Skip to content
Norivo

Trust and Security

Governance software should be governed too.

Norivo applies security, privacy and AI governance controls across the platform and across our own use of AI. Here is how.

Norivo Technologies Ltd is registered in England and Wales. Customer data is processed in accordance with UK GDPR and, where applicable, the EU GDPR. A Data Processing Agreement is available to customers.

Platform controls

  • Data hosting and residency

    Norivo's primary database is configured in EU regions. Some processing is carried out by sub-processors headquartered outside the UK and EEA. Appropriate contractual transfer mechanisms are used where required. The table below identifies each provider, its purpose and its processing location so customers can assess transfers against their own requirements.
  • Encryption

    Customer data is encrypted in transit and at rest using the security controls of Norivo's infrastructure providers.
  • Identity and access

    Authentication is provided by Clerk, with multi-factor authentication available, session management and role-based access control. Norivo does not store customer passwords. Administrative routes are gated by role.
  • Tenant isolation

    Organisation-scoped access controls enforce tenant separation. Application access is limited to the requesting customer's authorised organisational context.
  • Backups and resilience

    Automated backups and point-in-time recovery are used in line with the active database plan.
  • Monitoring and incident response

    Uptime monitoring, error tracking and performance alerting are in place. Incident response procedures are documented.

Processing locations

Sub-processors

ProviderPurposeProcessing location
VercelApplication hosting and edge deliveryEU / US
NeonPostgreSQL database hostingEU
ClerkAuthentication and user managementUS
AnthropicAI processing for NoraUS
UpstashRedis caching and job queueEU
ResendTransactional emailUS
StripePayment processingEU / US

Nora

How Nora uses customer data

Nora accesses only the organisational context required for an authorised request. Self-serve outputs are advisory and reviewed by the customer. Managed outputs are reviewed by Norivo specialists as part of delivery. Nora is registered in Norivo's own AI Systems Registry and governed under VALID.

Audit status

Compliance status

Norivo is not currently certified to SOC 2 or ISO 27001. Norivo will publish audit status on this page once a formal audit programme is engaged. Enterprise prospects can request a security questionnaire and a security review discussion in the meantime.

Security requests

Request the Data Processing Agreement, sub-processor information, security questionnaire responses or a security review discussion through the Contact page.