Skip to content
Navira نافيرا — by SHAHMCO
Sign in

Where your data lives

Your data is hosted on enterprise-grade managed cloud infrastructure, encrypted at rest, with strict per-company isolation enforced at the database level — one company's records are walled off from another's in the database itself, not merely hidden in the interface. If your organisation has a specific data-residency requirement, raise it early and we will give you a straight answer.

One company cannot see another

Every table is protected by database-level row-level security — 73 tables, 207 policies, and not one of them without a scope. Sixteen tables go further and carry no policy at all, so an ordinary connection is refused outright. One company's data is not merely hidden from another in the interface; the database refuses to return it.

The distinction matters: application-level filtering fails open when a developer forgets a condition. Database-level security fails closed — the row is never returned, whatever the application asks for.

The key that signs your invoices

The private key that signs your invoices is encrypted at rest with AES-256-GCM under a key held outside the database, so a database copy alone cannot sign anything in your name.

The key pair is generated inside Navira for your device and the certificate is issued by ZATCA to your VAT number — not ours. Nobody at Navira can read the private key out of the database, and if you leave, your cryptographic identity is still yours.

Sessions end on their own

Sessions end after 20 minutes of inactivity and after 12 hours regardless, enforced on the server rather than in the browser.

An unattended screen at a shop counter is the most common way tax records are exposed, and it is not solved by a password policy. Signing out revokes the session rather than merely forgetting it.

Issued documents cannot be altered

An issued invoice cannot be edited or deleted. Corrections are made the way tax law expects — with a credit or debit note that references the original.

Enforced by a database trigger, not by hiding the edit button. Every submission to the tax authority, and its response, is retained as an audit trail against the document.

In transit, and everywhere else

HTTPS everywhere with HSTS, a content security policy that forbids the site being framed, tiered rate limiting on every route, and constant-time verification of incoming payment webhooks.

More than 3,300 automated tests run on every change, covering the VAT engine, the ZATCA document pipeline and the accounting ledger.

Where our responsibility ends

Worth stating plainly, because it is the line every accounting system in this market draws and the one your auditor will ask about.

  • Navira produces the documents and the filings; the submission and its accuracy remain yours. We are your software, not your tax advisor.

Have a security questionnaire?

Send it. We answer them in full rather than pointing you at a badge, and we will tell you where the answer is no.