Noru

Get certified · Stay certified

Get certified. Stay certified. Let the agents do the work.

ISO 27001, SOC 2, GDPR, NIS2, DORA and 30+ frameworks in total, run as one program. Noru's agents map the controls, draft the policies, gather the evidence from the systems you already run and catch what drifts — your team reviews and approves. The certificate your buyer is asking for, without the six-month spreadsheet.

Companies that run their compliance program on Noru

The way this usually goes

The deal is waiting on a certificate, and the program is a spreadsheet, a folder of screenshots and one person's calendar.

Audit prep turns into a month of chasing owners for evidence that already exists somewhere in your systems.

You pass, then drift — and the surveillance audit next year starts the scramble over from the beginning.

From kickoff to certificate

The path to certified, and the part after it.

Certification is not a project you finish; it is a state you have to keep being in. Noru runs both halves — the push to the first certificate, and the year of upkeep that decides whether the second one is easy.

01 · Scope

Pick the framework

ISO 27001, SOC 2, or both at once. Noru loads the control library, maps it against what you already have in place, and shows you the gap on day one instead of after a consultant's assessment.

02 · Close

Close the gaps

Agents draft the policies, map each control to the clause it satisfies, and open the remaining work as tasks with owners — so getting certified is a list, not a research project.

03 · Prove

Collect the proof

Evidence syncs continuously from AWS, GitHub, Entra ID and the rest of your stack, linked to the controls it satisfies as it arrives. Nobody takes screenshots.

04 · Audit

Pass the audit

Your auditor asks for a control. It is already mapped, already evidenced and already dated — so the week before the audit looks like every other week.

05 · Stay

Stay certified

Drift is caught the day it happens and the next task opens on its own, so the surveillance audit in year two is not year one all over again.

Add the next framework and it reuses the controls and evidence you already built
With Noru, we went from onboarding to completed ISO 27001 certification in just two weeks, following a clear and structured path from day one.
Ossus
Cortex/Review queue
4 need review

You approve everything

Nothing publishes itself.

Agents propose; your compliance lead accepts, edits or dismisses. Every item names the clause it touches and the data it was drawn from, so approving it is a judgment call rather than an act of faith — and it is the approval, not the draft, that enters your program and goes in front of your auditor.

  • Every output is a reviewable draft, attributable to what prompted it
  • Full audit trail of what changed, who approved it and when
  • Your program is never used to train, fine-tune or evaluate a model
  • Every model call runs under zero data retention at the model layer

Coverage

The standard your buyer is asking for, and the next one.

One control library across 31 frameworks. Implement a control once and the evidence you already collect carries every standard you add — so the second certificate costs a fraction of the first.

EU regulatory

The obligations most platforms treat as an afterthought. Agents map them onto controls you already run, then track the reporting and resilience deadlines as live work.

  • DORADORA
  • DORA (ICT TPP)DORA (ICT TPP)
  • DORA (Critical ICT TPP)DORA (Critical ICT TPP)
  • NIS2NIS2
  • EU Cyber Resilience ActEU Cyber Resilience Act
  • PSD2PSD2

AI governance

An AI register that assembles itself from your repositories, with classification and disclosure decisions attributed to the person who made them.

  • ISO 42001ISO 42001
  • EU AI ActEU AI Act

Certifications & control frameworks

Map a control once and the evidence carries every standard you add. Agents watch for drift between audits and open the next task before a finding does.

  • ISO 27001ISO 27001
  • SOC 2SOC 2
  • PCI DSS 4.0PCI DSS 4.0
  • NIST CSFNIST CSF
  • CIS v8CIS v8
  • ISO 27017ISO 27017
  • ISO 27018ISO 27018
  • ISO 22301ISO 22301

Privacy & data protection

Records of processing derived from the systems that hold the data, with assessments that fire on the signal rather than on the calendar.

  • GDPRGDPR
  • CCPACCPA
  • HIPAAHIPAA

Also covered

  • BSI C5
  • ENS
  • Cyber Essentials
  • Svensk e-legitimation
  • FedRAMP Moderate
  • FedRAMP Tailored
  • TX-RAMP L1
  • IRAP
  • ISMAP
  • MAS
  • KFSI
  • MLPS

Built from your systems

The registers an audit runs on, already written.

A certificate does not come out of one thing. It comes out of an asset register, a vendor list, a personnel record, findings, certificates and dated evidence, all current at the same time — and the reason that is hard is that every one of them is normally a document somebody has to remember to update. Connect your stack once and they are built from it instead, rewritten on every sync.

8registers kept current, filled from the data sources you connect

Every record keeps the source and the sync it arrived on

  • Asset register

    Every compute instance, container, database, bucket, repository and endpoint your connected accounts contain — typed, grouped and owned, each one keeping the provider, account and region it was discovered in.

  • Vendor register

    Sub-processors and suppliers detected from the applications your identity provider and code host actually authorise, each one carrying the evidence that found it and a confidence you can overturn.

  • Personnel record

    Joiners, leavers, roles and group membership, reconciled across every connected system into one identity per person — so an access review starts from a list that is already right.

  • Evidence vault

    Configuration, policy, access and logging evidence, dated as it arrives and mapped to the controls it satisfies on the way in rather than in a scramble the week before the audit.

  • Security findings

    Vulnerabilities and misconfigurations from your scanners and from your clouds' own security services — AWS Security Hub, GCP Security Command Center — landing where they can be linked to a risk and given an owner.

  • Certificate and domain inventory

    Hostnames discovered during sync — ACM certificates, Cloud DNS zones, App Service bindings — registered for certificate monitoring, so an expiry becomes a task instead of an outage.

  • Training record

    Course completions matched against the personnel record and against the campaign they belong to, with a plan nobody has set up yet provisioned rather than dropped on the floor.

  • Document inventory

    Policies and procedures collected from where your documents actually live, with location and filename used to infer the control each one supports before anybody maps it by hand.

Ask in plain language

Your program, answerable from wherever you work.

What is at risk today, what will the auditor want, which vendor is overdue for reassessment — asked in Claude, ChatGPT, Cursor or your terminal, and answered from your live program with the record it came from attached. Your existing Noru API key, no new infrastructure.

  • One connection, authorised by the API key you already issued
  • Answers cite the evidence, control or vendor they came from
  • Guardrails in the IDE: review a change against live control state
~/acme-platform — claude
  • Cursor
  • Claude
  • ChatGPT
  • Microsoft Copilot
  • Perplexity
  • Raycast
  • OpenCode icon
  • Zapier
  • n8n
  • Make

For engineering-led teams

A program you can build, not a binder you maintain.

If your team would rather work in a repository than a dashboard, the whole platform is an API and an MCP server — and the last mile ships as open-source pieces. Compliance built the way software is: version-controlled, reviewable, continuously validated. None of it is required — the same program runs from the app.

A piece does the local work — reading the repo, the pipeline, the laptop — then diffs against what Noru already holds and pushes only what changed.

# Claude Code or Codex, in the repo you want covered/evidence-push:scan   # find artifacts for unmet expectations/evidence-push:diff   # compare against what Noru holds/evidence-push:push   # land it, for review# every claim carries who decided it, when, and why#   owner: security-lead#   decided_at: 2026-08-31#   expires_at: 2027-08-31

Open source · MIT

The last mile runs where the work lives

Some compliance work cannot be done by a server-side integration — it lives in a repository, a pipeline or a laptop. Noru publishes those as open pieces for Claude Code and Codex: each runs :scan, :diff and :push, and every claim they land carries an owner, a date and a rationale.

  • ai-inventoryModel calls, agents, prompts and evals, found in the repo
  • evidence-pushLocal artifacts pushed against unmet evidence expectations
  • privacy-datamapSchema and personal-data categories mapped from source
  • iac-scanInfrastructure and pipeline configuration, read in place
  • change-controlSegregation of duties, proven from the change history
  • governance-recordsMeeting minutes, audit plans and decisions, recorded
  • review-signoffHuman attestation captured against machine output
  • audit-packArtifacts and workpapers bundled for one framework
  • noruThe hub — connect, doctor and context for every piece
Browse the pieces on GitHub

Evidence your auditor accepts

Don't ask your auditor to take the agent's word for it.

The first question anyone asks about AI-gathered evidence is how you know it is real. Open any evidence item and its Integrity row answers: the fingerprint taken the moment it was captured, when that was, and what produced it — a connected tool reading a provider's API, a person uploading a file, or Noru's own records. Then press the button and find out whether it still matches.

  • It says “Sealed”, not “Verified”, until someone checks — a digest recorded at capture proves what was captured, not that nothing changed since
  • One click recomputes it and answers plainly: unchanged since capture, or changed
  • Provenance in words, not codes: what produced it, how it was collected, and when
  • Items that predate integrity capture hide the row instead of claiming a verdict nobody can act on
Evidence/NORU-EVD-2841

Who it's for

One system, every stakeholder

Compliance & GRC

Controls mapped, policies drafted and evidence gathered continuously — you approve, rather than chase.

Security & CISO

One program behind every certificate and every security review, with drift caught the day it happens.

Engineering

No screenshot requests. Evidence comes out of the systems you already run, over an API and an MCP server.

Founders & leadership

The certificate that unblocks the deal, and a program that holds it without hiring a compliance team.

Data sources

Connect the systems you already run.

Identity, cloud, code and security tools, connected with read-only scopes and synced on a schedule rather than collected by hand before an audit. Every provider states what it reads before you connect it, and what it collects lands dated in the evidence vault with the integration that produced it named on the record.

  • Identity and people

    4
    • GoogleGoogle Workspace
    • HaileyHRHaileyHR
    • JungleMapJungleMap
    • MicrosoftMicrosoft Entra ID
  • Cloud and infrastructure

    9
    • AWSAWS
    • CloudflareCloudflare
    • DatabricksDatabricks
    • GCPGoogle Cloud
    • MicrosoftMicrosoft Azure
    • Neo4jNeo4j Aura
    • NeonNeon
    • SupabaseSupabase
    • VercelVercel
  • Code and work

    6
    • ConfluenceConfluence
    • GitHubGitHub
    • GitLabGitLab
    • Google DriveGoogle Drive
    • LinearLinear
    • MicrosoftSharePoint & OneDrive
  • Security and monitoring

    2
    • DatadogDatadog
    • DetectifyDetectify

Book a demo

See it on your own data.

A walkthrough against the framework you are actually chasing, with your questions answered by practitioners.

  • 45 minutes, tailored to the frameworks and use cases you care about
  • Answers from practitioners, not a sales script
  • Leave with a concrete rollout plan — or a clear no-fit

We respond within one business day. No mailing lists, no spam.

FAQ

Frequently asked questions

What compliance leads and security teams ask before they let an agent near the program.

Talk to us

Can we actually get ISO 27001 certified with Noru?

Yes — it is what most customers arrive for. Noru is not a certification body and does not sell the audit: you appoint your own auditor, and Noru is where the program lives before, during and after. Lawline completed its first ISO 27001 certification with Noru as the operational hub for policies, controls and evidence, and Ossus describes going from onboarding to completed certification in two weeks. How long it takes you depends on how much is already in place.

How does the auditor see our evidence?

Through the mapping, not through a folder. Every control shows the evidence that satisfies it, when it was captured and what produced it, and audit-ready exports run per framework. The audits module plans internal and external audits against evidence that already exists, so preparation is a review rather than a collection exercise.

What do the agents actually do?

The work a person would otherwise do by hand. They map controls across the frameworks you carry, draft and map policies, gather evidence from your connected systems and link it to the controls it satisfies, flag a control the moment it drifts, and surface the next most valuable task. Each output is a reviewable draft — nothing enters your program, or reaches your auditor, without a human accepting it.

Every compliance vendor says “agentic” now. What is different here?

Three things you can check rather than take on trust. Reach: the agents work every area a certificate depends on — controls, evidence, policies, risk, vendors, privacy, training and audits — not a chat box over a few endpoints. Depth: the frameworks the category skips are first-class, including DORA with both ICT third-party regimes, NIS2, the EU Cyber Resilience Act, PSD2, ISO 42001 and the EU AI Act alongside ISO 27001 and SOC 2. Provenance: every evidence record carries a capture-time digest and a record of what produced it, so an auditor can check the agent's work rather than believe it.

How do you keep an agent from doing something it should not?

Two bounds, not one. Over MCP every tool is bound to a domain-scoped permission — read:controls, write:evidence — and a tool with no rule is unreachable rather than permissively scoped; inside the product, Cortex resolves org.read and org.write against the role of whoever is driving, so a viewer cannot update a control through an agent any more than through the UI. And nothing an agent produces is published by the agent — policies, mappings and evidence links land as drafts a person accepts, edits or dismisses, with the change recorded against them.

How do we know the evidence an agent gathered is real?

Open the item and check. Every evidence record is written with a canonical SHA-256 of its content, a SHA-256 of the stored file's bytes where there is a file, and a provenance record naming what produced it, how it was collected and when — and the evidence drawer shows all of it on an Integrity row. The row reads “Sealed” rather than “Verified” until somebody presses “Check it hasn't changed”, because a digest recorded at capture proves what was captured, not that nothing has changed since; pressing it recomputes the digest and answers unchanged or changed. The digests are computed where evidence is written and are never accepted from the caller, an upload may declare the SHA-256 it expects and a mismatch is rejected before anything is stored, and items that predate integrity capture hide the row rather than claiming a verdict nobody can act on.

Do we have to send our data to a model provider?

For a Cortex answer, the relevant program context goes to a model provider — and comes straight back. We run every model call under zero data retention terms: the provider returns the output and keeps no copy of the prompt or the response, nothing is queued for human review, and nothing is retained for training. Your data is never used to train, fine-tune or evaluate a model, ours or theirs. AI enrichment stays opt-in per organization, every suggestion is a draft until your team accepts it, and both commitments are contractual — Section 4.6 of the Terms and Sections 3.5–3.6 of the DPA.