Noru

Security

Security at Noru.Built to be examined.

Noru's security program protects customer data, keeps compliance continuous and makes responsible disclosure straightforward. This page sets out how it works: the controls, where data lives, what AI is allowed to do with it, and how to reach us when something is wrong.

Acknowledged within 24 hoursTriaged within 3 business daysCoordinated disclosure within 90 daysProcessed in Sweden, within the EEAsecurity.txt

Program

Security is how Noru operates, not a project beside it.

Governance, secure engineering, monitoring, resilience and transparent disclosure, run as one program. The goal is not to document controls but to make them operational and repeatable.

Governance

Security is built into how Noru operates

We maintain documented security, incident management and business continuity practices, review access on a least-privilege basis, and use policy-driven controls to keep responsibilities clear as the platform evolves.

Core controls

Technical and organisational safeguards work together

Our program includes RBAC, MFA for administrative access, secure development practices, vulnerability management, monitoring and alerting, and vendor due diligence for subprocessors and critical providers — including zero data retention terms with every AI model provider we use.

Transparency

Security information is accessible and actionable

We are deliberate about trust and transparency. Customers and researchers can review our disclosure policy, machine-readable security.txt file, advisories, encryption details and contact paths from one place.

Principles

01

Limit access to people with a legitimate business need, and review that access regularly.

02

Apply layered safeguards across infrastructure, product and internal operations rather than relying on a single control.

03

Build security into development and operational processes, so issues are found earlier and remediation is easier to track.

04

Keep the program observable and transparent through clear policies, contact paths and published disclosure materials.

Safeguards

Controls across product, infrastructure and operations.

Administrative, physical and technical safeguards designed to protect personal and customer data, reflected in our legal terms, disclosure processes and trust documentation.

Access control

  • Role-based access control and least-privilege access patterns.
  • Multi-factor authentication for administrative access.
  • Periodic access reviews and authorisation checks for sensitive systems.
  • Single sign-on support where available.

Data protection

  • TLS for data in transit.
  • Encryption at rest for production data and backups.
  • Secure key management practices.
  • Logical tenant separation designed to prevent cross-customer access.
  • No model training on customer data, and zero data retention with every AI model provider.

Monitoring and resilience

  • Security logging, monitoring and alerting for important systems.
  • Audit trails for administrative actions.
  • Documented incident response processes and breach notification paths.
  • Backup and disaster recovery measures that support service continuity.

Secure delivery

  • Peer review and code review as part of normal engineering workflows.
  • Dependency scanning, vulnerability management and security testing.
  • Network controls, patching and environment hardening appropriate to the hosting environment.
  • Due diligence and contractual controls for subprocessors and other vendors.

For customers performing vendor reviews, additional program detail is available through our Trust Centre.

Data handling

Where your data lives, and what it is used for.

Where customer data is processed, what it may be used for, and how we tell you when something affects it.

Data residency

Regional processing and transfer controls

Noru's primary processing location is Sweden, within the EEA. Limited sub-processing activities may involve the United States, and cross-border transfers are supported through contractual and legal transfer mechanisms where required.

Purpose boundaries

Customer data handling is purpose-bound

We process data to provide and secure the service, maintain availability, prevent abuse and support customer use of the platform — and for nothing else. Customer data is never used to train, fine-tune or evaluate any AI model, ours or a provider's, and every AI feature runs under zero data retention terms. Both are contractual commitments in our Terms and DPA.

Disclosure

Researchers and customers have a direct path to us

We publish a clear vulnerability disclosure policy, support encrypted reports, and use advisories and direct communication to coordinate remediation when issues affect customers.

AI Data Handling

Your data trains nothing

Noru is an AI platform running over the most sensitive material a company has — its controls, its evidence, its unresolved findings. That only works if the data goes one way: in to answer your question, and nowhere else.

01

We never train on your data

Your controls, evidence, policies, privacy records and prompts are never used to train, fine-tune or evaluate a model — not ours, not a provider's. Nothing you put into Noru makes a model better for anyone else. It is written into the Terms and the DPA, not left as a setting you have to find.

02

Zero data retention at the model layer

Every AI feature calls its model provider under zero data retention terms. Prompts and outputs exist only for as long as it takes to return your result: nothing is stored by the provider afterwards, nothing is queued for human review, nothing is retained for training. We will not engage a provider that cannot offer those terms.

Zero data retention describes the model layer. Noru stores the data you put into the platform in order to run it, under the retention and deletion terms in the DPA — customer-controlled deletion, and return or deletion within 30 days of termination.

Both commitments are contractual. See Section 4.6 of the Terms and Sections 3.5–3.6 of the DPA.

Responsible disclosure

From report to coordinated disclosure.

Submit a report, get an acknowledgement, move through validation and triage, then coordinate remediation and communication based on impact. Fast intake matters, but so does predictable follow-through.

01 · Report

Send the report

Email security@noru.tech, or encrypt the report with our PGP key. Reproduction steps, affected assets and impact indicators help us move faster.

02 · Acknowledge

Acknowledged within 24 hours

We confirm receipt and keep you informed while the report is being worked.

03 · Triage

Triaged within 3 business days

We validate the finding, assess severity, scope the remediation and tell you what we concluded.

04 · Coordinate

Coordinated disclosure within 90 days

Our target, adjusted when customer safety requires it. Remediation first, then publication timing agreed with you where possible. Affected customers hear from us directly, and through advisories.

What helps us validate fast

  • Clear reproduction steps and the impacted endpoints or workflows.
  • Evidence that distinguishes a real security boundary issue from expected behaviour.
  • Contact details for follow-up while remediation is in progress.

Good-faith research that follows the disclosure policy is authorised under its safe harbour. Prefer to encrypt? Our PGP key is published alongside its fingerprint.

Trust, settled.

Every control, every piece of evidence, continuously verified.