Norami Trust CenterRequest access

Operated by AI BLU, LLC · United States

Norami

A current view of our security controls, privacy and compliance posture, sub-processors, and documents available for customer review.

Last reviewed July 15, 2026

Controls

Reviewed Jul 15, 2026
Ask about a control

Infrastructure security

  • Encryption in transit & at rest

    TLS 1.2+ in transit; AES-256 at rest via Supabase.

  • Tenant isolation

    Postgres Row-Level Security is enforced at the database layer.

Product & access security

  • Access control & audit logging

    Scoped roles; security-relevant actions are audit-logged.

  • Vulnerability monitoring

    Dependabot alerts and automated security fixes are enabled.

Incident response

  • Breach notification

    Affected customers are notified without undue delay; internal escalation targets support applicable regulatory timelines.

Assurance roadmap

  • SOC 2 Type II

    In progress

    Targeted; Norami is not yet certified.

  • Third-party penetration test

    Planned

    Scheduled near the first enterprise close.

Processor posture

Norami (AI BLU, LLC) acts as a data processor for customer data.

  • GDPR customer DPA

    In place

    Processor-signed DPA published; it becomes binding when accepted by the customer.

  • EU→US transfer basis

    In place

    EU SCCs (Module 2) are included in the DPA; a Transfer Impact Assessment is maintained.

  • Sub-processor transparency

    In place

    Public list with 10 business days’ notice.

  • Data-subject rights

    In place

    Access, export, and erasure are implemented.

  • Record of Processing Activities

    In progress

    The internal Article 30 record is being finalized.

  • EU Representative

    Planned

    Applicability review and appointment before targeted EU offering.

US infrastructure. EU transfers rely on SCCs + a TIA, not EU data residency or DPF certification.

Sub-processors

14 listed

Third parties that process data on our behalf, the service each provides, and where processing takes place.

View canonical list
Workspace owners receive at least 10 business days' notice before a sub-processor is added or replaced, with a right to object on reasonable grounds.
Sub-processorPurposeLocation
AnthropicAI model processing — generating answers from your dataUnited States
OpenAIAI model processing and text embeddingsUnited States
CohereAI reranking of retrieved document excerptsCanada (service provider); United States (hosting)
LlamaIndex (LlamaParse)Document parsing and OCR for uploaded filesUnited States (EEA region available)
E2BSandboxed code execution for data analysisUnited States
SupabaseApplication database, authentication, and file storageUnited States
WorkOSOptional enterprise SSO and directory synchronization for authentication and account provisioningUnited States
VercelApplication hosting and serverless computeUnited States (global edge)
RailwaySpreadsheet ingestion worker — parses uploaded spreadsheets into the queryable row indexUnited States
CloudflareNetwork, DNS, and the secure data-ingestion tunnelGlobal
SentryApplication error monitoring and crash reportingUnited States
StripePayment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
PerplexityOptional business-context research at onboardingUnited States