Skip to main content

The platform handles sensitive operating data. Here is how it is handled.

NGX manages contracts, invoices, vendor records, assets, documents, sourcing activity, and execution workflows. This page states how that data is handled today.

What is true today.

These are the specifics a security buyer asks for first, answered rather than deferred to scoping.

Authenticated application access

Access is by named user inside a workspace. There is no public document sharing and no unmanaged file exchange.

Review-first AI extraction

Extracted terms, obligations, risks and suggested actions are surfaced with the source document behind each line, so a team can check them before acting on them.

Decision and workstream context

Records, documents, owners, tasks, decisions, and timing stay attached so teams can review what happened and why.

Hardened public website headers

The public site configuration includes HSTS, Content Security Policy, frame restrictions, content-type protection, referrer policy, and permissions policy headers.

What is true today, area by area.

This is not a substitute for a formal security review. It is what NGX can tell you today, area by area.

Access and permissions

Every user is named and authenticated. Access is scoped by role and by workspace, so who can view a record, who can change it and who can act on it are three separate answers.

Document handling

Contracts, invoices, proposals, order forms and supporting files are operating records, not attachments. Each stays connected to the vendor, the obligation, the decision and the task it belongs to.

Audit trail

Ownership, timing, workstreams, decisions and next steps are preserved, so a team can see what changed and why.

AI-assisted extraction

Document intelligence extracts terms, obligations, risks and action signals, and it extracts rather than decides. A person reviews before anything acts on it, and anything ambiguous goes to that review instead of into the record.

Commercial data context

NGX connects invoices, commitments, renewals, vendor records, and contract context so financial and operational users can work from the same facts.

A record is only useful if you trust how it was built.

Security questions about a platform are usually about storage and access. An advisory relationship raises a different set, and they deserve direct answers.

Separation between clients

Each client's record is its own tenant, and access is scoped to it. There is no automatic disclosure of one client's information to another, and no client's commercial terms are surfaced to another client as a comparison point.

Who can see your information

Your team, and the NarrowGateX people working on your engagement.

Evidence provenance

Every fact carries the document it came from and a grade describing how well it is supported. That is what lets you audit the record rather than trust it, and it is the same mechanism that makes an unverified figure visible instead of quiet.

What the AI workers cannot do

Each worker states a limit publicly. None of them approves, commits, sends or decides. Supplier messages are blocked until a person approves the draft, which is enforced in the platform rather than promised in a policy.

Market information

Market evidence is gathered through legitimate sourcing and research activity, and each observation carries its source and the date it was seen. Client-confidential information is not repurposed as market evidence for someone else.

Provider compensation

NarrowGateX holds relationships across the technology market, and where compensation from a provider applies to a transaction it is disclosed to the client. Provider economics never determine a NarrowGateX recommendation.

Who answers for the recommendation

A platform cannot be accountable and an AI worker cannot be asked why. A named NarrowGateX advisor develops the recommendation, states what it rests on and what was rejected, and takes the question when someone senior pushes back on it. That is the part of this relationship that a control document cannot cover, and it is usually the part that matters most.

The first security conversation should be specific.

The right review depends on what you plan to load, who needs access, and how NGX will support decisions and execution.

What documents and records will be loaded into NGX?

Who needs access across IT, finance, procurement, sourcing, leadership, and advisors?

Which workflows require audit trails, approval visibility, or executive reporting?

Which AI-assisted extraction use cases need human review before action?

Which systems remain source systems, and where should NGX become the operating layer?

What retention, deletion, backup, and export expectations need to be documented before launch?