ExecutiveNavigants™

Security, privacy and data handling

ExecutiveNavigants is built for POPIA and holds to the stricter GDPR standard. Conversations are not stored, documents are read for the turn they are attached to and not retained, and no model is ever trained on your content. The detail is below.

Is it safe to upload my data here?

There are levels to data security, and ExecutiveNavigants is designed to be safer than most ways of using AI.

Level 1: Cloud storage. Most organisations already store confidential documents in OneDrive or Google Drive. These services encrypt the files, but the documents remain stored, connected to an identifiable account, and accessible until somebody deletes them.

Level 2: Consumer AI. When you attach a document to ChatGPT or Claude, the actual file is uploaded into the chatbot and remains associated with that conversation according to the product’s retention settings.

Level 3: Commercial and enterprise AI. ChatGPT Business, Claude for Work, Copilot and commercial model APIs generally provide better data controls and do not train their models on business data by default. However, “commercial,” “Copilot” or “Azure” does not automatically mean zero retention, private networking or complete tenant isolation.

Level 4: Specially secured enterprise deployments. Azure and similar platforms can provide private endpoints, regional processing, tenant isolation and additional governance controls—but only when those controls have been deliberately purchased, configured and administered. Simply saying that a model runs “on Azure” does not prove that these protections are enabled.

ExecutiveNavigants takes a different approach. You upload the file to us only long enough for us to extract its raw text in memory. We do not store the original file, and we do not upload that file to ChatGPT, Claude or another model platform.

Instead, we pass only the extracted text, anonymously, through commercial APIs in a single chat round. Every model request is restricted to a verified Zero Data Retention endpoint, which means neither OpenRouter nor the model provider retains the prompt or response or uses it to train a model.

Once the model has returned what the workflow needs, we immediately drop everything else from the chat—except long documents, which are cleaned up when you start the next chat, with a 72-hour sweeper for any stragglers. Your conversation is never written to our database.

Removing personal identifiers, client names and unnecessary confidential details remains excellent practice wherever you use AI. But where the information is genuinely needed, ExecutiveNavigants gives you an unusually low-retention way to process it.

Can we use confidential documents and sensitive internal information?

Yes, and you can prove the mechanism to yourself in about a minute.

Test it. Attach a file and ask a question about it in the same message. You get an answer. Now ask about the same document in your next message: on our standard workflows the model will tell you it can no longer see it.

That is one-shot ingestion. The document is read once, the useful facts are extracted into the answer, and the original is dropped from the conversation rather than carried forward. A few workflows that genuinely need a document across several steps have this turned on deliberately, and they say so.

What we store, precisely. Your conversation is never written to our database; there is no message table in it. The original file is never stored at all. Where a long workflow works through a document in sections, that working text is held for that job only: it is deleted when you start your next chat, and within 72 hours at the latest.

We reach the models through their commercial APIs, not through consumer chat products.

What do you store, and for how long?

Very little, and we can be specific.

Your account. An email address, and a mobile number for verification. That is what is needed to run the account and bill it.

Your conversations. Not stored. There is no messages table in our database. Chat history lives in your browser for the session.

Your documents. The original file is never stored. Where a multi-step workflow needs the converted text across its stages, that text is held for that job only, deleted when you start your next chat, else within 72 hours at the latest if you do not activate the deletion.

Usage records. Session metadata, which model ran, and what it cost, so that billing is accurate and you can see your own spend. That record holds no content from your work.

Do you train models on our data, and what do the model providers see?

We do not train any model on your data, and we do not use your content to build anything.

What leaves our server on each request is the message content for that turn and nothing else. The interface machinery, attachment bookkeeping and rendering data are stripped out before the request is sent.

Beyond that, we will only tell you what is true of our own choices. We reach the models through their commercial APIs, not through consumer chat products, which is a materially different arrangement from a staff member pasting a document into a public chatbot.

Is this an agent? Can it reach our email or our systems?

No. Navigants follow defined workflows and ask for your judgement at important stages. They do not independently decide to send email, change your calendar or operate your internal systems.

You work with material you deliberately supply. Uploading a calendar export, for example, is different from granting access to your live calendar.

That reduces the access you need to grant. The aim is to automate the preparation, calculation and production work while leaving business authority with you.

Are you POPIA compliant? Who owns the outputs? Can you sign an NDA or DPA?

We are built for POPIA. We collect the minimum needed to run your account: an email address, and a mobile number for verification. Your chats, your documents and your clients' data are never stored in our database. Ask us to delete your account and those details go with it.

We describe the controls rather than wave a compliance certificate, because that is the honest position and it is the one you can actually check.

You own your outputs, entirely. We claim no rights over anything the system produces for you. We can operate under an NDA and provide the standard data processing documentation your vendor onboarding requires.

Full terms, privacy and refund policies.