Security and data
Navigent works with information about real people. So the rules are simple and strict: you're in charge of the candidates' data, we delete what you don't use, the AI model never sees who the candidates are, and nobody at Navigent looks without a reason you can see.
Who is responsible
- You are the controller, and Navigent is the processor of candidate data. It's set out in the data processing agreement, which the owner accepts when the organization is created.
- Navigent itself is the controller of your account data, of navigent.io, of the "Remove me from Navigent" page and of the suppression list.
- Candidates come from a database of professional profiles, each linked to the person's LinkedIn profile.
- As the controller, you inform candidates that you process their data. Navigent adds no line about it to your messages. If you want one, you write it into your own template.
- Roles, assessments and decisions are never shared with other customers, and candidate data is never used across organizations.
What we keep, and for how long
| Data | For how long |
|---|---|
| Candidates who aren't on a shortlist for an active role | 90 days after they were last fetched |
| Candidates on the shortlist or further along for an active role | As long as the role is active. Close it, and they're deleted 90 days later |
| Hired candidates for a closed role | As long as you choose for the workspace, 12 months by default |
| Profile photos | Fetched only when the workspace has photos turned on, and deleted with the candidate |
| Decisions, notes and messages about a candidate | Deleted with the candidate |
| The log of AI assessments | 6 months. Without the name once the candidate is deleted |
| Your do-not-contact list | Until you delete an entry yourself |
| The activity feed | 12 months |
| The log of exports | 2 years |
| Roles whose search was never started | 30 days |
| Account data | As long as the organization exists, then 30 days |
| Your acceptance of the terms and the data processing agreement | The organization's lifetime plus 5 years, as the record of what you accepted |
| Job ad files | Not stored. Only their text |
| LinkedIn profiles used to find people like them | Not stored |
A daily job deletes by these rules.
What the AI model never sees
- Names, photos, email addresses and phone numbers. To the model, candidates are numbers, and it gets only the career: titles, employers, tenure, seniority and town.
- Sensitive traits. Gender, age, ethnicity, health, religion and union membership are never guessed or used. Years of experience are only compared with what the role asks for.
- Instructions from outside. Job ads, web pages, files and profiles are data to the model, never orders. The model can't take actions, and every source it cites is checked against the candidate's real history before it's shown.
Every assessment is logged with the model, the prompt version, the input and the result, and kept for 6 months. A person makes every shortlist and reject decision, and every decision is saved.
Who can see what
- Sign-in without passwords. You sign in with Google or a sign-in link by email. Navigent uses no passwords.
- Permissions. Users are owners, admins or members, with access to every workspace or to selected ones. A workspace you can't access looks as if it doesn't exist. Only the owner handles the subscription and billing.
- Organizations kept apart. Every table in the database has access rules for every row, so one organization can never see another's data. The rules are tested with every change to the code.
- Exports. Every CSV export is logged with who, what and when, and owners and admins can see the log.
- Your accounts. LinkedIn, Gmail and Outlook connect through a secure sign-in. Navigent never sees the password and doesn't hold the access to the accounts itself. Remove a user, and their accounts are disconnected.
- Your inboxes. Only conversations with candidates in your campaigns are stored. Nothing else in the inboxes ever reaches Navigent.
- No tracking. The product has no third-party analytics, and messages have no open or click tracking.
When Navigent's staff need to help
- No access by default. Our staff can't see candidate data. Without access they see only a role's shape, numbers and status; names, photos and profiles are hidden.
- Access with a reason and a time limit. If support needs to see your data to help, it takes a written reason and a time limit of 8 hours at most. The access is read-only. Anything more needs a second approval, which is logged too.
- You see everything. The owner gets an email when access is granted, and sees every grant and every action under Settings › Security. The owner can end an access at once.
- Two-step sign-in. All staff sign in with two steps, and every action is written to a log kept for 2 years.
The Chrome extension
The extension asks for no access to linkedin.com when you install it. It reads only the profile you have open, and only when you click, and it never reads contact details, messages or your history. It talks only to Navigent. It never navigates, scrolls, clicks or sends anything on LinkedIn itself. You disconnect it under Settings, and signing out in the extension closes its access.
Encryption, operations and hosting
- All traffic between your browser and Navigent is encrypted with HTTPS, and your browser is told never to use anything else. Data is encrypted at rest as well.
- We take daily backups and can restore the database to any point in time. We rehearse a restore at least twice a year.
- Keys and secrets never live in the code, and every change is scanned for known vulnerabilities and for keys included by mistake.
- Job ad files are read in memory and never stored, and links to ads are fetched under fixed security rules.
The database holding your data and the candidates' is in the EU, in Frankfurt, and Navigent runs in the same place.
Sub-processors
The suppliers that may come into contact with personal data are on our list of sub-processors, with what each one processes. We publish the list when Navigent opens. We tell you 30 days before we add a new one.
The list also shows where each supplier processes data, and on what basis data may be transferred, confirmed in writing by the supplier.
When a candidate wants to be removed
When Navigent opens, anyone can ask to be removed on the Remove me from Navigent page, with the link to their LinkedIn profile and an email they confirm. The person is then deleted from every customer's workspaces, including yours, and goes on a suppression list that applies to all of Navigent's customers: they are never fetched, assessed or contacted through Navigent again. The list holds no names or links, only codes that can't be read back. It happens on a standing instruction in the data processing agreement, so you don't have to approve each case.
Anything else a candidate asks is yours to answer, as the controller, and Navigent gives you the tools: everything about a candidate is on their card and in your organization's full export, deleting a candidate removes the photo and everything that belongs to them, and an objection puts the candidate on your do-not-contact list.
The data processing agreement
The owner accepts the data processing agreement when the organization is created. We publish it when Navigent opens. It covers the sub-processors, the deletion rules, the exception for the AI log, transfers, and the standing instruction to remove those who ask. When there's a new version, it's accepted at the next sign-in, and the earlier acceptance is kept.
Questions about security
Write to info@navigent.io, and we'll answer.