{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"navan","name":"Navan","domain":"navan.com","category":"Travel and hospitality","one_liner":"Streamline your corporate travel management and expense processes in one","trust_center_url":"https://trust.navan.com/","security_page_url":null,"url":"https://certreports.com/vendors/navan/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 19 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/navan/soc-2","evidence":[{"source_type":"trust_center","source_name":"Navan trust centre (Drata)","url":"https://trust.navan.com/","fetched_at":"2026-09-19 07:33:17.167532+00","content_hash":"16e00e06e3a562acaef2ff82105fdac96206b7b7706e2c38807cf341d0546f07","wayback_url":null,"quote":"SOC 2 Type 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/navan/gdpr","evidence":[{"source_type":"trust_center","source_name":"Navan trust centre (Drata)","url":"https://trust.navan.com/","fetched_at":"2026-09-19 07:33:17.167532+00","content_hash":"16e00e06e3a562acaef2ff82105fdac96206b7b7706e2c38807cf341d0546f07","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/navan/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Navan trust centre (Drata)","url":"https://trust.navan.com/","fetched_at":"2026-09-19 07:33:17.167532+00","content_hash":"16e00e06e3a562acaef2ff82105fdac96206b7b7706e2c38807cf341d0546f07","wayback_url":null,"quote":"PCI DSS","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/navan/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Navan trust centre (Drata)","url":"https://trust.navan.com/","fetched_at":"2026-09-19 07:33:17.167532+00","content_hash":"16e00e06e3a562acaef2ff82105fdac96206b7b7706e2c38807cf341d0546f07","wayback_url":null,"quote":"ISO/IEC 27001","confidence":1}]},{"framework":"csa-star","framework_name":"CSA STAR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a CSA STAR Level 1 self-assessment on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states CSA STAR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/navan/csa-star","evidence":[{"source_type":"trust_center","source_name":"Navan trust centre (Drata)","url":"https://trust.navan.com/","fetched_at":"2026-09-19 07:33:17.167532+00","content_hash":"16e00e06e3a562acaef2ff82105fdac96206b7b7706e2c38807cf341d0546f07","wayback_url":null,"quote":"CSA STAR","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Drata) as of 19 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 1 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/navan/security","evidence":[{"source_type":"trust_center","source_name":"Navan trust centre (Drata)","url":"https://trust.navan.com/","fetched_at":"2026-09-19 07:33:17.167532+00","content_hash":"16e00e06e3a562acaef2ff82105fdac96206b7b7706e2c38807cf341d0546f07","wayback_url":null,"quote":"SOC 1 Type 2","confidence":1}]}],"brief":{"summary":"According to Navan's trust centre, as of 19 Sep 2026, the company has a SOC 2 Type II report on file. Navan's trust centre also states, as of 19 Sep 2026, that the company meets GDPR requirements. As of 19 Sep 2026, Navan states on its trust centre that it holds PCI DSS. Navan states on its trust centre, as of 19 Sep 2026, that it holds ISO/IEC 27001. Navan's trust centre further states, as of 19 Sep 2026, that the company holds CSA STAR and has a SOC 1 Type II report on file.","bullets":["SOC 2 Type II and SOC 1 Type II reports: vendor states on trust centre, as of 19 Sep 2026","PCI DSS and ISO/IEC 27001: vendor states on trust centre, as of 19 Sep 2026","GDPR and CSA STAR: vendor states on trust centre, as of 19 Sep 2026"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 10:38:09.899087+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trust.navan.com/","availability":"public","detail":"1 subprocessors listed on the trust centre","as_of":"2026-09-19"}],"subprocessors":[{"name":"Status Monitoring Amazon Web Services","domain":null,"purpose":null,"location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T15:51:07.160Z"}