Under the hood
How Noru computes, syncs, stores, and secures what you see.
These pages explain the engines behind the screens: where a number comes from, what changed a record, and why a status changed when nobody clicked anything. Read them when a guide tells you what happened and you need to know why, or when an auditor asks how a figure is derived.
Every page has the same shape: a three-bullet summary, the concepts involved, how it works (the rules, the thresholds, and what triggers a change), the failure modes, and what you can change yourself.
Data model and operating model
Organizations, segments, records, and how the modules connect.
Sync model and job scheduler
How integrations sync, retry, and fail, and how background jobs run.
Evidence lifecycle and integrity
Automatic and manual evidence, qualification, and the attestation hash chain.
Control status and coverage
How coverage is computed and when a control changes status on its own.
Policy versioning and acknowledgements
Version bumps, policy logs, review reminders, and attestation links.
Risk scoring and reports
Likelihood, impact, residual risk, generated risks, and report snapshots.
Vendor risk and questionnaire AI
Vendor risk sweeps, document gathering, and AI-assisted questionnaire review.
Privacy scanner and drift
What the scanner observes, how findings map to obligations, and how drift is detected.
AI and Cortex
Models, data handling, tool permissions, and what AI can and cannot change.
RBAC and security model
Roles, capabilities, org MFA, API keys, OAuth, and where authorization is enforced.
Notifications and email
Notification types, live delivery, email templates, and user preferences.
Written from the current release, not from the roadmap
Each page describes what the product does today, at the depth a security reviewer or auditor needs: behaviour, thresholds, and boundaries rather than implementation. Where older material and the product disagree, the product wins. If you need a statement verified for an audit, ask your Noru contact.
Popular tasks
- Why a control flipped to Pending review on its own
- Why a data source says Needs reauthentication instead of retrying
- What makes an uploaded file count toward coverage
- When a policy version number changes, and when it does not
- How a risk level is derived from likelihood and impact
- What runs on its own, and roughly how often
- How to prove an evidence file has not changed since capture
Last updated on