Access control is only as strong as the platform security beneath it, from authentication and transport to deployment quality and the final access result.
NG-Key is built for access control, so the security model begins with platform security: strong user authentication, protected credential handling, encrypted and integrity-protected communication paths, verifiable access outcomes, tightly controlled privileged administration, and disciplined production delivery.
The goal is not a single isolated control. The goal is a managed control chain across identity, decisioning, communication paths, release governance, and evidence.
Privileged administration, secret handling, protected transport, runtime segmentation, and operational visibility provide the baseline on which secure access control depends.
Passkeys with FIDO2 and WebAuthn capable flows support stronger authentication than reusable shared secrets and help bind access to real user devices.
NG-Key supports deployments that combine modern public-key credentials with reader hardware for LEGIC and MIFARE-class environments, and the current credential path can carry DESFire-linked identifiers where physical media is part of the rollout.
Canonical events, hashes, signatures, and blockchain-backed verification trails strengthen the inspectability of access audits, permission changes, and related high-impact events.
Key Controls and Design Principles
Use passkeys and FIDO2 or WebAuthn capable flows, verified enrollment paths, and explicit account ownership to reduce weak authentication exposure.
Protect traffic with HTTPS, TLS, or equivalent encrypted transport controls, keep stored secrets encrypted at rest, and keep end-to-end encryption enabled where the dependent path supports it.
Stronger production security starts before runtime with change management, pre-production validation, and controlled promotion into production.
Keep access events, provisioning changes, privileged actions, and order-related handover or fulfillment events traceable so investigations and compliance reviews have usable context across operational and commercial flows.
- Where a dependent client, reader, or integration path supports end-to-end encryption, it should remain enabled and verifiable. Where that is not available, each hop should still be protected with HTTPS, TLS, or equivalent encrypted transport controls.
- Restrict identity integration settings, broker credentials, and reader-specific secrets to authorized roles and review them periodically, and keep sensitive settings encrypted at rest.
- Keep production secrets on target hosts or equivalent protected secret stores and out of exports, screenshots, and unmanaged channels.
- Use delivery pipelines that enforce pre-production validation and release readiness checks before production deployment.
- Review monitoring, alerts, ledger failures, and operational signals as part of security operations because degraded runtime behavior can become a security event.
- Use explicit ownership, invitation hygiene, disciplined offboarding, and reviewable card or transponder assignment flows so dormant privileged or credential access does not accumulate over time.
How NG-Key supports information security management preparation
This document does not state or imply ISO/IEC 27001 certification for NG-Key. It explains how the platform scope, controls, and evidence surfaces are structured to support customer assurance, supplier review, and the operator's own information security management preparation.
- Governance and change management (A.5, A.8.32): tenant-scoped administration, least-privilege roles, separation between customer and partner surfaces, and controlled promotion of production releases.
- Identity and access (A.5.15, A.8.2, A.8.5): passkeys and WebAuthn-capable authentication, explicit credential ownership, reviewable enrollment and offboarding, and access decisions tied to auditable identities and reader scope.
- Operations and monitoring (A.8.9, A.8.15, A.8.16): encrypted secret handling, protected transport, runtime segmentation, operational telemetry, and review of alerts, ledger integrity, and anomalous access or fulfillment patterns.
- Evidence and traceability (A.8.15, A.5.28): canonical access and administration events, permission changes, provisioning activity, and high-impact commercial or handover events, supported by verifiable ledger trails where enabled.
- Customers remain responsible for endpoint hygiene, local policies, physical site controls, credentials in their own estate, integration configuration in their environment, and contractual scope for subprocessors and data locations.
Security remains strongest when platform controls, delivery discipline, and customer operations work together.
NG-Key provides platform controls for strong authentication, encrypted secret storage, protected transport options, credential and media handling, audit visibility, ledger-backed evidence, and traceable access decisions. Customers and partners still need disciplined identity governance, endpoint hygiene, approval workflows, ordering controls, and operational review around who receives access and who keeps administrative responsibility.
That shared-responsibility model is strongest when it stays explicit: technical safeguards, validated delivery, runtime visibility, and accountable operating practice reinforce each other instead of leaving gaps between teams.