Compliance automation
Norven runs SOC 2, ISO 27001, Israeli Privacy Law (Amendment 13), and GDPR on a single continuous record — built for security teams that have to pass the audit and ship the product in the same week.
No credit card · Auditor seats always free · 14-day trial
Program readiness
Implemented
279
Partial
37
Not implemented
12
SOC 2 Type II
142 / 169 controls
ISO 27001:2022
66 / 93 controls
Israeli Privacy Law (Amendment 13)
47 / 51 controls
GDPR
24 / 63 controls
Connect the stack you already run
One practice, every framework
A single implementation — MFA, encryption at rest, access reviews — satisfies the equivalent requirement in every framework you carry. Norven keeps the map current so adding a second or third framework is not a second project.
Trust Services Criteria, Type I or Type II. Continuous evidence collection mapped to CC and A categories.
Read the framework guideAnnex A aligned to the 2022 revision. Statement of Applicability with versioned applicability rationale.
Read the framework guideAmendment 13-ready. Privacy Protection Authority requirements as a first-class framework — not a footnote.
Read the framework guideArticle-29-aligned data-protection controls, Records of Processing, and DPIA workflow.
Read the framework guideHow it works
OAuth into the systems you already run — AWS, Google Workspace, Okta, GitHub, Microsoft 365, the rest. Tokens land in Supabase Vault, never in a database column.
Evidence flows in on schedule, hashed on ingest, immutable thereafter. You see what changed and when, in plain English and Hebrew.
Board updates, customer trust reports, auditor evidence packs — each one a real export, not a screenshot of a dashboard. Auditor seats are scoped, read-only, and free.
What sets Norven apart
Board update, customer trust report, auditor evidence pack — generated, not formatted by hand. The professional looks competent without burning the weekend.
Built English-first for the world, with Amendment 13 of the Israeli Privacy Law as a first-class framework and full Hebrew + RTL support. No "international edition" coming later.
Your auditor logs in with a scoped, read-only seat. We never charge for the people whose job is to verify your work.
When you are ready
Free for fourteen days. No credit card. Connect your stack and Norven starts pulling evidence the same hour.