Trust and Security
Governance software should be governed too.
Norivo applies security, privacy and AI governance controls across the platform and across our own use of AI. Here is how.
Norivo Technologies Ltd is registered in England and Wales. Customer data is processed in accordance with UK GDPR and, where applicable, the EU GDPR. A Data Processing Agreement is available to customers.
Platform controls
Data hosting and residency
Norivo's primary database is configured in EU regions. Some processing is carried out by sub-processors headquartered outside the UK and EEA. Appropriate contractual transfer mechanisms are used where required. The table below identifies each provider, its purpose and its processing location so customers can assess transfers against their own requirements.Encryption
Customer data is encrypted in transit and at rest using the security controls of Norivo's infrastructure providers.Identity and access
Authentication is provided by Clerk, with multi-factor authentication available, session management and role-based access control. Norivo does not store customer passwords. Administrative routes are gated by role.Tenant isolation
Organisation-scoped access controls enforce tenant separation. Application access is limited to the requesting customer's authorised organisational context.Backups and resilience
Automated backups and point-in-time recovery are used in line with the active database plan.Monitoring and incident response
Uptime monitoring, error tracking and performance alerting are in place. Incident response procedures are documented.
Processing locations
Sub-processors
| Provider | Purpose | Processing location |
|---|---|---|
| Vercel | Application hosting and edge delivery | EU / US |
| Neon | PostgreSQL database hosting | EU |
| Clerk | Authentication and user management | US |
| Anthropic | AI processing for Nora | US |
| Upstash | Redis caching and job queue | EU |
| Resend | Transactional email | US |
| Stripe | Payment processing | EU / US |
Nora
How Nora uses customer data
Nora accesses only the organisational context required for an authorised request. Self-serve outputs are advisory and reviewed by the customer. Managed outputs are reviewed by Norivo specialists as part of delivery. Nora is registered in Norivo's own AI Systems Registry and governed under VALID.
Audit status
Compliance status
Norivo is not currently certified to SOC 2 or ISO 27001. Norivo will publish audit status on this page once a formal audit programme is engaged. Enterprise prospects can request a security questionnaire and a security review discussion in the meantime.
Security requests
Request the Data Processing Agreement, sub-processor information, security questionnaire responses or a security review discussion through the Contact page.