Documentation
Set up, operate, and understand Noru: step-by-step guides, technical deep dives, connector references, and developer access.
These are the product docs for the Noru app. They tell you where every page is, what each button does, and how the numbers on screen are computed. Start with the guides if you are new; go under the hood when you need to know why something happened.
Guides
Every page in the app, task by task, with screenshots. Start here.
Under the hood
How syncs, evidence, control coverage, jobs, AI, and permissions actually work.
Data sources
Every connector: what it asks for, what it collects, how it syncs, what to do when it breaks.
Developers
API keys, the REST API, and connecting AI clients over MCP.
Reference
Roles, statuses, frameworks, the page map, and a glossary.
New to Noru?
Follow Getting started: sign in, create your organization, choose frameworks, invite your team, and connect a first data source. The first week checklist takes it from there.
Popular tasks
- Connect GitHub so repository and access evidence collects on its own
- Invite a team member and pick the right role
- Upload evidence and link it to a control
- Mark a control implemented and see why coverage matters
- Publish your trust page and put it on your own domain
- Set up Cursor or Claude with MCP to query your program from an AI client
- Run an internal audit and export the report
How the product fits together
- Settings and frameworks define organizational context and the requirement sets in scope.
- Data sources collect system facts, evidence, assets, identities, findings, and privacy signals on a schedule.
- Personnel, assets, vendors, and the privacy data map describe the people, technology, third parties, and data processing inside that scope.
- Controls, policies, risks, findings, and assessments record what should happen, what can go wrong, what was observed, and how you respond.
- Tasks, training, internal audit, and review queues turn those records into owned work.
- Evidence, reports, audit packages, and the trust center communicate the resulting posture.
Data model and operating model explains how these records relate and what is derived from what.
What Noru does not do
Noru structures compliance work and evidence. It does not make legal, audit, or risk decisions for you, it does not make an unsupported system compliant by connecting it, and it does not guarantee an audit outcome without truthful scope, maintained evidence, and operating controls. Derived and AI-assisted records must be reviewed against your real systems and obligations.
Last updated on