Passwords are not stored in plain text
Account and shared-route passwords are protected with Argon2, a modern password-hashing method designed to make stolen hashes difficult to misuse.
Navio handles job addresses, route instructions, driver activity and records from the field. Its security controls are designed to limit access, protect user accounts and give businesses control over what is shared.
Navio uses individual accounts, verified email addresses and server-managed sessions to keep normal product access tied to an identifiable user.
Account and shared-route passwords are protected with Argon2, a modern password-hashing method designed to make stolen hashes difficult to misuse.
Sign-in sessions use secure, HTTP-only cookies. Session tokens are randomly generated, stored by Navio only as hashes and checked for expiry on use.
Navio applies cross-site request forgery protection to authenticated actions that create, change or delete information.
Reset links are single-use, expire after a short period and do not reveal whether an email address belongs to a Navio account.
Drivers receive a browser link for the work assigned to them. They do not need the office user's Navio login, and the office remains in control of the shared route.
Shared routes use randomly generated links. A link can be disabled or replaced from Navio when it should no longer provide access.
A business can require a separate password before a driver route opens. Successful access is remembered through a signed, time-limited browser cookie.
The office can control which imported job fields are included in the driver view, helping avoid sharing information that is not needed in the field.
Disabled or expired links are rejected. Changing the shared-route password also invalidates browser access granted under the previous password.
Route progress, issues, comments and completion details remain associated with the relevant route and stop, so the office can review a consistent operational record.
Route and account queries are scoped to the signed-in user or their business. Permission checks restrict sensitive actions within business accounts.
Driver photos and signatures are stored separately from application records. Office access uses short-lived links generated only after an authorised request.
Navio validates supported image formats, file size and image dimensions before a driver photo or signature is accepted.
Subscription checkout and billing management are handled through Stripe. Navio does not ask customers to enter card details into its own forms.
Security is ongoing work. If you believe you have found a vulnerability, an exposed route or unusual account activity, please report it directly so it can be reviewed.
Include a concise description and the affected page or route. Do not email passwords, private customer information or exploit data; we can arrange a safer way to exchange sensitive details.