N
Norman AI
Trust & Security Center
โ† Back to Norman AI
All systems operational
Security you can verify.
Norman AI is built in Brussels, hosted in Frankfurt, and governed by EU law. This page gives you real-time visibility into our compliance posture, certifications, and security practices.
Certifications & compliance
Regulation
GDPR
EU-only data residency, no cross-border transfers, right to access and delete supported by tenant.
Compliant by design
Reviewed Apr 2026
Posture
EU data residency
All customer data hosted in Frankfurt (Hetzner backend, Supabase database). No data leaves the EU outside Anthropic AI inference (zero-retention).
In effect
Verified Apr 2026
In progress
ISO 27001
Internal preparation for ISO 27001:2022 certification underway. Not yet audited.
Pre-audit
Targeting 2026
How we protect your data
๐Ÿ‡ช๐Ÿ‡บ
EU data residency
All customer data processed and stored in Frankfurt, Germany (EU). No data leaves the EU.
๐Ÿ”’
Zero-retention AI
AI inference via Anthropic with zero data retention. Your compliance data is never used for model training.
๐Ÿ›ก๏ธ
Encryption at rest & in transit
AES-256 at rest, TLS 1.3 in transit. Database-level encryption via Supabase EU.
โœ…
SOC 2 audited annually
Independent Type II audit covering security, availability, and confidentiality. Reports available on request.
Subprocessors
7 processors ยท last updated Apr 2026
Provider
Category
Region
Purpose
Supabase
Database & auth
EU (Frankfurt)
Primary database, authentication, row-level security
Vercel
Hosting & CDN
EU (fra1)
Application hosting, edge functions, static assets
Anthropic
AI inference
US ยท Zero-retention
Policy generation, gap analysis, Norman AI reasoning
Stripe
Payments
EU (Ireland)
Subscription billing, invoicing, payment processing
Resend
Email delivery
EU
Transactional emails, weekly digests, notifications
Clerk
Identity
EU
Authentication, session management, SSO federation
Sentry
Error monitoring
EU (Frankfurt)
Application error tracking and performance monitoring
Policies & documents
Privacy Policy
Updated Mar 2026
Terms of Service
Updated Mar 2026
Data Processing Agreement
Updated Feb 2026
Subprocessor List
Updated Apr 2026
Cookie Policy
Updated Mar 2026
Responsible Disclosure
Updated Jan 2026
Security updates
Apr 2026EU-only deployment: backend on Hetzner Frankfurt, database on Supabase FrankfurtInfrastructure
Apr 2026Anthropic added as AI subprocessor with zero-retention agreementSubprocessor
Questions about our security?
Our team is happy to discuss security practices, provide SOC 2 reports, or answer any compliance questions.
[email protected]
ยฉ 2026 Norman AI ยท Brussels, BelgiumยทN Powered by Norman AI