Data handling and network requirements
nTop is a desktop application. It runs locally and stores all user-generated design files (CAD imports, exports, and models built in nTop) on the user’s own computer. Design data is never transferred to nTop’s cloud services. A limited set of other data does move between the desktop app and nTop’s cloud, depending on license type and user settings:
For this data to transfer, the user needs an active internet connection, and an organization’s firewall can’t be blocking app.ntop.com, updater.ntop.com, analytics.ntop.com, and crashes.ntop.com. Personalized Usage Data can be turned off during installation or later via File > Settings. IT administrators whose organization needs to disable the required data transfers can reach out to nTop Support directly.
Data hosting and infrastructure
nTop’s infrastructure and data are hosted on Google Cloud Platform (GCP), following GCP’s security best practices. Infrastructure spans multiple GCP availability zones, so systems keep running if one zone fails. See GCP regional clusters for more. In the event of a catastrophic outage, nTop is designed to support extended offline access without interruption.Encryption
REST communications use SSL/TLS. Sensitive data such as tokens and credentials is salted and encrypted in our database, and any of that data cached locally (like license information or access tokens) is encrypted at rest. User credentials are salted and encrypted using BCrypt. No nTop staff member can view or decrypt a password once it’s created.Access control
Only authorized nTop staff can access customer data, granted strictly on a need-to-know basis and routinely audited. During support issues, we ask for permission before accessing customer data, except when investigating a security incident or suspected abuse, and even then we access only the minimum information needed to resolve the issue. Employees with administrative access to our GCP instance are required to have two-factor authentication enabled. End users can also enable two-factor authentication when logging into their nTop dashboard at app.ntop.com.Incident response
nTop maintains an Incident Response Policy covering escalation procedures, rapid mitigation, and post-incident review, and all employees are informed of it.Personnel security
- Employee vetting. New hires go through background checks in accordance with local laws, including employment verification and criminal checks for US employees.
- Confidentiality. Every employee contract includes a confidentiality agreement.
- Training. All employees complete security awareness training annually.
- Policies. nTop maintains a comprehensive set of security policies, updated regularly and shared company-wide.

