Government and defense engineering teams rely on nTop for computational design and analysis. The same security foundation and data-handling practices that protect every nTop customer apply to public-sector work. Here's what that looks like.
Data handling and network requirements
nTop is a desktop application. It runs locally and stores all user-generated design files (CAD imports, exports, and models built in nTop) on the user's own computer. Design data is never transferred to nTop's cloud services.
A limited set of other data does move between the desktop app and nTop's cloud, depending on license type and user settings:
| Data type | Required? | What it includes | Sent to |
|---|---|---|---|
| License Authentication | Required for cloud-authenticated licenses | User email and encrypted password, product name, session start/end times, device fingerprint ID, device OS, geo-hash based on IP address | app.ntop.com |
| Version Data | Required | Current software version (to check for and deliver updates) | updater.ntop.com |
| Anonymous Usage Data | Required | Organization name, system information (CPU, GPU, OS, software version, device type/ID), crash reports, feature usage | analytics.ntop.com, crashes.ntop.com |
| Personalized Usage Data | Optional | User first name, last name, and email, appended to the required data above, for personalized support and individualized usage reporting | analytics.ntop.com |
For this data to transfer, the user needs an active internet connection, and an organization's firewall can't be blocking app.ntop.com, updater.ntop.com, analytics.ntop.com, and crashes.ntop.com. Personalized Usage Data can be turned off during installation or later via File > Settings. IT administrators whose organization needs to disable the required data transfers can reach out to nTop Support directly.
Data hosting and infrastructure
nTop's infrastructure and data are hosted on Google Cloud Platform (GCP), following GCP's security best practices. Infrastructure spans multiple GCP availability zones, so systems keep running if one zone fails. See GCP regional clusters for more. In the event of a catastrophic outage, nTop is designed to support extended offline access without interruption.
Encryption
REST communications use SSL/TLS. Sensitive data such as tokens and credentials is salted and encrypted in our database, and any of that data cached locally (like license information or access tokens) is encrypted at rest. User credentials are salted and encrypted using BCrypt. No nTop staff member can view or decrypt a password once it's created.
Access control
Only authorized nTop staff can access customer data, granted strictly on a need-to-know basis and routinely audited. During support issues, we ask for permission before accessing customer data, except when investigating a security incident or suspected abuse, and even then we access only the minimum information needed to resolve the issue.
Employees with administrative access to our GCP instance are required to have two-factor authentication enabled. End users can also enable two-factor authentication when logging into their nTop dashboard at app.ntop.com.
Incident response
nTop maintains an Incident Response Policy covering escalation procedures, rapid mitigation, and post-incident review, and all employees are informed of it.
Personnel security
- Employee vetting. New hires go through background checks in accordance with local laws, including employment verification and criminal checks for US employees.
- Confidentiality. Every employee contract includes a confidentiality agreement.
- Training. All employees complete security awareness training annually.
- Policies. nTop maintains a comprehensive set of security policies, updated regularly and shared company-wide.
Physical security
nTop's offices use code-based entry and badge-only access to work areas. Server infrastructure is restricted to IT personnel and a small number of key individuals, with badge access logged and hallways/server room under video monitoring.
Reporting a security issue
If you discover a security concern, email us at security@ntop.com. We treat security correspondence and vulnerability reports as a top priority and work with researchers acting in good faith toward user privacy and data.