Data Use & Security Measures

Last Updated: June 9, 2026

PaveWay Group, Inc. implements industry-standard technical and organizational security measures to protect sub-Saharan African graduate data processed on Navigate.

1. Data Encryption

- **In Transit**: All data transmitted between your browser and our servers is encrypted using Secure Sockets Layer (SSL) / Transport Layer Security (TLS 1.3) protocols.

- **At Rest**: User profiles, matched opportunities, and uploaded CV files are encrypted at rest on our secure Firebase Cloud Firestore and Cloud Storage servers using AES-256 standards.

2. Access Controls & Database Security

  • We enforce strict Role-Based Access Control (RBAC).
  • Client-side write access to sensitive billing properties (like tier statuses and credit values) is blocked in database rules. These values can only be updated via verified, secure server-side cloud APIs.
  • Uploaded CV PDF files are stored in user-isolated directories where only the account owner is granted read/write credentials.

3. Ingestion Pipeline Safety

- Our document parser runs within isolated, sandboxed serverless environments. - User files submitted to Gemini / Vertex AI models are processed in enterprise cloud environments. These models operate under strict covenants that prohibit the retention or training of public models on consumer documents.

4. Vulnerability Management & Audits

- We conduct periodic security assessments, code quality reviews, and dependency checks. - System notifications and security alerts are monitored to detect and block distributed denial of service (DDoS) attempts or credential stuffing.