/ SECURITY
Only the data you granted.
norami answers from inside your own workspace. Each assistant reaches only the datasets you linked to it, and every answer shows what it used.
- ISO/IEC 42001 compliant
- GDPR DPA with EU SCCs
- SOC 2 Type II in progress
[ WHERE WE STAND ]
What’s in place, and what isn’t yet.
We publish our status as it is. Reports, policies and the full list of controls live in the trust center.
OPEN THE TRUST CENTER- In place
ISO/IEC 42001
Compliant with the AI management system standard. This is not a certification claim.
- In place
GDPR
Processor-signed DPA with EU SCCs, a transfer impact assessment and an appointed EU representative.
- In progress
SOC 2 Type II
Targeted. norami is not yet certified.
- Planned
Penetration test
An independent third-party test is planned.
[ BUILT IN ]
Part of how norami answers, not added after.
Isolated per workspace
Each customer's data is scoped to its own workspace, with Row-Level Security switched on for every table.
Encrypted in transit and at rest
TLS 1.2 or newer in transit and AES-256 at rest. Database credentials get their own AES-256-GCM encryption.
Read-only by design
norami reads your data and never writes to it. Database sessions are read-only, and generated queries are single SELECT statements with row caps and timeouts.
A fresh sandbox for each answer
Python analysis runs in a new sandbox with no internet access and no credentials, shut down as soon as the answer is done.
[ HOW IT’S ENFORCED ]
Follow one question.
The same four checks run on every question, in the product itself.
[ THE DETAILS ]
The controls behind it.
Identity, access, data handling and the companies we rely on, stated plainly.
- Sign-in
- Email and password with two-factor authentication (TOTP), required for privileged areas. On Enterprise, SAML or OIDC single sign-on and SCIM directory sync, which admins can make mandatory.
- Roles and access
- Five workspace roles, from owner to viewer. People reach an assistant through their department or a direct grant, and each assistant reaches only the datasets linked to it.
- Audit log
- Sign-ins, role and access changes, uploads, connections, exports and deletions go to an append-only, hash-chained log. The database blocks edits and deletions.
- Connected databases
- Read-only sessions over TLS, single SELECT queries and a script for a read-only role. Credentials are encrypted with AES-256-GCM and never reach the AI model.
- Uploaded files
- Files go to private storage through signed links and are checked against their file type. Deleting a dataset removes its rows and, once nothing uses it, the original file.
- Sub-processors
- Every third party that processes your data is listed publicly with its purpose and location. Owners get at least 10 business days' notice before one is added or replaced.
- Incident response
- Affected customers are notified without undue delay. Dependency alerts and automated security fixes are on, and error reports are stripped of request bodies, cookies and user details.
- Where it runs
- US infrastructure. Transfers from the EU rely on the SCCs in our DPA and a transfer impact assessment, not EU data residency.
Does norami train AI models on our data?
No. norami does not use your workspace content to train AI models. Every AI provider we use is listed in the trust center with what it receives and why.
Can norami change the data in our systems?
No. Database connections open read-only sessions over TLS, custom queries must be a single SELECT, and we provide a script for a read-only role. norami copies rows on the schedule you set and answers from that copy, so the AI model never queries your database or sees its credentials.
Who in our company can see what?
Admins decide. People reach an assistant through their department or a direct grant, and each assistant can only query the datasets linked to it. That list is checked on the server for every query.
Where is our data stored?
In the United States, encrypted at rest and scoped to your workspace. For EU customers, transfers are covered by the EU SCCs in our DPA and a transfer impact assessment. We don't offer EU data residency today.
Do you support single sign-on?
Yes, on Enterprise: SAML or OIDC single sign-on with SCIM directory sync, which admins can require for everyone. Two-factor authentication is available too, and required for privileged areas.
What happens to our data if we leave?
The workspace owner can export everything first. Deleting a workspace starts a 30-day grace period, after which the data is erased and the erasure is recorded in the audit log.
Can we see a SOC 2 report or pen test results?
Not yet. SOC 2 Type II is in progress and a third-party penetration test is planned. The trust center shows the current status of both, and our DPA with EU SCCs is available today.
[ Get started ]
See norami on
your real data.
Tell us about your data and we'll get in touch to arrange a walkthrough. Prefer to explore on your own? Create your workspace and bring your data in minutes.