Noru

Pricing

Priced around your program.

Every deployment runs on the same platform. You licence the capability packages your obligations actually require, and we price against the scope you run them at.

Trusted by security and privacy minded organizations across the world

Every deployment

One platform under every package.

Whatever you licence, you get the same system of record — connected to your systems, mapped once, and continuously proven.

One control library, mapped once

ISO 27001, SOC 2, GDPR, DORA, NIS2, ISO 42001 and 30+ frameworks in total, sharing the same controls and the same evidence. The next standard reuses what you already collect.

Continuous evidence from your systems

20+ integrations across cloud, identity, code and collaboration turn what you already run into versioned, mapped evidence. No screenshots, no quarterly scramble.

Cortex AI, grounded in your program

Agents that draft policies, map controls and surface the next most valuable task against your real data — with your team approving every change, and your data never used to train a model.

Enterprise assurances from day one

EU data residency, role-based access control, published subprocessors, zero data retention on every AI call, a DPA and an SLA. The things procurement asks for are not an upgrade path.

Capability packages

Licence only what your obligations require.

Each package adds capability to the same system of record. Start where the pressure is, and add the next one without a second implementation.

Privacy Automation

Derive records of processing from the systems that actually hold the data, and keep assessments, transfers and retention current as those systems change.

  • Privacy AutomationMap every data flow, continuously
  • Data SourcesConnect once, sync forever
  • Risk RegisterKnow your risk before anyone asks
  • PoliciesKeep every policy acknowledged

Pricing based on the systems connected and the processing activities in scope.

Book a demoHow this works

Agentic Compliance

Put agents to work across the systems you already run — mapping controls, gathering evidence and drafting policies against your live program, with your team accepting every change.

  • CortexAsk anything, act on answers
  • ControlsImplement once, satisfy many
  • Evidence VaultNever chase a screenshot again
  • PoliciesKeep every policy acknowledged

Pricing based on the systems the agents act across and the volume of work they run.

Book a demoHow this works

Compliance & Audit

Run every framework your buyers and regulators ask for from one control library, and walk into audits with the evidence already collected.

  • ControlsImplement once, satisfy many
  • Evidence VaultNever chase a screenshot again
  • AuditsWalk in already prepared
  • PoliciesKeep every policy acknowledged

Pricing based on the frameworks in scope and the size of your workforce.

Book a demoHow this works

AI Governance

Govern the models and agents you ship under the EU AI Act and ISO 42001: an AI register built from your repositories, one finding per legal claim, and controls attached to what is actually running.

  • ControlsImplement once, satisfy many
  • Risk RegisterKnow your risk before anyone asks
  • PoliciesKeep every policy acknowledged
  • Privacy AutomationMap every data flow, continuously

Pricing based on the number of AI systems and models under governance.

Book a demoHow this works

Third-Party & Supply Chain Risk

Score vendors by the data and access they actually hold, collect their evidence once, and keep the register current between reviews.

  • Vendor RiskSee every vendor's posture
  • Risk RegisterKnow your risk before anyone asks
  • Evidence VaultNever chase a screenshot again
  • Trust CenterPublish proof, not promises

Pricing based on the vendors under management and the assessment volume you run.

Book a demoHow this works

Risk Management

Run a register scored off live signals from your stack — security findings, vendor posture and control status — with every risk owned and tracked to treatment.

  • Risk RegisterKnow your risk before anyone asks
  • SecurityTrack every finding to resolution
  • Vendor RiskSee every vendor's posture
  • ControlsImplement once, satisfy many

Pricing based on the risks under management and the systems feeding the register.

Book a demoHow this works

How we scope it

What shapes your price.

No public price list, and no mystery either — these are the four variables we work through with you on the first call.

Packages licensed

Start with the obligations you actually have. Adding a package later reuses the controls and evidence already in place.

Scope under management

Frameworks, connected systems, processing activities, AI systems, vendors — the volume the platform governs.

Organization size

Headcount in scope for policies, training and access, and the number of legal entities you run.

Deployment and support

Onboarding depth, migration from an incumbent, and the support model your program needs.

Book a demo

Get a scoped quote.

Tell us what you're obligated to prove and to whom. We'll show you the platform against it and price the packages you'd actually run.

  • We walk the platform against the obligations you actually have
  • You leave knowing which packages fit and what they cost
  • A written quote after the call — or a clear no-fit

We respond within one business day. No mailing lists, no spam.

FAQ

Pricing FAQ

Talk to us

What does every deployment include?

The platform: one control library mapped across 30+ frameworks, continuous evidence from 20+ integrations, Cortex AI grounded in your program, EU data residency, role-based access control, a DPA and an SLA. Also every trust commitment we make — we never train on your data, and every AI feature runs under zero data retention — which apply to every customer on every package rather than to an enterprise tier. Packages add capability on top; they don't unlock the basics.

Can we start with one package and add another later?

Yes. Every package runs on the same system of record, so adding Privacy Automation or AI Governance later reuses the controls, evidence and assets you already have. There is no re-platforming and no second implementation.

How is each package priced?

By the scope it governs. Compliance & Audit by the frameworks in scope and workforce size, Privacy Automation by connected systems and processing activities, AI Governance by the AI systems under governance, and Third-Party & Supply Chain Risk by the vendors under management.

How do we get a quote?

Book a demo. We walk the platform against your obligations, agree the packages and scope, and send a written quote — or tell you Noru isn't the right fit. For procurement and invoicing questions, reach sales@noru.tech.

Trust, settled.

See it running against your own systems.