Documentation

Set up, operate, and understand Noru: step-by-step guides, technical deep dives, connector references, and developer access.

These are the product docs for the Noru app. They tell you where every page is, what each button does, and how the numbers on screen are computed. Start with the guides if you are new; go under the hood when you need to know why something happened.

New to Noru?

Follow Getting started: sign in, create your organization, choose frameworks, invite your team, and connect a first data source. The first week checklist takes it from there.

How the product fits together

  1. Settings and frameworks define organizational context and the requirement sets in scope.
  2. Data sources collect system facts, evidence, assets, identities, findings, and privacy signals on a schedule.
  3. Personnel, assets, vendors, and the privacy data map describe the people, technology, third parties, and data processing inside that scope.
  4. Controls, policies, risks, findings, and assessments record what should happen, what can go wrong, what was observed, and how you respond.
  5. Tasks, training, internal audit, and review queues turn those records into owned work.
  6. Evidence, reports, audit packages, and the trust center communicate the resulting posture.

Data model and operating model explains how these records relate and what is derived from what.

What Noru does not do

Noru structures compliance work and evidence. It does not make legal, audit, or risk decisions for you, it does not make an unsupported system compliant by connecting it, and it does not guarantee an audit outcome without truthful scope, maintained evidence, and operating controls. Derived and AI-assisted records must be reviewed against your real systems and obligations.

Last updated on