Norven
Start free trial

Security

How we protect the evidence you trust us with.

Norven is a compliance product. A bug here is not "oops" — it is a breach of the trust we sell. The controls below are P0 always, not best-effort.

Engineering posture

Six commitments, enforced in CI.

Per-tenant isolation

Every tenant-scoped table is protected by Postgres Row-Level Security. Cross-tenant joins are forbidden outside platform-admin tooling. A tenant-isolation test for every table is mandatory at PR time.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Per-tenant data encryption keys, with customer-managed encryption keys (CMEK) on the Enterprise tier.

Secrets in Vault, never in env

Customer OAuth tokens, API keys, and service-account JSONs live in Supabase Vault. Direct env access for customer credentials is a code-review block. Secrets never appear in logs or error messages.

Immutable evidence

Evidence artifacts are hashed on ingest with SHA-256 and stored append-only. "Deletes" are soft-deletes recorded with reason, actor, and timestamp — the original record remains for the retention window.

Audit log of audit logs

Every read and write of evidence is recorded in an append-only audit_log table, separate from application logs. The audit trail is itself the artifact your auditor reviews.

MFA enforced for admins

Multi-factor authentication is required for all admin roles. SAML SSO available on Enterprise. Magic link + Google SSO for everyday access.

Current state

Where we are, today.

We are honest about what is in production versus what is on the roadmap. If a row reads "In progress," it means exactly that — not a marketing dodge.

Hosting
Cloudflare + Supabase (eu-central) · Tel Aviv residency on Enterprise
SOC 2 Type II
In progress · Type I bridge planned
ISO 27001:2022
On the roadmap
Penetration tests
Annual third-party · ad-hoc on major releases
Backups
Continuous WAL · 35-day point-in-time recovery
Uptime target
99.9% rolling 30-day

Report a vulnerability

Good-faith research is welcome. Get in touch.

Send disclosures to security@norven.app. We acknowledge within 24 hours, never penalize good-faith research, and credit researchers who request it.