Security

Responsible disclosure policy — how to report a vulnerability and what to expect from us.

If you have found a security issue in Navige, please email us directly at hello@navige.ai. Do not open a public GitHub issue for security vulnerabilities.

What we ask

What you can expect from us

In scope

TargetExamples
api.navige.aiAuthentication bypass, tenant data leakage, injection, approval flow manipulation
app.navige.aiXSS, CSRF, session issues
navige.aiReflected or stored XSS, open redirects
Navige SDKsnpm package, Python SDK — logic or security bugs

Out of scope

Safe harbour

We consider security research conducted under this policy to be authorised. We will not pursue civil or criminal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. If a third party initiates legal action against you for research you conducted under this policy, we will make clear that your actions were authorised by us.

How to report

Email: hello@navige.ai

You can also reach us via the /.well-known/security.txt standard contact file.

What we track

Every report we receive is logged with: date received, severity assessment, fix date, and whether it was publicly disclosed. We are building a track record we can share with enterprise customers and auditors.