Noru

The Intelligent Compliance Platform

Privacy.Automated.

Data discovery and compliance controlsfor GDPR Article 30 — automated.

Privacy/Data map
Live
Systems
Datasets
Processing activities
Purposes
Data categories
Data subjects
Customer onboarding & KYCProcessing activityLegal basisLegal obligationRetention5 years

Trusted by security and privacy minded organizations across the world

Privacy automation

Privacy records thatmaintain themselves.

AI agents continuously monitor every system that handles personal data and read the actual evidence in full, not human interpretation or memory. Always accurate. Always up to date.

Learn more
Privacy/Scan
Live
  1. Commit scanned

    payments-api · 148 files read

    + customers.national_id

  2. Field classified

    National identifier · personnummer

  3. Record updated

    Art. 30 register updated automatically

  4. Transfer flagged

    New sub-processor outside the EEA · Ch. V

Privacy compliance,operationalized.

Privacy guardrails run inside the development workflow. When a change introduces sensitive data or a transfer abroad, the right assessment fires on its own.

Learn more
Privacy/Assessments
3 need review

DPIA triggered

Customer onboarding & KYC · customers.national_id

Review

Cross-border transfer detected

Marketing communications → US ad platform

Review

Legal basis suggested

Drafted by AI · Contract — Art. 6(1)(b) · retention 7 yrs

AcceptDismiss

Safeguard accepted

SCCs recorded · Maja Lindqvist

Accepted · 1 h ago

All in one shared overview.

A single source of truth for legal and tech alike: each data field maps into a shared standard, and a dynamic map of your systems shows what is used, where it is and why.

Learn more
Privacy/Data map
Live
Systems
Activities
Purposes
Categories
Customer onboarding & KYCProcessing activityLegal basisLegal obligationRetention5 years

How to get going

Set it up once. Then it’s running.

01

Connect Noru to your systems

Noru's agents plugs into your codebase and automatically maps where personal data lives.

02

Complete the mapping

Once your systems are mapped, your legal team fills in the gaps — purpose, lawful basis and retention.

03

Data map is live

You have an accurate RoPA that updates itself when your systems change, and flags what needs your attention.

Integrations

Built on your data sources.

Connect the systems you already run. Data stays fresh, with real-time security insights—not on a quarterly scramble.

  • Amazon Web ServicesAWS
  • CloudflareCloudflare
  • ConfluenceConfluence
  • DatabricksDatabricks
  • DatadogDatadog
  • DetectifyDetectify
  • GitHubGitHub
  • GitLabGitLab
  • Google Cloud PlatformGCP
  • Google DriveGoogle Drive
  • Google WorkspaceGoogle
  • HaileyHRHaileyHR
  • JungleMap (NanoLearning)JungleMap
  • LinearLinear
  • MicrosoftMicrosoft
  • Neo4j AuraNeo4j
  • NeonNeon
  • SupabaseSupabase
  • VercelVercel

Security

Built for enterprise requirements.

The assurances procurement and security teams look for — EU data residency, strong encryption, fine-grained access control, full subprocessor transparency, and an AI platform that never trains on your data — in place from day one.

EU data residency

Your data is stored and processed in the EU, on European cloud infrastructure and squarely under EU data-protection law.

AES-256 encryption

Encrypted in transit and at rest, with integration credentials sealed using AES-256-GCM and decrypted only at the moment they're used — never sitting in the clear.

Role-based access control

Granular, role-based permissions across your org and teams, so every person sees exactly what they should — and nothing they shouldn't.

Subprocessor transparency

Every subprocessor we rely on is published and kept current on your trust center — so you can see who touches your data before you ever sign.

We never train on your data

Your controls, evidence, policies and prompts are never used to train, fine-tune or evaluate a model — ours or a provider's. It's in the Terms and the DPA, not buried in a settings toggle.

Zero data retention

Every AI feature runs under zero data retention terms with its model provider. Prompts and outputs live long enough to answer you and no longer — nothing stored, nothing reviewed, nothing kept for training.

FAQ

Noru questions answered

Talk to us

What is Noru?

Noru is an enterprise trust platform. It connects to the systems you already run, keeps your risk, evidence, privacy records and vendors continuously current, and turns them into live proof for the customers, board members and regulators who need to believe you — not a PDF from last quarter. Trust your company can prove, continuously.

Which frameworks does Noru support?

Whatever your buyers and regulators ask for. Noru ships with ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, NIS2, DORA, NIST CSF, CIS v8, FedRAMP and 30+ frameworks in total — and because controls are mapped once and reused, adding the next standard reuses the evidence you already collect instead of starting a new program.

What are Noru's packaged solutions?

Solutions bundle the platform's modules around a concrete outcome. Agentic Compliance puts AI agents to work running your program across every system. Privacy Automation derives records of processing from the systems that hold the data. Regulatory Compliance covers the frameworks incumbents skip — DORA, NIS2, CRA and Nordic sector regulators. AI Governance runs ISO 42001 and NIST AI RMF. Third-Party Risk Management scores vendors by real data access, and Risk Management keeps a live register fed by your systems.

What does Noru integrate with?

Noru integrates with AWS, GCP, Microsoft Azure, GitHub, GitLab, Entra ID, Google Workspace, Databricks, Slack, Linear, and more, turning their signals into continuous, mapped evidence. AI clients such as Claude, ChatGPT, Cursor, and Perplexity can also query your live compliance program over the Model Context Protocol (MCP).

Do we need to replace our existing tools?

No. Noru sits on top of the systems your teams already use — cloud, identity, code, and collaboration tools — and turns their signals into mapped evidence. There is nothing to migrate and no parallel process to maintain.

Do you train AI models on our data?

No — never. Your controls, evidence, policies, privacy records and prompts are never used to train, fine-tune or evaluate any model, ours or a provider's. Every AI feature also runs under zero data retention terms, so the model provider processes your prompt to return the answer and keeps nothing afterwards: nothing stored, nothing queued for human review, nothing reused. Both commitments are contractual — Section 4.6 of the Terms and Sections 3.5–3.6 of the DPA — not a setting you have to find and switch off.

How do we get started?

Book a demo and we'll walk through the platform against your frameworks and use cases — the packages you'd licence, the systems we'd connect, and what a rollout looks like. You'll leave with a concrete plan or a clear no-fit.

The Intelligent Compliance Platform

See it running in your organisation.