Enterprise

Built to pass a security review, not just a demo.

Single sign-on, role-based access control, SIEM streaming, and a deployment model your infra team can sign off on — the controls a security questionnaire actually asks for.

Talk to sales → See pricing
Identity & Access
Your identity provider, your access model.
Nobody signs in with a shared password, and every role's permissions are enforced on every request — not just hidden in the UI for roles that shouldn't see them.
Single sign-on (OIDC)
Okta, Azure AD, Google Workspace, or any OIDC-compliant IdP. A member signing in with an email at your registered domain is routed through your IdP and joins your org automatically.
Live
Role-based access control
Owner, admin, and viewer roles, enforced on every mutating action — kill switches, policies, approvals, billing, settings.
Live
SAML
Every major IdP this targets — Okta, Azure AD, Google Workspace — already speaks OIDC. SAML is a scoped fast-follow, available on request for enterprise deals that need it.
On request
Self-hosted deployment
Run Navige entirely inside your own environment via Docker Compose — nothing leaves your network, and licensing is a one-time offline check with no phone-home call to Navige at all. Built and verified end to end, for teams whose data residency or network policy means a shared cloud isn't an option at all.
Live
Managed bring-your-own-cloud
A Navige-managed deployment running inside your own cloud account, so you get the managed experience without self-hosted's operational overhead. On our roadmap — talk to us about your timeline.
Roadmap
Observability & Integration
Every decision, streamed into the tools you already run.
Governance data reaches your SIEM and your own risk model in real time — it doesn't live only in Navige's dashboard.
SIEM streaming
An HMAC-signed event for every governance decision — allowed, denied, pending, approved, rejected, expired. Ingested natively by Splunk HEC, Datadog, Microsoft Sentinel, and Elastic.
Live
Blockchain-anchored audit trail
Every batch hashed as a Merkle tree and anchored to Polygon — a single record can be proven without exposing the rest of its batch, and a separate completeness check catches a record deleted before it was ever anchored. Opt-in, free on every plan. Try the public verifier →
Live
Signed decision receipts
A portable, per-action evidence object — decision, the exact policy version that fired, and a Merkle proof when anchored — signed and verifiable completely offline. Hand one to a regulator or a client without them needing a Navige login.
Live
Shadow mode
Run fully connected without ever actually blocking or holding anything — every decision is still computed and recorded, none of it enforced. A report shows exactly what governance would have caught, before you ever let it touch production traffic.
Live
Agent Risk Score
Every agent scored 0–100 from real signals — autonomy level, coverage, ownership, denied or blocked calls, financial or destructive tool access, and access to sensitive systems.
Live
Gateway latency (p50/p95/p99)
Real overhead the governance layer adds to every tool call, computed from your own traffic and shown in your dashboard.
Live
On latency specifically: the number is only as meaningful as the traffic behind it. A brand-new organization sees a "too few samples" note until there's enough real call volume.
Contract & Compliance
Terms your legal and security teams can sign off on.
The paperwork a real procurement process needs.
MSA + DPA
A standard Master Services Agreement and a published Data Processing Agreement covering sub-processors, transfer mechanisms, and breach notification.
Live — read the DPA
SOC 2
Navige's access controls and audit-evidence practices are built with SOC 2's requirements in mind. Formal certification has not yet been started.
Roadmap
Dedicated SLA
A formal uptime and support-response commitment. No uptime SLA exists today — this is on our roadmap as we build the monitoring history to back one, not something we'll write into a contract before we can actually stand behind it.
Roadmap
PII & secret masking
Emails, phone numbers, card numbers, and API keys are masked before they're ever written to storage — on every plan, not an enterprise add-on.
Live
See it applied
Same controls, mapped to your actual use case.
Ready to run this past security?
We'll walk your team through the architecture, the DPA, and whatever your questionnaire actually asks.
Talk to sales → Start free instead
Technical docs: navige.ai/technical · DPA: navige.ai/dpa