Noru

The platform

One Operating System for Compliance

Every module shares the same controls, evidence and data model. Implement once, and your proof stays current for every counterparty, every security review, every framework you add.

Trusted by security and privacy minded organizations across the world

How it fits together

From your systems to settled trust.

Connect the systems you already run. Noru's agents turn them into a live compliance program — privacy, regulations, AI governance, vendors and risk — and keep every counterparty proven, with your team in the loop.

Your systems

Code, cloud, identity and the tools your team lives in.

  • GitHub
  • AWS
  • GCP
  • Microsoft
  • GitLab
  • Datadog
  • Cloudflare
  • Google

+ more integrations

Agents that run your program

Grounded in your live data, Noru's agents do the work across every system — every action a draft you approve.

  • Agents map controls and keep evidence current across 30+ frameworks
  • Privacy records and DPIAs derived from your code
  • DORA, NIS2 and CRA proven from one evidence base
  • AI governance — the EU AI Act and ISO 42001
  • Risk and vendor exposure scored off real system signals

Every counterparty

Everyone who asks you to prove it, answered from one system.

  • Customers: proof you're secure, the moment they ask
  • Your board: risk, always current
  • Regulators: every report they need, ready
  • Auditors: everything they ask for, already verified

Govern

Set the rules once. Policy, risk and oversight live in one system instead of scattered spreadsheets.

Controls

One control library, mapped across ISO 27001, SOC 2, GDPR and 30+ frameworks — the same evidence reused everywhere.

Policies

AI-assisted drafting, versioning, approvals and acknowledgements, mapped to the controls they satisfy.

Risk Register

A live register linked to security findings, controls and treatments — not a yearly workshop artifact.

Audits

Plan internal and external audits against evidence that already exists, on a calendar the whole team can see.

Operate

Run the program day to day. Evidence, assets, security findings and people stay current without chasing.

Evidence Vault

Evidence collected continuously from your systems, versioned, tagged and linked to controls automatically.

Assets

An asset inventory reconciled from your infrastructure — the foundation for scoping controls and risk.

Security

Certificates, vulnerabilities and pen-test findings tracked to resolution and linked to risk.

People & Training

Directory, policy acknowledgements and awareness campaigns with completion tracked per person.

Data Sources

20+ integrations — AWS, GCP, Azure, GitHub, Slack, Entra ID and more — feeding evidence in real time.

Prove

Show your work — to customers, your board and regulators — with proof that is live, not a PDF from last quarter.

Trust Center

A public trust page on your own domain showing your security posture, policies and subprocessors — always current.

Vendor Risk

A vendor register with risk scoring, security questionnaires and evidence collected from responses.

Privacy Automation

Data maps, records of processing and impact assessments derived from the systems that hold the data and enriched by AI.

Cortex AI

AI agents grounded in your actual program: they draft policies, map controls, gather evidence and surface the next move — you approve.

Cortex

Ask anything about your program. Cortex drafts policies, maps gaps and suggests the next most valuable task.

Integrations

Built on your data sources.

Connect the systems you already run. Data stays fresh, with real-time security insights—not on a quarterly scramble.

  • Amazon Web ServicesAWS
  • CloudflareCloudflare
  • ConfluenceConfluence
  • DatabricksDatabricks
  • DatadogDatadog
  • DetectifyDetectify
  • GitHubGitHub
  • GitLabGitLab
  • Google Cloud PlatformGCP
  • Google DriveGoogle Drive
  • Google WorkspaceGoogle
  • HaileyHRHaileyHR
  • JungleMap (NanoLearning)JungleMap
  • LinearLinear
  • MicrosoftMicrosoft
  • Neo4j AuraNeo4j
  • NeonNeon
  • SupabaseSupabase
  • VercelVercel

01

MCP guardrails where dev happens

Bring live control and policy context into Cursor, Claude, ChatGPT, Copilot, and other MCP clients your team already uses.

  • Review pull requests and changes against live control state
  • Give teams compliant remediation guidance in-line
  • Keep security decisions in-bounds without leaving developer workflows
View MCP Guides

02

API-first compliance automation

Use the Noru API to connect CI/CD, ticketing, and internal tooling so compliance checks and evidence updates run automatically.

  • Trigger checks from commits, pull requests, deploys, and infra changes
  • Sync evidence and task ownership without manual chasing
  • Build custom compliance workflows on a single source of truth
API & Documentation

Trust by design

MCP + API prevents drift

Move trust work from periodic audit prep into your day-to-day engineering flow. MCP provides in-context guardrails and the API powers automated checks and evidence sync.

Coverage

Say yes to any buyer.

One control library across 30+ frameworks — controls map once and the evidence you already collect carries every standard you add.

  • ISO 27001ISO 27001
  • SOC 2SOC 2
  • GDPRGDPR
  • NIS2NIS2
  • DORADORA
  • ISO 42001ISO 42001
  • EU AI ActEU AI Act
  • HIPAAHIPAA
  • PCI DSS 4.0PCI DSS 4.0
  • NIST CSFNIST CSF
  • CIS v8CIS v8
  • +20more frameworks

FAQ

Platform questions answered

Talk to us

How does Noru collect evidence automatically?

Noru connects to the systems that already hold the truth — cloud accounts, identity providers, source control, device management and collaboration tools — and reads their state on a schedule. Each signal is mapped to the controls it satisfies, so evidence accumulates as a by-product of running the business rather than as a task somebody has to remember before an audit.

What does continuous control monitoring actually mean?

It means a control has a current state rather than a last-reviewed date. Noru re-checks the underlying signal on an interval, records the result, and raises a finding when the control drifts out of conformance — so the gap surfaces when it opens instead of during audit fieldwork months later.

How does one control library cover 30+ frameworks?

Most frameworks ask overlapping questions in different words. Noru maps a single control set to every framework it satisfies, so implementing access review once satisfies the corresponding requirement in SOC 2, ISO 27001, NIS2 and the rest. Adding a framework reuses the evidence you already collect instead of starting a second programme.

Do we have to replace the tools we already use?

No. Noru sits on top of your existing stack and reads from it. There is nothing to migrate, and no parallel process for engineers to maintain alongside the systems they actually work in.

How is AI used, and where is it not?

Cortex drafts — policies, control narratives, privacy records, assessment responses — grounded in the evidence already in your programme, and every output is attributable and reviewable. It does not silently decide whether a control passes or a legal basis holds. Those remain accountable human judgements, recorded with the person who made them. And it never learns from you: your data is not used to train, fine-tune or evaluate any model.

Is our data used to train models, and what does the provider keep?

Nothing, and nothing. Customer data is never used to train, fine-tune or evaluate a model — ours or a third party's — and every AI call runs under zero data retention terms, so the model provider returns the output and retains no copy of the prompt or the response. No human review queue, no training corpus, no exceptions by plan. Both commitments sit in the Terms (Section 4.6) and the DPA (Sections 3.5–3.6), so your procurement team can read them rather than take our word for it.

Can other tools query our compliance data?

Yes. Noru exposes a REST API and a Model Context Protocol server, so AI clients such as Claude, ChatGPT, Cursor and Perplexity can query your live control, evidence and risk data directly, scoped by an API key you control.

Where is our data hosted?

In the EU. Noru runs with EU data residency, encryption in transit and at rest, role-based access control, and a published subprocessor list, with a DPA and SLA available as part of every deployment. AI inference is the one processing activity that may leave the EEA, and it runs under zero data retention terms with EU Standard Contractual Clauses in place.

See the platform against your systems.

A 45-minute walkthrough, tailored to your stack and use cases.