NG-Key
NG-Key
Secure Mobile Enrollment and Access Control
Security Area

NG-Key Security Overview

A public security overview for NG-Key access control, aligned to ISO/IEC 27001:2022 control themes across identity, operations, traceability, and governance.

Security Principles

Access-control security depends on platform security across identity, runtime, delivery, and the final access decision.

NG-Key is designed for access control, so the security model starts with strong identity, tenant boundaries, protected key handling, and verifiable event history.

This page summarizes the most important security themes, including tenant boundaries, passkey-ready identity, ledger traceability, and operational governance.

Platform Security Foundation

Privileged administration, secret storage, protected transport, runtime segmentation, and operational visibility create the baseline on which secure access control depends.

Credentials and Media Technologies

Passkeys with FIDO2 and WebAuthn capable flows support stronger authentication than reusable shared secrets and help bind access to real user devices.

Deployment Quality and Rollout Security

Production delivery is stronger when every rollout passes repeatable pre-production validation before promotion.

Ledger-Backed Traceability

Access audits, permission changes, and related commercial or handover events gain stronger accountability when canonical events, hashes, and verification trails remain inspectable.

Security Visualization

A concise visual for platform security, delivery quality, and traceability.

The security overview combines authentication, tenant isolation, protected transport, controlled release, and traceable records into one due-diligence narrative.

It complements the detailed written sections below and the downloadable security whitepaper for deeper technical review.

Security Overview Visual
NG-Key Security Visualization

The visual highlights the relationship between strong authentication, secure delivery, and ledger-backed visibility in the NG-Key platform.

Important Security Points
  • Use explicit role ownership and least-privilege administration instead of informal shared access or long-lived broad permissions.
  • Use passkeys and FIDO2 or WebAuthn capable credential flows where stronger user-device binding is required, and keep enrollment and ownership review explicit.
  • Where physical media is used, keep card or transponder assignments reviewable and consistent across reader scope, including DESFire-linked identifiers where supported by the deployment path.
  • Protect client, platform, broker, and service traffic with HTTPS, TLS, or equivalent encrypted transport controls wherever the deployment path allows it, and keep end-to-end encryption enabled where the full path supports it.
  • Keep sensitive integration secrets and stored keys encrypted at rest and handled only through authorized operational processes.
  • Keep critical database and service traffic on protected network paths and segmented runtime boundaries, and keep production secrets on target hosts or equivalent protected secret stores.
  • Run production delivery through controlled change management with documented checks before runtime promotion.
  • Use audit history, telemetry, blockchain-backed ledger events, and commercial event traces together because security-relevant anomalies often surface first as operational or fulfillment irregularities.