Security

A cockpit that concentrates sensitive data has to defend itself.

NavOps brings together the IT budget, supplier contracts and application criticality. That is exactly what an attacker would want to read. Here are the product’s security choices, and what stays on your side.

The principles

  • Partitioned by default

    Cross-tenant access does not exist in the model, so there is nothing to deny.

  • Encrypted transport, end to end

    In transit and at rest, with no configurable exception.

  • Least privilege

    A role sees its scope of entities, and nothing else.

  • Access traceability

    Reads and changes on sensitive data leave a trace.

Tenant isolation

Isolation is not something you enforce with a filter you might forget to apply. The customer space identifier is part of the access key to the data: a query that does not carry it returns nothing. There is therefore no path, not even an accidental one, that lets one customer read another’s data.

The same holds for background jobs and exports: they run within the scope of a single customer space.

  • Each customer gets its own data space, identified at the root of the model.
  • Every query is bounded to the authenticated customer's space; there is no "all organisations" query.
  • Exports and backups are produced per customer space, never pooled into one file.
  • In On-Premise mode the isolation is physical: one installation, one customer.

Encryption

Transport encryption is not a configuration option: there is no cleartext entry point to switch off. At rest, data and backups are encrypted, so access to the storage medium does not grant access to the content.

Technical logs exist for diagnosis, not for archival: they record events and technical identifiers, not your amounts or your contract clauses.

  • Transport encryption on every connection, with no cleartext endpoint available.
  • Data encrypted at rest, backups included.
  • No steering data is written to technical logs.
  • The exports you generate travel over the same encrypted transport.

Strong authentication

A cockpit displaying the group budget and the contract register deserves better than a password. Multi-factor authentication is available on every access, and we recommend enforcing it with no convenience exceptions.

Authorisation follows the same least-privilege principle: a role carries a scope of entities. The consolidated group view is not visible by default; it is granted.

  • Multi-factor authentication available on every access.
  • Roles carry a scope of entities: a subsidiary manager sees only their subsidiary.
  • Expiring sessions, revocable immediately by an administrator.
  • Traceability of sign-ins and of changes to sensitive data.

Hosting in France

Locating data in France is not enough if the operator hosting it answers to another jurisdiction. The NavOps sovereign cloud mode runs on Scaleway, an operator under French law, in its French regions — backups included.

If that guarantee is not enough for your internal policy, On-Premise mode settles the matter by design: nothing leaves your network.

  • Scaleway infrastructure, French regions, for the sovereign cloud mode.
  • An operator under French law: no dependency on extraterritorial legislation.
  • Backups kept in the same geographic zone as the data.
  • In On-Premise mode the question does not arise: the hosting is yours.

Operations and updates

The security of an application rests as much on the long run as on its architecture. Security patches are published for both deployment modes: we apply them ourselves in the sovereign cloud, and we make them available On-Premise, where you stay in control of the application window.

Reversibility is part of the arrangement: your data exports in an open format, at any time, without having to ask us. A possible exit is also a security guarantee.

  • Security patches published for both deployment modes.
  • In cloud mode we apply the patches; On-Premise, you choose the window.
  • Your data exports at any time in an open format, with no action needed from us.
  • No steering data is reported back to us from an On-Premise installation.

Security

What stays on your side

The security of a steering application rests as much on how it is operated as on its code. These points belong to your organisation.

  • Account lifecycle management: joiners, movers and leavers.
  • Enabling strong authentication on every access, with no convenience exceptions.
  • Defining the entity scope of each role, as tightly as possible.
  • In On-Premise mode, server hardening, backups and applying new versions.

Compare both modes

www.navops.fr

And this website, specifically

The site you are reading is strictly static: no database, no API, no secret, no server-side processing. There is nothing to steal and nothing to inject. Every transactional journey leaves for the application, on another domain.

  • No cookies, no trackers, no third-party analytics.
  • No form on this site sends data anywhere.
  • No resource loaded from a third-party domain, fonts included.
  • The site source contains no secret: it is deployable anywhere.

Reporting a vulnerability

If you believe you have found a flaw on the site or in the application, write to us. Please describe the observed behaviour precisely and hold off public disclosure until we have been able to fix it.

securite@navops.fr

Ready to frame your steering?

Open your cockpit, with your own figures.

Subscription and account creation happen inside the application. This site collects nothing: it takes you there.

You are heading to app.navops.cloud — a page hosted by the application.