Evidence
Where proof lives: the evidence vault for artifacts and policies for governing documents.
Evidence is what an auditor reads to believe a control operates. In Noru it comes in two shapes: artifacts in the evidence vault, uploaded by you or synced from data sources, and policies, the governing documents you write, version, and approve. Both link to controls, and both count toward coverage.
Evidence vault
Upload, import, validate, filter, and inspect evidence, and see how automatic evidence arrives.
Policies
Create policies by hand, from a template, with AI, or from Confluence; approve them and download the master list.
Policy editor
Edit content, manage versions and review cadence, link controls, and act on Cortex change proposals.
Control detail
Where evidence and policies get linked to the controls they satisfy.
Two kinds of proof
A policy says what should happen; an evidence item shows that it did. A control that requires a policy is satisfied by an approved policy linked to it; a control that requires a configuration screenshot, a log export, or a synced setting is satisfied by a valid evidence item in the right slot.
Popular tasks
- Upload a file and link it to a control in the same dialog
- Check an evidence item has not changed since capture
- Import documents detected by a document integration
- Create a policy with AI from your organization context
- Approve policies in bulk
- Create a new draft of an approved policy
- Apply a Cortex change proposal
- Download the master document list for an auditor
Last updated on