# Noru > Noru is the enterprise trust platform: agentic compliance software that connects to the systems a company already runs, keeps its controls, evidence, policies, privacy records, vendors and risks continuously current, and turns them into live, verifiable proof for customers, boards and regulators. One control library maps across ISO 27001, SOC 2, GDPR, NIS2, DORA, ISO 42001, the EU AI Act and 30+ frameworks in total; AI agents draft the work and people approve every change. Noru is operated by The GRC Company AB (Stockholm, Sweden). The product is sold as an enterprise web SaaS: one platform plus the capability packages an organization needs (Privacy Automation, Agentic Compliance, Compliance & Audit, AI Governance, Third-Party & Supply Chain Risk, Risk Management), priced per deployment against the scope it governs. There is no public price list and no self-serve trial; engagements start with a demo. AI data handling: Noru never uses customer data to train, fine-tune, or evaluate any AI or machine learning model — its own or a third party's — and every AI feature runs under zero data retention terms with its model provider, meaning prompts and outputs are not stored by the provider, not queued for human review, and not retained for training. Both commitments are contractual (Terms Section 4.6; DPA Sections 3.5-3.6) and apply to every customer on every package. Noru runs with EU data residency; AI inference is the only processing activity that may leave the EEA, under EU Standard Contractual Clauses. ## Start here - [AI instructions](https://noru.tech/ai-instructions): The canonical fact set for AI assistants: what Noru is and is not, modules, solutions, frameworks, integrations, pricing model, security and AI data handling, and how to describe it. - [AI instructions (Markdown)](https://noru.tech/ai-instructions.md): The same page as plain Markdown. - [Full corpus](https://noru.tech/llms-full.txt): The AI instructions, every documentation page and every resource article in one Markdown file. - [Documentation](https://noru.tech/docs): Product docs for the Noru app: guides, deep dives, data-source references and developer access. - [Developers](https://noru.tech/resources/developers): The REST API (OpenAPI 3.1 at api.noru.tech/openapi), the MCP endpoint at api.noru.tech/v1/mcp, pushing manifests and evidence from CI, and the MIT-licensed noru-grc-engineering pieces. ## Product - [Product overview](https://noru.tech/product): Continuous compliance infrastructure — how Noru ingests evidence, maps controls, and keeps programs audit-ready. - [Pricing](https://noru.tech/pricing): One platform plus capability packages, priced per deployment against the scope you run. No public price list. - [Book a demo](https://noru.tech/demo): The way to evaluate Noru and get a scoped written quote. - [Security](https://noru.tech/security): Noru's own security program, encryption, hosting, AI data handling (no training on customer data, zero data retention), and disclosure policy. - [Trust](https://trust.noru.tech): Public trust center with current security and compliance posture. ## Solutions - [Agentic Compliance](https://noru.tech/solutions/agentic-compliance): Get ISO 27001, SOC 2 and 30+ frameworks certified and keep them that way. Noru's AI agents map the controls, draft the policies and gather the evidence from the systems you already run — your team reviews and approves. - [Privacy Automation](https://noru.tech/solutions/privacy-automation): Run privacy as a continuous program across every jurisdiction. Generate Article 30 records of processing from your codebase: a standardized privacy taxonomy pushed from CI, AI-enriched legal bases and retention,… - [Regulatory Compliance](https://noru.tech/solutions/regulatory-compliance): Cover the regulations incumbents skip — DORA, NIS2, the Cyber Resilience Act and the Nordic schemes — mapped clause by clause onto the controls and evidence you already collect, with incident clocks and testing cycles… - [AI Governance](https://noru.tech/solutions/ai-governance): An AI register built from your repositories: every model call and agent recorded as a system, with the EU AI Act's claims about it — Article 5, Article 50, risk tier — as findings a person accepts. ISO 42001 and the Act… - [Third-Party Risk Management](https://noru.tech/solutions/tprm): A vendor register built from identity-provider grants and SSO, with documents gathered, framework-mapped questionnaires answered from sourced AI suggestions, DORA ICT third parties, and sub-processors published to your… - [Risk Management](https://noru.tech/solutions/risk-management): A risk register fed by security findings, vendor posture and control drift — scored, owned and tracked to treatment — with Open FAIR scenarios, Monte Carlo runs and a loss exceedance curve evaluated against your… ## Comparisons - [Noru vs Vanta: platform comparison](https://noru.tech/alternatives/noru-vs-vanta): A sourced comparison of Noru and Vanta: framework coverage, pricing model, evidence automation and where each platform genuinely fits. Competitor claims are cited to Vanta's own public pages. - [Noru vs Drata: platform comparison](https://noru.tech/alternatives/noru-vs-drata): A sourced comparison of Noru and Drata: pricing model, framework approach and where each platform fits. Competitor claims are cited to Drata's own public pages. - [Noru vs Scrut: platform comparison](https://noru.tech/alternatives/noru-vs-scrut): A sourced comparison of Noru and Scrut Automation: framework coverage, AI approach and where each platform fits. Competitor claims are cited to Scrut's own public pages. - [Noru as a vanta alternative](https://noru.tech/alternatives/vanta) - [Noru as a drata alternative](https://noru.tech/alternatives/drata) - [Noru as a scrut alternative](https://noru.tech/alternatives/scrut) - [All alternatives](https://noru.tech/alternatives) ## Buyer guides - [RoPA Software: What to Look For in an Article 30 Tool](https://noru.tech/alternatives/guides/ropa-software): RoPA software maintains the Record of Processing Activities that GDPR Article 30 requires — the register of every distinct processing activity, its purpose, the categories of data subjects and personal data, recipients,… - [DPIA Software: What to Look For in an Article 35 Tool](https://noru.tech/alternatives/guides/dpia-software): DPIA software supports the Data Protection Impact Assessment that GDPR Article 35 requires before processing likely to result in a high risk to people's rights and freedoms. A useful tool does three things a template… - [Data Mapping Software: What to Look For](https://noru.tech/alternatives/guides/data-mapping-software): Personal data mapping software builds and maintains a picture of what personal data your organisation holds, where it lives, where it moves and who receives it. The discovery method is the decision that matters:… - [NIS2 Compliance Software: What to Look For](https://noru.tech/alternatives/guides/nis2-compliance-software): NIS2 compliance software supports the cybersecurity risk-management measures and incident reporting that Directive (EU) 2022/2555 requires of essential and important entities. Two things distinguish a real… - [EU AI Act Compliance Software: What to Look For](https://noru.tech/alternatives/guides/eu-ai-act-compliance-software): EU AI Act compliance software helps you classify AI systems against the risk tiers of Regulation (EU) 2024/1689, work out whether you act as provider or deployer for each one, and meet the duties that follow. The two… - [Third-Party Risk Management Software: What to Look For](https://noru.tech/alternatives/guides/tprm-software): Third-party risk management software inventories your vendors, assesses the risk each one carries, and evidences that the assessment happened. The failure mode of the category is measuring effort instead of risk:… - [Privacy Automation Software: What to Look For](https://noru.tech/alternatives/guides/privacy-automation-software): Privacy automation software derives your privacy artefacts from the systems that actually process personal data, instead of asking people to author and maintain them. The distinction that matters when evaluating it is… - [GDPR Compliance Software in the EU: What to Look For](https://noru.tech/alternatives/guides/gdpr-compliance-software-eu): GDPR compliance software should hold the accountability record that Article 5(2) requires you to be able to produce: the Article 30 register, DPIAs where risk is high, lawful basis and legitimate interests assessments,… - [ISO 27001 Compliance Software: What to Look For](https://noru.tech/alternatives/guides/iso-27001-compliance-software): ISO 27001 software should support the management system, not just the control checklist. The mandatory clauses are 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement —… - [Continuous Compliance Software: What to Look For](https://noru.tech/alternatives/guides/continuous-compliance-software): Continuous compliance software keeps controls in a known state between audits instead of reconstructing that state before one. The word is used loosely, so test it directly: ask how often each control is re-checked,… ## Resources - [Compliance as Code: Treating Controls Like Software (2026-08-19)](https://noru.tech/resources/compliance-as-code): What it means to manage compliance the way you manage software — controls defined in version control, evidence produced by pipelines, and drift caught by a check rather than an audit. The practices that transfer from… - [Deriving Your Article 30 RoPA From the Codebase (2026-08-17)](https://noru.tech/resources/article-30-ropa-from-your-codebase): How to generate a GDPR Article 30 record of processing from source code instead of maintaining it by hand: what to annotate, which fields derive cleanly, which require human judgement, and how the register stays current… - [Wiring Privacy Records Into Your CI Pipeline (2026-08-14)](https://noru.tech/resources/privacy-records-from-ci): The pipeline mechanics of keeping privacy records current: where the sync step belongs, what it should push, when to fail a build versus warn, and the failure modes that quietly stop a privacy manifest from being… - [Fideslang: Describing Personal Data in an Open Taxonomy (2026-08-12)](https://noru.tech/resources/fideslang-taxonomy-guide): A practical guide to the fideslang privacy taxonomy — data categories, data subjects and data uses — why an open vocabulary beats a proprietary schema, and how to annotate a real codebase without boiling the ocean. - [AI Governance for Engineering Teams (2026-08-10)](https://noru.tech/resources/ai-governance-for-engineering-teams): How to run EU AI Act obligations as engineering controls rather than paperwork: keeping an honest inventory of the AI you actually ship, deciding provider versus deployer per system, and treating Article 50 transparency… - [Querying Compliance Data Over MCP (2026-08-07)](https://noru.tech/resources/mcp-for-compliance-data): What the Model Context Protocol changes for compliance work: letting an AI client query your live control, evidence and risk data instead of a stale export, and the scoping and audit questions to settle before you… - [The AI Act's Transparency Rules Are Live: What Actually Changed on 2 August 2026 (2026-08-06)](https://noru.tech/resources/eu-ai-act-article-50-transparency-what-changed-august-2026): The high-risk deadline moved, so a lot of teams concluded nothing happened. In fact Article 50's transparency duties, the enforcement powers behind them, and the fines that back them all took effect on schedule. Here is… - [Continuous Evidence Collection: What Auditors Actually Accept (2026-08-05)](https://noru.tech/resources/continuous-evidence-collection): How to produce audit evidence as a by-product of running your systems: what makes evidence acceptable, why collection timestamps decide whether a SOC 2 Type II works, and the failure modes that leave a programme quietly… - [International Data Transfers, From an Engineer's Point of View (2026-08-03)](https://noru.tech/resources/data-transfers-for-engineers): How third-country transfers arise from ordinary infrastructure decisions — regions, CDNs, managed services, support access — how to detect them in your own stack, and what the privacy team needs from you when they do. - [The Record of Processing Activities: GDPR's Most Demanding Document, and How to Stop Maintaining It by Hand (2026-06-29)](https://noru.tech/resources/gdpr-ropa-record-of-processing-activities-guide): The Article 30 RoPA is the spine of GDPR accountability — and the document most likely to be quietly wrong. Here is what a RoPA actually has to contain, who really has to keep one, why the manual version drifts out of… - [Consent Monitoring: The Banner Is Not the Control (2026-06-29)](https://noru.tech/resources/consent-monitoring-the-banner-is-not-the-control): A consent banner proves you asked the question. It says nothing about whether your site actually honors the answer. Here is why continuous consent monitoring — not a one-time CMP setup — is the control regulators now… - [Privacy Automation: From Code Scanning to Continuous Compliance (2026-06-22)](https://noru.tech/resources/privacy-automation-guide): Privacy automation turns one-off audits into continuous, jurisdiction-wide compliance. Here's what it is, how an open privacy taxonomy standard lets you describe data once, and how scanning your source code keeps your… - [Beyond the Checklist: Why We Built Real-Time Certificate Discovery into Noru (2026-04-27)](https://noru.tech/resources/beyond-the-checklist-real-time-certificate-discovery): Most GRC inventories are stale the moment they're saved. Noru now tails Certificate Transparency logs in real time to discover new certificates and subdomains, map risk, and produce audit-ready evidence continuously. - [Embedded Compliance in Practice: A Q&A with Kive CTO Islahul (2026-03-30)](https://noru.tech/resources/embedded-compliance-in-practice-kive-cto-islahul): A conversation with Kive CTO Islahul on embedding compliance into daily engineering workflows using Noru and AI automation. - [Noru Partners with XFA to Simplify Compliance and Device Security (2026-03-26)](https://noru.tech/resources/noru-partners-with-xfa-to-simplify-compliance-and-device-security): Noru and XFA are partnering to bring real-time device visibility and verification into the compliance workflow, helping teams automate checks and stay audit-ready. - [Noru raises SEK 6M pre-seed to launch "agentic compliance" platform for tech companies (2026-03-17)](https://noru.tech/resources/noru-raises-sek-6m-pre-seed-agentic-compliance): Noru, a Stockholm-based startup building an AI-native platform for regulatory compliance, has raised SEK 6 million in a pre-seed funding round led by Ampli Ventures. - [The Noru Evidence Gradient: Redefining How GRC Evidence Evolves (2026-03-06)](https://noru.tech/resources/noru-evidence-gradient): Discover the Noru Evidence Gradient, a revolutionary approach to modernizing GRC by evolving compliance evidence from AI-inferred signals to validated, multi-framework proof. - [The End of Manual Compliance: How AI is Redefining GRC for Modern Businesses (2026-03-04)](https://noru.tech/resources/the-end-of-manual-compliance): AI-driven GRC automates compliance, reducing costs and preparation time, while ensuring continuous readiness and lower risk exposure for modern businesses. Embrace the future of autonomous compliance with Noru. - [Noru - From Cost Center to Growth Engine: Turning Compliance into a Competitive Advantage (2026-03-02)](https://noru.tech/resources/from-cost-center-to-growth-engine): Transform compliance from a cost center into a growth engine with AI-driven automation, enhancing trust, shortening sales cycles, and opening new market opportunities. - [Beyond Checkboxes: The Future of AI-Driven GRC in a Multi-Framework World (2026-02-27)](https://noru.tech/resources/beyond-checkboxes): AI-driven GRC revolutionizes compliance by unifying frameworks, automating tasks, and transforming compliance into a strategic business advantage in today's multi-framework world. - [Trust by Design: How AI is Embedding Compliance into the DNA of Modern Organizations (2026-02-25)](https://noru.tech/resources/trust-by-design): Embedding governance, security, and risk management with AI-driven compliance ensures organizations operate securely and efficiently, transforming compliance from a reactive task to a proactive strategy. - [ISO 27001 vs ISO 27002: Understanding the Key Differences and How They Work Together (2026-02-23)](https://noru.tech/resources/iso-27001-vs-iso-27002-differences): Discover the key differences between ISO 27001 and ISO 27002 and how they work together to create a comprehensive information security framework. - [ISO 27001 Ultimate Guide: Everything You Need to Know About Information Security Management (2026-02-20)](https://noru.tech/resources/iso-27001-ultimate-guide): Comprehensive guide to ISO 27001, covering implementation, certification, and maintenance to enhance information security and build trust in your organization. - [GDPR Compliance Guide: Complete Framework for Data Protection and Privacy (2026-02-18)](https://noru.tech/resources/gdpr-compliance-complete-guide): Comprehensive guide to GDPR compliance, covering legal requirements, practical implementation, and tools to protect data and avoid penalties. Learn how to build a robust data protection program. - [SOC 2 Ultimate Guide: Everything You Need to Know About Service Organization Control (2026-02-16)](https://noru.tech/resources/soc-2-ultimate-guide): Learn everything about SOC 2 compliance, from audits to Trust Service Criteria, and how to streamline the certification process to build customer trust and accelerate sales. - [NIST Cybersecurity Framework: Complete Implementation Guide for Risk Management (2026-02-13)](https://noru.tech/resources/nist-cybersecurity-framework-guide): Comprehensive guide on implementing the NIST Cybersecurity Framework to manage cybersecurity risk, enhance protection, and achieve regulatory compliance efficiently. - [ISO 27001 vs SOC 2: Key Differences and Which Framework to Choose (2026-02-11)](https://noru.tech/resources/iso-27001-vs-soc-2-comparison): Explore the key differences between ISO 27001 and SOC 2 to determine the best security framework for your organization's needs. - [GDPR vs CCPA: Complete Comparison of Privacy Laws and Compliance Requirements (2026-02-09)](https://noru.tech/resources/gdpr-vs-ccpa-comparison): Comprehensive comparison of GDPR and CCPA privacy laws, highlighting key differences, similarities, and compliance strategies for businesses. Learn how to build effective privacy programs. - [How to Implement ISO 27001: Step-by-Step Guide for Organizations (2026-02-06)](https://noru.tech/resources/how-to-implement-iso-27001-step-by-step): Implement ISO 27001 with ease using this comprehensive step-by-step guide, covering all phases from planning to certification, and addressing common challenges and solutions. - [SOC 2 Implementation Guide: How to Achieve Compliance and Build Customer Trust (2026-02-04)](https://noru.tech/resources/soc-2-implementation-guide): Learn how to achieve SOC 2 compliance with this comprehensive guide, from initial planning to audit execution, ensuring data security and building customer trust. - [NIST vs ISO 27001: Which Cybersecurity Framework Should You Choose? (2026-02-02)](https://noru.tech/resources/nist-vs-iso-27001-comparison): Compare NIST CSF and ISO 27001 to choose the right cybersecurity framework for your organization, considering your specific needs, regulatory requirements, and business objectives. - [GDPR Implementation Guide: Step-by-Step Compliance for Organizations (2026-01-30)](https://noru.tech/resources/gdpr-implementation-step-by-step-guide): Achieve GDPR compliance with this step-by-step guide covering everything from initial assessment to continuous improvement, ensuring your organization's data protection practices meet regulatory standards. - [SOC 2 vs ISO 27001 vs NIST: Complete Framework Comparison for Security Leaders (2026-01-28)](https://noru.tech/resources/soc-2-vs-iso-27001-vs-nist-comparison): Compare SOC 2, ISO 27001, and NIST frameworks to determine the best fit for your organization's security needs and industry requirements. - [ISO 27001 Controls: Complete Guide to Annex A Implementation (2026-01-26)](https://noru.tech/resources/iso-27001-controls-annex-a-guide): Learn how to implement ISO 27001 Annex A controls effectively with this comprehensive guide covering all 114 controls and practical implementation advice. - [GDPR vs CCPA vs PIPEDA: Complete Privacy Law Comparison Guide (2026-01-23)](https://noru.tech/resources/gdpr-vs-ccpa-vs-pipeda-privacy-law-comparison): Compare GDPR, CCPA, and PIPEDA to understand key differences, compliance requirements, and strategies for effective privacy management in a global digital economy. - [SOC 2 Type I vs Type II: Understanding the Key Differences and Requirements (2026-01-21)](https://noru.tech/resources/soc-2-type-i-vs-type-ii-differences): Learn the key differences between SOC 2 Type I and Type II reports, their requirements, and best practices for implementation to ensure your organization’s security and compliance. - [NIST Cybersecurity Framework Implementation: Step-by-Step Guide for Organizations (2026-01-19)](https://noru.tech/resources/nist-cybersecurity-framework-implementation-guide): Implement the NIST Cybersecurity Framework with our detailed guide to enhance your organization's cybersecurity posture through systematic risk management. - [ISO 27001 vs SOC 2 vs NIST: Which Security Framework Should You Choose? (2026-01-16)](https://noru.tech/resources/iso-27001-vs-soc-2-vs-nist-which-framework-choose): Compare ISO 27001, SOC 2, and NIST CSF to find the best security framework for your organization. Learn key differences, use cases, and selection criteria to make an informed decision. - [SOC 2 Trust Service Criteria: Complete Guide to Security, Availability, Processing Integrity, Confidentiality, and Privacy (2026-01-14)](https://noru.tech/resources/soc-2-trust-service-criteria-complete-guide): Understand SOC 2 Trust Service Criteria, including Security, Availability, Processing Integrity, Confidentiality, and Privacy, and learn how to implement them for SOC 2 compliance. - [GDPR Data Protection Impact Assessment (DPIA): Complete Guide and Template (2026-01-12)](https://noru.tech/resources/gdpr-data-protection-impact-assessment-guide): Learn how to conduct GDPR Data Protection Impact Assessments (DPIAs) with our complete guide, including practical templates and steps to ensure compliance and protect individual privacy rights. - [ISO 27001 Risk Assessment: Complete Guide to Information Security Risk Management (2026-01-09)](https://noru.tech/resources/iso-27001-risk-assessment-complete-guide): Complete guide on ISO 27001 risk assessments, covering identification, evaluation, and treatment of risks to ensure compliance and protect information assets. ## MCP integrations - [Cursor MCP setup](https://noru.tech/resources/mcp/cursor): Connect Cursor to Noru over MCP and review controls, evidence and audit blockers without leaving your editor. Setup steps, config and example prompts. - [Claude MCP setup](https://noru.tech/resources/mcp/claude): Connect Claude to Noru over MCP for compliance analysis grounded in live controls, risks and evidence. Setup steps, config snippets and example prompts. - [Perplexity MCP setup](https://noru.tech/resources/mcp/perplexity): Connect Perplexity to Noru over MCP and run natural-language search against live compliance data. Setup steps, config snippets and example prompts. - [Raycast MCP setup](https://noru.tech/resources/mcp/raycast): Connect Raycast to Noru over MCP and pull compliance answers from a single desktop shortcut. Setup steps, config snippets and example prompts included. - [ChatGPT MCP setup](https://noru.tech/resources/mcp/chatgpt): Set up Noru MCP in ChatGPT developer mode and build compliance assistants on live organizational data. Setup steps, config snippets and example prompts. - [OpenCode MCP setup](https://noru.tech/resources/mcp/opencode): Connect OpenCode to Noru over MCP and query live compliance data from your terminal workflow. Setup steps, config snippets and example prompts included. - [Zapier MCP setup](https://noru.tech/resources/mcp/zapier): Connect Noru MCP to Zapier and automate compliance workflows across your stack. Setup steps, connection config and example automations included. - [Microsoft Copilot MCP setup](https://noru.tech/resources/mcp/copilot): Connect Microsoft Copilot Studio to Noru over MCP and query compliance data inside Microsoft 365. Setup steps, config snippets and example prompts. - [n8n MCP setup](https://noru.tech/resources/mcp/n8n): Connect the n8n MCP Client to Noru for compliance workflow orchestration and AI agents. Setup steps, connection config and example workflows included. - [Make MCP setup](https://noru.tech/resources/mcp/make): Use the Make MCP Client with Noru to build visual no-code automations for compliance operations. Setup steps, connection config and example scenarios. ## Documentation - [Frameworks](https://noru.tech/docs/reference/frameworks): The framework catalog with ids, display names, and category. - [FAQ](https://noru.tech/docs/reference/faq): Short answers to the questions support hears most, each linking to the page with the detail. - [Glossary](https://noru.tech/docs/reference/glossary): Terms used across Noru and these docs, each linked to the page that explains it. - [Reference](https://noru.tech/docs/reference): Tables you look things up in: roles, statuses, frameworks, routes, shortcuts, terms, and answers to common questions. - [Page map](https://noru.tech/docs/reference/page-map): Every route in the app, what the page is for, and the guide that covers it. - [Roles and permissions](https://noru.tech/docs/reference/roles-and-permissions): What admins, editors, and viewers can see and do, which capability each action needs, and how MCP scopes follow roles. - [Search and shortcuts](https://noru.tech/docs/reference/search-and-shortcuts): What each search box in the app matches, how to search these docs, and the few keyboard shortcuts that exist. - [Statuses](https://noru.tech/docs/reference/statuses): Every status value across controls, evidence, policies, risks, vendors, findings, audits, training, privacy, integrations, and jobs, with the label the app shows. - [API keys](https://noru.tech/docs/developers/api-keys): Create scoped, expiring API keys and use them as bearer tokens for REST and headless MCP access. - [Developers](https://noru.tech/docs/developers): API keys, the REST API, and the MCP server: how to authenticate, what you can call, and how to connect an AI client. - [MCP client setup](https://noru.tech/docs/developers/mcp-clients): Step-by-step setup for Cursor, Claude, ChatGPT, Copilot, Raycast, Zapier, n8n, Make, and other MCP clients. - [MCP server](https://noru.tech/docs/developers/mcp-server): Connect AI clients to Noru over MCP with OAuth or API keys, and understand which tools each scope and role unlocks. - [REST API](https://noru.tech/docs/developers/rest-api): Authenticate, browse the OpenAPI reference, and call the Noru API from curl, fetch, or CI. - [Data sources](https://noru.tech/docs/data-sources): Every connector Noru supports, what each one asks for, what it collects, and how syncs behave. - [Permissions and security](https://noru.tech/docs/data-sources/permissions-and-security): How Noru stores connector credentials, what each authentication model can and cannot do, and what read-only really means per provider. - [Sync model](https://noru.tech/docs/data-sources/sync-model): How often each source syncs, what the sync button does, what each status means, and what a sync produces. - [Troubleshooting](https://noru.tech/docs/data-sources/troubleshooting): Connection, authentication, partial collection, and stale-evidence problems. - [Your account](https://noru.tech/docs/guides/account): Profile, organization access, and notification preferences. - [Assets](https://noru.tech/docs/guides/assets): Keep the asset register current: discovered and manual assets, grouping, ownership, classification, and risk links. - [Cortex](https://noru.tech/docs/guides/cortex): Ask Noru's AI assistant about your program, draft policies, and review generated work. - [Data sources page](https://noru.tech/docs/guides/data-sources): Connect, sync, reauthenticate, inspect, and disconnect integrations from the app. - [Guides](https://noru.tech/docs/guides): Task-first guides for every page in the Noru app. - [Notifications](https://noru.tech/docs/guides/notifications): In-app notifications, live updates, and per-user email preferences. - [Overview dashboard](https://noru.tech/docs/guides/overview): Read framework progress, work through the readiness plan, and use the privacy plan variant. - [Tasks](https://noru.tech/docs/guides/tasks): Work assigned through policies, risks, evidence, controls, vendors, and treatments. - [AI and Cortex](https://noru.tech/docs/under-the-hood/ai-and-cortex): Where AI is used in Noru, how customer data is handled, how Cortex tools are gated by role, and how AI output is marked so it is never mistaken for a decision. - [Control status and coverage](https://noru.tech/docs/under-the-hood/control-status-and-coverage): How coverage is computed and when a control changes status on its own. - [Data model and operating model](https://noru.tech/docs/under-the-hood/data-model-and-operating-model): Organizations, segments, records, and how the modules connect. - [Evidence lifecycle and integrity](https://noru.tech/docs/under-the-hood/evidence-lifecycle-and-integrity): Automatic and manual evidence, qualification, and the attestation hash chain. - [Under the hood](https://noru.tech/docs/under-the-hood): How Noru computes, syncs, stores, and secures what you see. - [Notifications and email](https://noru.tech/docs/under-the-hood/notifications-and-email): Where in-app notifications come from, how they reach the browser, which emails exist, how preferences apply, and what Slack does and does not do. - [Policy versioning and acknowledgements](https://noru.tech/docs/under-the-hood/policy-versioning-and-acknowledgements): Version bumps, policy logs, review reminders, and attestation links. - [Privacy scanner and drift](https://noru.tech/docs/under-the-hood/privacy-scanner-and-drift): What the website scanner observes and cannot judge, how findings map to obligations, how scans are compared over time, and how register drift is detected. - [Risk scoring and reports](https://noru.tech/docs/under-the-hood/risk-scoring-and-reports): Likelihood, impact, residual risk, generated risks, and report snapshots. - [RBAC and security model](https://noru.tech/docs/under-the-hood/rbac-and-security-model): Roles and capabilities, where authorization is enforced, organization MFA, API keys, MCP OAuth, credential protection, and what is logged. - [Sync model and job scheduler](https://noru.tech/docs/under-the-hood/sync-model-and-job-scheduler): How integrations sync, retry, and fail, and how background jobs run. - [Vendor risk and questionnaire AI](https://noru.tech/docs/under-the-hood/vendor-risk-and-questionnaire-ai): What triggers a vendor risk assessment, how public security documents are gathered, how the risk level is derived, and how questionnaire answers and reviews are drafted by AI. - [Cloudflare](https://noru.tech/docs/data-sources/providers/cloudflare): Connect Cloudflare: authentication, permissions, what Noru collects, and troubleshooting. - [Amazon Web Services](https://noru.tech/docs/data-sources/providers/aws): Connect Amazon Web Services: authentication, permissions, what Noru collects, and troubleshooting. - [Confluence](https://noru.tech/docs/data-sources/providers/confluence): Connect Confluence: authentication, permissions, what Noru collects, and troubleshooting. - [Datadog](https://noru.tech/docs/data-sources/providers/datadog): Connect Datadog: authentication, permissions, what Noru collects, and troubleshooting. - [Databricks](https://noru.tech/docs/data-sources/providers/databricks): Connect Databricks: authentication, permissions, what Noru collects, and troubleshooting. - [Detectify](https://noru.tech/docs/data-sources/providers/detectify): Connect Detectify: authentication, permissions, what Noru collects, and troubleshooting. - [DigitalOcean](https://noru.tech/docs/data-sources/providers/digitalocean): Connect DigitalOcean: authentication, permissions, what Noru collects, and troubleshooting. - [GitHub](https://noru.tech/docs/data-sources/providers/github): Connect GitHub: authentication, permissions, what Noru collects, and troubleshooting. - [GitLab](https://noru.tech/docs/data-sources/providers/gitlab): Connect GitLab: authentication, permissions, what Noru collects, and troubleshooting. - [Google Cloud Platform](https://noru.tech/docs/data-sources/providers/google-cloud): Connect Google Cloud Platform: authentication, permissions, what Noru collects, and troubleshooting. - [Google Workspace](https://noru.tech/docs/data-sources/providers/google-workspace): Connect Google Workspace: admin-only OAuth, directory and group sync, connected-app discovery, and the scopes that are broader than read-only. - [HaileyHR](https://noru.tech/docs/data-sources/providers/haileyhr): Connect HaileyHR: API-key setup, the employee and company data Noru reads, the schema profile that feeds the privacy data map, and what stays in Hailey. - [Google Drive](https://noru.tech/docs/data-sources/providers/google-drive): Connect Google Drive: file-scoped OAuth, the Picker selection step, what Noru reads about each chosen file, and what it never touches. - [JungleMap](https://noru.tech/docs/data-sources/providers/junglemap): Connect JungleMap (NanoLearning): credential setup, how activity plans become training campaigns, and which completion data Noru writes. - [Linear](https://noru.tech/docs/data-sources/providers/linear): Connect Linear: read-scope OAuth, the team, issue, project, and member data Noru collects for change management, and what it leaves alone. - [Microsoft Azure](https://noru.tech/docs/data-sources/providers/microsoft-azure): Connect Microsoft Azure: the Cloud Shell setup script, federated workload identity with Reader and Security Reader, what Noru reads from ARM, and the legacy secret path. - [Microsoft Entra ID](https://noru.tech/docs/data-sources/providers/microsoft-entra-id): Connect Microsoft Entra ID: delegated Graph scopes with admin consent, the user, group, policy, and sign-in data Noru reads, and what the People directory gets from it. - [Microsoft SharePoint and OneDrive](https://noru.tech/docs/data-sources/providers/microsoft-sharepoint): Connect Microsoft SharePoint and OneDrive: delegated Graph scopes, the site and library you choose, the file metadata Noru reads, and the reach of Files.Read.All. - [Neo4j Aura](https://noru.tech/docs/data-sources/providers/neo4j-aura): Connect Neo4j Aura: Aura API client credentials, the two tenant and instance reads Noru makes, and why it never touches graph data. - [Supabase](https://noru.tech/docs/data-sources/providers/supabase): Connect Supabase: read-only Management API scopes, the organization, project, auth, and edge-function data Noru collects, and the toggles that do nothing. - [Vercel](https://noru.tech/docs/data-sources/providers/vercel): Connect Vercel: the Marketplace install flow, the team, project, deployment, environment variable, and domain data Noru collects, and how domains reach certificate monitoring. - [Audit calendar](https://noru.tech/docs/guides/audit/audit-calendar): See internal and external audits on one timeline. - [External audit](https://noru.tech/docs/guides/audit/external-audit): Track engagements and build controlled evidence packages for auditors. - [Internal audit](https://noru.tech/docs/guides/audit/internal-audit): Plan, perform, document, finalise, and export an internal audit. - [Evidence vault](https://noru.tech/docs/guides/evidence/evidence-vault): Upload, import, validate, filter, and inspect evidence, and see how automatic evidence arrives. - [Evidence](https://noru.tech/docs/guides/evidence): Where proof lives: the evidence vault for artifacts and policies for governing documents. - [Policies](https://noru.tech/docs/guides/evidence/policies): Create policies by hand, from a template, with AI, or from Confluence; approve, review, and download the master list. - [Policy editor](https://noru.tech/docs/guides/evidence/policy-editor): Edit policy content, manage versions and review cadence, link controls, and act on Cortex change proposals. - [Control detail](https://noru.tech/docs/guides/controls/control-detail): Own a control: set status, link evidence and policies, add notes, and read guidance and history. - [Controls](https://noru.tech/docs/guides/controls): Search, filter, bulk-update, and export the control directory. - [Choose frameworks](https://noru.tech/docs/guides/getting-started/choose-frameworks): Pick the standards and regulations in scope and understand what enabling a framework loads. - [Connect your first data source](https://noru.tech/docs/guides/getting-started/connect-your-first-data-source): Connect GitHub, AWS, or your identity provider so evidence starts collecting automatically. - [Create your organization](https://noru.tech/docs/guides/getting-started/create-your-organization): Walk through the six-step organization wizard: frameworks, company details, context, billing details, and your first data source. - [First week checklist](https://noru.tech/docs/guides/getting-started/first-week-checklist): The order of work that gets an organization from empty to audit-ready, mapped to the dashboard readiness plan. - [Getting started](https://noru.tech/docs/guides/getting-started): From sign-up to a working compliance program in your first week. - [Invite your team](https://noru.tech/docs/guides/getting-started/invite-your-team): Add members, assign admin, editor, or viewer roles, and manage pending invitations. - [Sign in and accounts](https://noru.tech/docs/guides/getting-started/sign-in-and-accounts): Create an account, sign in, meet the MFA requirement, and switch between organizations. - [People directory](https://noru.tech/docs/guides/personnel/people-directory): Maintain the canonical personnel list, merge identities, and track MFA, training, and signatures. - [Training and acknowledgement](https://noru.tech/docs/guides/personnel/training-and-acknowledgement): Create training plans and campaigns, send reminders, and record policy acknowledgements. - [Privacy assessments](https://noru.tech/docs/guides/privacy/assessments): Run DPIAs and data-protection assessments with linked risks, evidence, and outcomes. - [Connected apps](https://noru.tech/docs/guides/privacy/connected-apps): Review third-party OAuth grants observed in your identity provider and map them to vendors. - [Privacy inbox](https://noru.tech/docs/guides/privacy/inbox): Decide on connector drift, connector proposals, record intake, and AI drafts. - [Data map](https://noru.tech/docs/guides/privacy/data-map): Ingest a Fideslang manifest, explore systems and datasets, and compare data map versions. - [Privacy overview](https://noru.tech/docs/guides/privacy): The privacy plan and overview: priorities, queues, and where each privacy record lives. - [Privacy monitoring](https://noru.tech/docs/guides/privacy/monitoring): Watch public sites for consent, cookie, tracker, and transport issues and read scan results. - [Privacy settings](https://noru.tech/docs/guides/privacy/privacy-settings): Set controller details, covered regulations, data-subject regions, and the security-measure catalog. - [Records of processing](https://noru.tech/docs/guides/privacy/records-of-processing): Maintain the RoPA, complete legal bases and retention, and export the Article 30 document. - [Create and edit risks](https://noru.tech/docs/guides/risk/create-and-edit-risks): Assess a risk with the full form, generate treatment suggestions, and record residual risk. - [Risk register](https://noru.tech/docs/guides/risk/risk-register): Work the risk register in table and matrix views and keep inherent and residual scores current. - [Risk reports](https://noru.tech/docs/guides/risk/risk-reports): Preview live reports, generate snapshots, and download PDFs for management and auditors. - [Certificates](https://noru.tech/docs/guides/security/certificates): Monitor domains and Certificate Transparency records and act on expiring certificates. - [Security findings](https://noru.tech/docs/guides/security/findings): Triage findings by severity, assign owners, link risks and assets, and close them out. - [Billing](https://noru.tech/docs/guides/settings/billing): Where an admin sees the organization's billing status and reaches invoices and payment details. - [Organization context](https://noru.tech/docs/guides/settings/context): Reusable background that Cortex and generated content rely on. - [Developer settings](https://noru.tech/docs/guides/settings/developer): API keys and MCP access for the organization. - [Frameworks](https://noru.tech/docs/guides/settings/frameworks): Enable and disable the frameworks in scope for your organization. - [General settings](https://noru.tech/docs/guides/settings/general): Company details, logo, and organization deletion. - [Organization settings](https://noru.tech/docs/guides/settings): The admin-only settings page and its tabs. - [Integrations](https://noru.tech/docs/guides/settings/integrations): Slack, Microsoft Teams, and the API and MCP endpoints. - [Members](https://noru.tech/docs/guides/settings/members): Invite members, change roles, and remove access. - [Security settings](https://noru.tech/docs/guides/settings/security): Require multi-factor authentication for the organization. - [Trust center builder](https://noru.tech/docs/guides/trust-center/builder): Configure branding, content, sections, and advanced settings, then preview and publish. - [Custom domain](https://noru.tech/docs/guides/trust-center/custom-domain): Serve the trust page from your own domain with DNS verification and automatic SSL. - [Public trust page](https://noru.tech/docs/guides/trust-center/public-trust-page): What visitors see on your published trust page and how requests reach you. - [Trust center requests](https://noru.tech/docs/guides/trust-center/requests): Review and fulfil requests for gated certificate files. - [Vendor questionnaires](https://noru.tech/docs/guides/vendors/questionnaires): Build templates, send assessments, and review answers with AI assistance, including the vendor's portal. - [Vendor detail](https://noru.tech/docs/guides/vendors/vendor-detail): The seven vendor tabs: overview, risk, privacy, evidence, assessments, personnel, and activity. - [Vendor register](https://noru.tech/docs/guides/vendors/vendor-register): Add vendors, set owners and status, gather security documents, and merge duplicates. ## Tools - [Privacy auditor](https://noru.tech/tools/privacy-auditor): Free scan of any public site for cookies, trackers, consent banners and transport security, with a shareable report. - [All tools](https://noru.tech/tools) ## Company - [Company](https://noru.tech/company): Mission, values, and team. - [Case studies](https://noru.tech/case-studies): How customers use Noru. - [Security advisories](https://noru.tech/security/advisories): Published security advisories for Noru products. ## Optional - [Terms](https://noru.tech/terms-and-conditions) - [Privacy policy](https://noru.tech/privacy-policy) - [Cookie policy](https://noru.tech/cookie-policy) - [DPA](https://noru.tech/legal/dpa) - [SLA](https://noru.tech/legal/sla) - [DORA addendum](https://noru.tech/legal/dora-addendum) ## Contact - info@noru.tech