Built like a bank. Hosted like one too.
An identity-governance platform has to hold itself to its own standard. NDGM runs on single-tenant, dedicated infrastructure in the UK — one compute boundary, your data, our hardware. Here's exactly how it's built.
One compute boundary
Traffic enters through Cloudflare for TLS and DDoS protection, then terminates on dedicated NDGM hardware. There is no shared multi-tenant cloud plane — your estate's data lives on infrastructure scoped to NDGM, in the UK.
Crucially, the AI runs on the same boundary — a locally-hosted model on our own GPU. No customer data is sent to a third-party AI provider, ever.
Every database query is scoped to a single org_id by Postgres row-level security. Isolation is enforced at the data layer, not in application code.
super_admin, org_admin, reviewer, auditor and viewer. Each role sees and does exactly what its mandate allows — auditors read, they don't change.
No state changes without a record. Every write emits a matching audit event — actor, target, timestamp and metadata.
Every governance decision writes two records at once — a checksummed evidence item and an immutable audit event. Tamper-evident by construction, reproducible at audit time.
Reeve's reasoning runs on open models (Mistral Small, Phi‑4) served via Ollama, hosted on our own GPU. There is no OpenAI, Anthropic or Google in the loop. Every model interaction is token-attributed through OpenTelemetry, and decision reasoning chains are stored so each recommendation is explainable.
We publish our real status, not aspirational badges. Here's where each control and framework actually stands.
Found something? Tell us.
Report security issues to [email protected]. We acknowledge within one business day, aim to patch critical issues within seven days, and will credit you if you'd like. A PGP key is coming; there's no formal bounty yet, but we reward meaningful reports case by case.
A machine-readable /.well-known/security.txt (RFC 9116) is published.
Questions for our security team?
We're happy to walk your auditors and risk team through the architecture, the evidence model and our subprocessors.