Skip to content

Trust Centre

Security in specifics, not slogans.

You’re trusting N Six Hub with the operating record of your business. Here is how that trust is engineered — concretely, and without the phrase “military-grade” anywhere.

The architecture

How your data is protected

Tenant isolation

Every record is bound to your organisation at the data layer. Isolation is enforced in code and continuously verified by adversarial cross-tenant tests.

Encryption

Data is encrypted in transit; sensitive stored fields — statutory identifiers, third-party credentials — carry additional field-level encryption at rest.

Authentication & permissions

Role- and permission-scoped access down to modules and sensitive fields, with permission changes taking effect immediately.

Audit trail

Consequential actions — data changes, credential use, migrations, financial events — are written to an audit log your administrators can inspect.

AI boundaries

AI acts within the asking user’s permissions; prompts are screened so credentials and secrets never reach model providers; injected instructions inside your data are treated as data.

Migration safety

Migrations are read-only against your source, SSRF-screened, malware-scan uploaded files, and reversible by provenance — never a blind timestamp sweep.

Operations

Run like it matters

Backups & continuity

Your data is backed up on a defined schedule with tested restoration paths.

Monitoring

Platform health, queues and error rates are monitored, with alerting to the team.

Responsible disclosure

Found something? Contact security@nsixhub.com — we take reports seriously and respond.

Questions

Security FAQs

Is our company’s data separate from other subscribers?+

Yes. Every record is scoped to your organisation at the data layer, and cross-tenant isolation is part of our permanent adversarial test suite — we actively test that one organisation can never read another’s data.

Can AI features see everything?+

No. The AI Assistant acts as the asking user, inside that user’s permissions, and its actions are logged. AI is a way to use your access faster — never a way around it.

What happens to migration credentials?+

Source-platform keys are stored encrypted, excluded from ordinary queries, never written to logs, and never passed to AI providers. Migrations are read-only against your source, and outbound requests are screened so they can only reach the host you configured.

Is our data used to train AI models?+

No — workspace data is not used to train third-party foundation models.

Which certifications do you hold?+

We publish certifications here only when they are actually obtained — no borrowed badges. Ask us for our current security documentation for procurement reviews.

Trust is built in specifics.

Enterprise procurement? We’ll walk your security team through the architecture directly.