Data Use & Security Measures
Last Updated: June 9, 2026
PaveWay Group, Inc. implements industry-standard technical and organizational security measures to protect sub-Saharan African graduate data processed on Navigate.
1. Data Encryption
- **In Transit**: All data transmitted between your browser and our servers is encrypted using Secure Sockets Layer (SSL) / Transport Layer Security (TLS 1.3) protocols.
- **At Rest**: User profiles, matched opportunities, and uploaded CV files are encrypted at rest on our secure Firebase Cloud Firestore and Cloud Storage servers using AES-256 standards.
2. Access Controls & Database Security
- We enforce strict Role-Based Access Control (RBAC).
- Client-side write access to sensitive billing properties (like tier statuses and credit values) is blocked in database rules. These values can only be updated via verified, secure server-side cloud APIs.
- Uploaded CV PDF files are stored in user-isolated directories where only the account owner is granted read/write credentials.
3. Ingestion Pipeline Safety
- Our document parser runs within isolated, sandboxed serverless environments. - User files submitted to Gemini / Vertex AI models are processed in enterprise cloud environments. These models operate under strict covenants that prohibit the retention or training of public models on consumer documents.
4. Vulnerability Management & Audits
- We conduct periodic security assessments, code quality reviews, and dependency checks. - System notifications and security alerts are monitored to detect and block distributed denial of service (DDoS) attempts or credential stuffing.