Security & Compliance

Your data never leaves NetSuite

NSGPT runs live SuiteQL directly against your NetSuite instance — read-only, in real time. No ETL, no replication, no shadow copy of your ledger to secure. The most defensible security posture is the one where your data simply stays put.

Request a Demo

Your NetSuite Data

Read-Only SuiteQL

In-Session Analysis

Insight Returned

Read-only

NSGPT queries your data but never modifies it

Zero replication

No copy leaves your NetSuite instance

Real-time

Direct queries, never a stale extract

Certifications

Independently certified

NSGPT holds the certifications enterprise procurement and security teams require — verified by independent auditors, not self-attested.

SOC 2 Type II

Audited controls for security, availability, and confidentiality.

ISO 27001

Certified information security management system.

GDPR

EU data protection built in by design.

Architecture

Secure by architecture

Security you can verify in the design, not just the policy. Every layer is built so your financial data stays inside NetSuite.

Direct SuiteQL queries

Agents run read-only SuiteQL directly against your live NetSuite instance — the same data model, in real time.

No staging database

There is no NSGPT copy of your ledger. No ETL, no data warehouse, no nightly sync to breach.

Read-only access

Access is scoped to read-only at the NetSuite API permission level. NSGPT queries and analyzes, never writes back.

Sandboxed execution

All Python analysis runs inside a RestrictedPython sandbox, isolated from the host and network.

Row-level isolation

PostgreSQL-enforced row-level security keeps every organization's workspace strictly separated.

Encrypted credentials

Connection credentials are encrypted at rest with AES-256 and never exposed to agents or logs.

Governance

Humans stay in control

Autonomy with oversight. Every agent operates inside guardrails your team defines and can audit.

Approval gates

Sensitive actions pause for human sign-off before anything executes.

Full audit trails

Every query, agent action, and data access is logged with timestamp, user, and context.

RBAC & SSO

Role-based permissions map to your org and project hierarchy, with SAML and OAuth single sign-on.

Financial Controls

Security that strengthens your controls

NSGPT does more than protect your data — its risk and audit playbooks continuously test the controls inside it.

Fraud pattern detection

Benford's Law analysis, duplicate-payment scanning, and round-number anomaly flags across your ledger.

Segregation of duties

Flags creator-equals-approver violations and after-hours or weekend transaction activity.

Compliance validation

Continuous internal-control testing and gap analysis mapped to SOX and audit frameworks.

For Procurement & Security Teams

Questions, answered

Does NSGPT store or replicate my NetSuite data?

No. Read-only SuiteQL runs against your live NetSuite instance. Nothing is copied, replicated, or warehoused outside your environment.

Can NSGPT modify my NetSuite data?

No. All access is read-only, scoped at the NetSuite API permission level. NSGPT queries and analyzes but never writes back.

Are you SOC 2 and ISO 27001 certified?

Yes. NSGPT holds SOC 2 Type II and ISO 27001 certifications, and follows GDPR data-protection requirements.

How is access controlled?

Role-based permissions at the organization and project level, mapped to your NetSuite roles, with SAML and OAuth single sign-on.

Are AI outputs auditable?

Yes. Every agent action is logged with full context — the query executed, data accessed, analysis performed, and output generated.

How are credentials protected?

Connection credentials are encrypted at rest with AES-256. They are never exposed to agents or included in logs.

Put NSGPT through your security review

We'll walk your security and procurement teams through the architecture, certifications, and controls — and hand over the documentation you need to sign off.