Bank-Grade Security

Your data is sacred

We built Life Navigator with security-first architecture. Your personal, financial, and career data is protected by multiple layers of encryption and access control.

Encryption

AES-256 Encryption at Rest

All data stored in our database is encrypted using AES-256, the same standard used by banks and government agencies.

Column-Level Encryption

Sensitive fields like OAuth tokens, account numbers, and SSNs have an additional layer of encryption using pgcrypto with unique per-field keys.

TLS 1.3 in Transit

All data transmitted between your browser and our servers is encrypted with TLS 1.3. API keys and tokens never leave server-side code.

Access Control

Row-Level Security (RLS)

Every database table has PostgreSQL Row-Level Security policies. Users can only access their own data — enforced at the database level, not just the application layer.

Multi-Tenant Isolation

Your AI knowledge graph is completely isolated. Every Neo4j node and Qdrant vector is tagged with your unique tenant ID and filtered on every query.

Service-Role Separation

Administrative operations use a separate service-role key with higher privileges. This key is never exposed to client-side code.

GDPR Compliance

Right to Access (Article 15)

Export all your data as a JSON file at any time. One click gives you everything we store about you.

Right to Erasure (Article 17)

Delete your account and all associated data permanently. Cascading deletion removes your data from every table, graph node, and vector store.

Consent Tracking (Article 7)

Every consent you give is timestamped and versioned. You can review and revoke consent at any time from your settings.

Data Portability (Article 20)

Your data export includes goals, financial records, career information, and all other personal data in a standard JSON format.

Integration Security

OAuth 2.0 Token Vault

Gmail and Outlook tokens are stored in an encrypted vault table accessible only by server-side service role. Tokens are automatically refreshed and re-encrypted.

Minimal Scope Requests

We request only the OAuth scopes needed for the features you use. Email read access doesn't grant write access unless you enable sending.

No Data Selling

We will never sell, share, or monetize your personal data. Your data is used only to provide you with personalized advice.

Infrastructure

Supabase Platform

Hosted on Supabase with SOC 2 Type II certified infrastructure. Database backups, point-in-time recovery, and 99.9% uptime SLA.

Edge Function Isolation

Background processing (email sync, GraphRAG) runs in isolated Deno edge functions with per-request sandboxing.

Audit Logging

All sensitive operations are logged in our security audit trail. Data exports, deletions, and token operations are tracked with timestamps.

Questions about security?

We're happy to answer any security questions. Reach out to our team.

Get Started Free

AI Assistant

🤖

Welcome to AI Assistant

Loading AI agent...

Press Enter to send, Shift+Enter for new line

General information, not financial, tax, or legal advice.