Security
You decide what every file is allowed to touch
Founders trust you with their most sensitive documents. Navent keeps that trust, and lets you prove it.
| Label | What it means | Where it may go |
|---|---|---|
| Public | Already outside the company. | Any model |
| Internal | Ordinary deal material, like the deck. | Models you have approved |
| Confidential | Contracts, the cap table, third parties. | Models cleared for it |
| Restricted | Personal data, like payroll. | Only with personal fields removed |
| Sealed | Human eyes only. | No model, ever |
Sealed means sealed. No model can ever be cleared for it.
Your documents are read in Sweden. Reading, judgement and drafting run on Berget AI in Sweden. Open-web research goes to a provider in the US, which is sent search terms only — never a document.
- Every deal is encrypted with its own key, in the EU.
- Classified on arrival by fixed rules, not by a model.
- Opened in an isolated reader with no network access.
- AI that reads your documents cannot browse the web or run code.
- Delete a deal and its key is destroyed, making every copy unreadable, backups included.
- Provider keys are sealed on arrival and never shown again, whoever they belong to.
Every outbound query is screened and written down before it leaves. Anything that would reveal a customer, a price or what you are testing is rewritten or never sent. Registry, patent and trademark lookups carry the company name, because that is the question they answer.
Personal fields are stripped by fixed rules, not AI, and a person signs off the result before it is used.
- Every model call and search is logged: what it read, where it went, what it cost.
- Model spend has a monthly cap, enforced on the server.
- Every deal exports with its log, for an LP, an auditor or a founder who asks.
Found a vulnerability? [email protected]
For your security review
Everything your compliance team will ask for
Shared with every pilot firm before anything is signed.
Data processing agreement
GDPR Article 28 terms: you stay the controller, Navent acts only on your instructions.
Sub-processor list
Every provider that touches your data, where it is based, and 30 days’ notice before any change.
Security overview
How isolation, encryption, deletion and the model boundary work, in writing.
Incident response plan
Who acts, how fast, and how you are told. Notice within 48 hours, well inside GDPR’s 72.
Request the pack: [email protected]
Questions
Where are our documents stored and processed?
Stored in the EU, encrypted. Read by models at Berget AI in Sweden. Only open-web research reaches a US provider, and it sees search terms, never a document.
What encryption do you use?
TLS in transit. AES-256 at rest, with a separate key for every deal.
Is our data kept apart from other firms’?
Yes. Every firm has its own database and its own storage. Nothing is shared between tenants.
Are our documents used to train models?
Navent never does. And no model runs on our account: you connect your own, so your documents reach the provider under the terms you signed with them.
Who at Navent can see our data?
Your firm has its own database, and every deal its own key. Access to production is restricted and logged, and we never copy customer data onto laptops or into test environments.
Whose model account is used?
Model use is included in the subscription, up to a monthly cap. During early access your firm connects its own Berget and Anthropic accounts instead: Navent seals those keys, never shows them again, and holds every call to the cap.
How do people sign in?
Password plus two-factor authentication, required for partners and administrators. Sign-in with Google or Microsoft is on the way.
Are you GDPR compliant?
You are the controller and Navent the processor, under a data processing agreement we sign with every firm.
Can a label be wrong?
Yes, so a person confirms every label, and doubt always rounds up to the more sensitive class.
What happens when we leave?
You have 30 days to export everything. Then we delete it, destroy the keys and send a written deletion receipt.
Walk through it with your own policy
Bring your current policy. We’ll map it into Navent in an hour.