navisa
SecurityInsightsApplying yourself?Log inStart one case

Security

Built for a license.

PIPEDA. Canadian company. Your files stay inside your firm. Client documents never train a model. You approve every send.

Firm-isolated by design

Every firm’s cases sit behind a tenant boundary enforced on every single request, with encrypted sessions and cross-firm access blocked at the API. No other firm can ever see your files.

Encrypted in transit and at rest

TLS on everything in transit; documents and records encrypted at rest. Payments run entirely through Stripe (PCI-DSS Level 1) — card data never touches Navisa.

Your data never trains AI

Navisa’s AI runs under enterprise agreements with model training switched off. Your client documents and case data are never used to train any model, ever.

The AI searches public law — not your files

Our policy-retrieval index holds only public IRCC policy, legislation, and NOC sources. Your client documents are never embedded into any shared search index.

You own your data, on paper

Your firm is the controller; Navisa is the processor under a signed, PIPEDA-compliant Data Processing Agreement, with the full sub-processor list public. Export anytime; deleted within 30 days of closing your account.

You approve every action

Navisa drafts; you decide. Letters, forms, and client messages wait in a review queue — nothing is sent or filed until you explicitly approve it.

PIPEDA-compliantCanadian company (BC)Encrypted in transit and at restPayments on StripeSigned Data Processing Agreement

You can export your data. You approve every action. Client documents never train a model. The law index is public sources only.

Public rules and software — not legal advice, not a representative, not a prediction of IRCC’s decision.