Security & trust

Built to be audited, not just trusted.

Northgale processes the evidence behind consequential AI decisions. That makes security and auditability the product — not an afterthought.

Encryption in transit & at rest

All traffic is encrypted with TLS. Data at rest is encrypted with AWS KMS-managed keys across databases and object storage.

Least-privilege access

Access is granted through identity federation and scoped IAM roles. No long-lived root credentials are used for operations.

Secrets management

Credentials and secrets are stored in AWS Secrets Manager and never committed to source control.

Authentication

Sign-in is handled by Amazon Cognito with per-environment user pools and JWT-verified service access.

Audit logging & retention

Every explanation writes an immutable audit record. Retention is configurable by plan, up to unlimited on Enterprise.

Infrastructure isolation

The platform runs on AWS with per-environment isolation and encrypted, dedicated databases.

Compliance posture

Norma maps its audit trail to the frameworks that govern AI in regulated industries:

  • NIST AI RMF — Govern, Map, Measure, Manage
  • EU AI Act — transparency & high-risk logging
  • CFPB — adverse-action documentation
  • EEOC — non-discrimination & explainability

Enterprise plans include SOC 2 reports and a custom DPA under NDA. See our subprocessors and DPA for details.

Have a security question?