Security is foundational to what NORA does. We are asking your organization's asset owners to share candid information about your systems and controls. We take seriously the responsibility that comes with that trust, and we apply the same rigor to securing your data that we ask you to apply to securing your own systems.
Your data is encrypted in transit using TLS 1.2 or higher. Your data is encrypted at rest. Access to customer data is restricted to authorized personnel with a demonstrated need. We do not store payment card information — payment processing is handled by a PCI-compliant third party.
Your risk assessment responses, scores, and narratives are your data. We do not use your assessment content to train models, benchmark against other customers, or share with any third party except as required to provide the service. Each customer's data is logically isolated from other customers.
NORA uses Anthropic's Claude models to turn assessment answers into scores and narratives. That content is sent directly to Anthropic's API — not through a third-party AI reseller or a shared AI layer — and only to generate your assessment output. Anthropic acts as our subprocessor for this step, and by default does not use data submitted through its commercial API to train its models.
NORA runs on Base44's managed infrastructure. Base44 maintains physical and network security controls for the underlying platform. We rely on their infrastructure security and apply additional application-level controls on top of it.
If you believe you have found a security vulnerability in NORA, we ask that you report it to us responsibly before public disclosure. Please send details to security@norarisk.com. We will acknowledge your report within two business days and work with you to understand and address the issue.
For security questions or to report a vulnerability, contact security@norarisk.com.