Skip to main content

Trust

Security at Navlyt

Navlyt is built for regulated aviation operators managing sensitive compliance and crew records. Our security program is designed to protect data confidentiality, integrity, and availability across the platform lifecycle.

Encryption

All traffic to Navlyt is encrypted in transit with TLS 1.2+ and sensitive data is encrypted at rest with AES-256.

Access controls

Role-based permissions restrict access to operational and crew data. Authentication events are logged and reviewed.

Tenant isolation

Operator data is segmented by tenant boundaries and protected with isolation controls across application and data layers.

Monitoring and alerts

We monitor infrastructure health, authentication anomalies, and service reliability with real-time alerts and on-call response.

Backups and recovery

Automated backups are retained and tested for recovery. Recovery procedures are documented and reviewed on a regular schedule.

Vulnerability management

Dependencies and infrastructure are continuously scanned. Critical issues are prioritized and remediated under defined SLAs.

Operational security practices

  • Least-privilege access for production systems
  • Secure SDLC with code review before deployment
  • Secrets managed outside source control
  • Audit logging for key data and configuration changes
  • Incident response runbooks with internal escalation
  • Sub-processor due diligence and contractual safeguards

Security contacts

Security requests and vulnerability disclosures: support@navlyt.com

For enterprise procurement questionnaires, we respond within one business day.