Security at Navio

Practical protection for operational data.

Navio handles job addresses, route instructions, driver activity and records from the field. Its security controls are designed to limit access, protect user accounts and give businesses control over what is shared.

Start with a verified user.

Navio uses individual accounts, verified email addresses and server-managed sessions to keep normal product access tied to an identifiable user.

Passwords are not stored in plain text

Account and shared-route passwords are protected with Argon2, a modern password-hashing method designed to make stolen hashes difficult to misuse.

Sessions stay out of browser storage

Sign-in sessions use secure, HTTP-only cookies. Session tokens are randomly generated, stored by Navio only as hashes and checked for expiry on use.

Account changes receive an extra check

Navio applies cross-site request forgery protection to authenticated actions that create, change or delete information.

Password recovery is time limited

Reset links are single-use, expire after a short period and do not reveal whether an email address belongs to a Navio account.

Share the route, not the whole account.

Drivers receive a browser link for the work assigned to them. They do not need the office user's Navio login, and the office remains in control of the shared route.

Long, random route links

Shared routes use randomly generated links. A link can be disabled or replaced from Navio when it should no longer provide access.

Optional password protection

A business can require a separate password before a driver route opens. Successful access is remembered through a signed, time-limited browser cookie.

Only selected job fields are shown

The office can control which imported job fields are included in the driver view, helping avoid sharing information that is not needed in the field.

Access changes take effect

Disabled or expired links are rejected. Changing the shared-route password also invalidates browser access granted under the previous password.

A driver link is an access credential. Send it only to the intended recipient and disable it when the route no longer needs to be available.

Keep field records attached to the right work.

Route progress, issues, comments and completion details remain associated with the relevant route and stop, so the office can review a consistent operational record.

Business data stays separated

Route and account queries are scoped to the signed-in user or their business. Permission checks restrict sensitive actions within business accounts.

Evidence files use controlled access

Driver photos and signatures are stored separately from application records. Office access uses short-lived links generated only after an authorised request.

Uploads are checked before storage

Navio validates supported image formats, file size and image dimensions before a driver photo or signature is accepted.

Payment details stay with the payment provider

Subscription checkout and billing management are handled through Stripe. Navio does not ask customers to enter card details into its own forms.

Tell us when something does not look right.

Security is ongoing work. If you believe you have found a vulnerability, an exposed route or unusual account activity, please report it directly so it can be reviewed.

Current assurance scope. Navio does not currently claim ISO 27001, SOC 2 or another independent security certification. This page describes controls implemented in the product; it is not a certification or guarantee against every possible security event.
Report a security concern

Include a concise description and the affected page or route. Do not email passwords, private customer information or exploit data; we can arrange a safer way to exchange sensitive details.

Email Navio