SECURITY
Security
NWX Invest holds information that matters: who you are, what you hold, and how to reach you. This page explains where that information lives, who inside NWX can reach it, and what we do to keep anyone else out. No system is completely secure and no method of transmission or storage can be guaranteed: the controls below reduce risk, they do not eliminate it. It also covers the part we cannot do without you — recognising a message that is pretending to be us — because in private markets that is where the losses actually happen.
Effective August 2026
Where the platform runs
The NWX Invest platform and this website run on Google Cloud, in a project dedicated to NWX Invest and kept separate from every other entity in the group. Google Cloud maintains independent certifications for the infrastructure it operates, including ISO/IEC 27001 and SOC 2. Those certifications are Google's and cover the infrastructure layer. They are not certifications of NWX Invest, and we do not present them as ours. What is ours is everything built on top: how accounts are created, who may see what, and which actions one person is allowed to complete alone.
Encryption
Traffic between your browser and NWX Invest is encrypted in transit using TLS; the padlock in your address bar is the visible part of it. Information held in our systems is encrypted at rest by the underlying Google Cloud services. Passwords are never stored in a form anyone can read, including us — what we hold is a one-way hash, which is why a password can be reset but never retrieved. Anyone who offers to read your password back to you does not work here.
Who can see what
Investor records are visible only to the NWX personnel whose work requires them, and access is granted by role rather than on request. Administrative actions are logged with the account that performed them and the time, so any change to a record can be traced to a person afterwards. Access is reviewed when a role changes and removed when someone leaves. This is the least interesting control on the page and the one that does the most work: most data losses are not break-ins, they are accounts nobody remembered to close.
Two people, not one
Changes that affect an investor's position or a fund's reported figures go through an approvals queue in which the approver cannot be the person who initiated the change — an administrator's account included. Direct database access is restricted to a small number of named engineers, is logged, and is not a route by which investor-facing records are changed in the ordinary course. The same two-person rule governs any request that would move money: prepared by one person, released by another. A control that one convinced employee can satisfy is not a control. It is a single point of failure with a policy attached to it.
People, not only software
NWX uses AI to organise research, summarise documents and support service work. It does not approve transactions, move money, change an investor's record or send investor communications on its own. Each of those has a named person accountable for it, and that does not change as the tooling improves. This belongs on a security page rather than a technology page: software that acts on what it reads is an exposure before it is a feature, because what it reads can be written by someone else.
What NWX will never ask you for
We will never ask for your password, and nobody here has a reason to know it. We will never send you new or changed wire instructions by email. We will never ask you to act on payment instructions urgently, discreetly, or before a deadline that appears in the message itself. We will never ask you to move funds to a "safe" or "holding" account, and we will never ask you to read back a one-time verification code. A message that does any of these did not come from us, however convincing the logo, the signature or the sender name looks.
Checking that a message is really from us
Stop before you act, not after. Payment instructions are confirmed by voice, on a number you already have — one you have used before, or one taken from this website — never a number printed in the message asking you to call. Treat any change of bank details as suspicious by default: it is the single most common way money is lost in private markets, and a genuine change survives a phone call while a fraudulent one does not. Read the sender's full address rather than the display name, and be sceptical of urgency, secrecy, and anything that arrives outside the process we have already used with you.
Protecting your own account
Use a password you do not use anywhere else, ideally generated and kept by a password manager rather than remembered. Multi-factor authentication is on our roadmap for the investor portal and is not yet available; until it is, the strength and uniqueness of that password is what protects your account, which is why it should not be a password you use anywhere else. Keep the email address on your account current — it is how we reach you and how recovery works. Lock the devices you use to reach the portal, and avoid signing in over public Wi-Fi.
Telling us something looks wrong
If you think your account has been compromised, if you have received a message that misuses the NWX name, or if you have already acted on one, write to info@nwxinvest.com with the details and any headers or screenshots you still have. If money may have moved, call as well as write: the first hours matter more than anything else, and a payment that has only just left can sometimes still be recalled. Nobody here will be irritated by a false alarm. We would rather look at ten of them than miss one real event.
Where security ends and privacy begins
This page is about protecting information. Which information we collect, why, how long we keep it and who else receives it is a different question, answered in the Privacy Policy. What this website is and is not offering you is answered in the Important Notice.