listed separately in the Certifications section of this page.
Secure development
- Change review: code changes are reviewed before being merged to the main branch. Production deployments require sign-off from the Director.
- Dependency scanning: third-party dependencies are reviewed for known vulnerabilities. Automated scanning is being introduced as part of our move toward Cyber Essentials certification.
- Secret management: secrets, credentials, and API keys are not committed to source control. They are managed via environment variables and platform secret stores. Repositories are checked for accidentally committed secrets as part of code review.
- Static analysis: static analysis tooling is being formalised as part of the Cyber Essentials programme. Code review currently serves as the primary gate.
- Penetration testing: no formal penetration test has been completed to date. A test is being scoped as part of the Cyber Essentials Plus programme. Results and remediation status will be available for discussion on request once complete.
Vulnerability and patch management
- Routine patching: operating system and application packages are patched on a monthly schedule. Where possible, patches are applied to a non-production environment first before being promoted to production.
- Critical vulnerabilities: patches for critical CVEs are applied as quickly as a fix is available, outside the routine schedule where necessary.
- Tracking: open vulnerabilities are tracked manually and reviewed monthly, or immediately when a critical advisory is published.
- End-of-life software: software that has reached end of life and is no longer receiving security updates is replaced at or before that date.
Incident response
- Reporting: security incidents should be reported to contact@navitratech.com. This address is monitored by the Director during business hours.
- Incident response plan: Navitra maintains a business continuity and incident response plan covering detection, containment, eradication, recovery, and post-incident review.
- Severity classification: incidents are assessed by impact and urgency. High-severity incidents affecting client data or service availability are escalated immediately to the Director.
- Regulatory notification: where a security incident involves personal data and meets the reporting threshold under UK GDPR, we notify the Information Commissioner's Office within 72 hours of becoming aware. See our Privacy Notice for further detail.
- Client notification: where an incident affects a client's data or services, we will notify the client within 24 hours of confirming the incident, regardless of whether the regulatory threshold is met.
- Post-incident review: a written post-incident review is completed following each significant incident. Findings are shared with affected clients on request.
Business continuity and backups
- Backup frequency: critical data is backed up daily.
- Backup location: backups are stored separately from the primary environment.
- Restore testing: backup restoration is tested annually.
- Recovery objectives: recovery time and recovery point objectives are defined in the business continuity plan and are available for discussion with enterprise clients on request.
- Business continuity plan: a full business continuity plan is in place covering key service failure scenarios, staff unavailability, and infrastructure outage.
People
- Pre-employment checks: right-to-work verification and professional references are obtained for all staff and contractors before they begin work.
- Confidentiality: all staff and contractors with access to client data or company systems are required to sign a confidentiality agreement before beginning work. Obligations survive termination of employment or engagement.
- Security training: security awareness training covering phishing, password hygiene, data handling, and incident reporting is provided to all staff on joining and is being formalised into an annual programme as part of our Cyber Essentials work.
- Security awareness: staff receive updates on relevant threats and policy changes. Phishing simulation and a formal awareness schedule are being introduced alongside the Cyber Essentials programme.
Sub-processors
We use third-party sub-processors for hosting, email, and infrastructure services. A current list of sub-processors who may handle personal data is maintained in our Privacy Notice.
We enter into written data processing agreements with all sub-processors before allowing them to process personal data on our behalf. We assess sub-processors' security posture before onboarding them and review them at least annually or when a significant change occurs.
Sub-processors are permitted to access only the data necessary for the service they provide. Contractual restrictions on onward transfers are included in all data processing agreements.
Certifications and audits
This section states what we hold, what we are working toward, and what we have not yet started.
Currently held
None currently held.
In progress
- Cyber Essentials: working toward certification. Self-assessment in progress.
- Cyber Essentials Plus: working toward certification. Dependent on Cyber Essentials completion; penetration test being scoped.
- ISO 27001: working toward certification. No current target date; work is ongoing alongside the Cyber Essentials programme.
- Penetration test: no formal test completed. Being scoped as part of the Cyber Essentials Plus process.
Requesting a security pack
Enterprise buyers and clients may request additional detail beyond this page — for example, a completed security questionnaire, evidence of specific controls, a draft data processing agreement, or penetration test summary. Send requests to contact@navitratech.com. We aim to respond within five business days.
Version 1.0 · Last reviewed 25 September 2026 · Owner Jaydev Bhatt, Director