Customer workspace boundaries
Tenant and project scope is carried through the application and database layer. Access is not based on obscurity or knowledge of a record identifier.
NORM combines workspace isolation, least-privilege access, explicit sensitive-data controls, auditable evidence and deterministic calculation to protect the information behind workforce decisions.
We explain what we use, why we use it and which controls are actually implemented — without overstating protections or certifications that do not belong to NORM or Impulso Advisors.
NORM separates authentication, workspace membership, permissions, sensitive-response access, model evidence and release integrity instead of collapsing them into one broad admin concept.
Tenant and project scope is carried through the application and database layer. Access is not based on obscurity or knowledge of a record identifier.
Users receive roles and capabilities intentionally. Sensitive individual data remains behind an additional explicit permission boundary.
Completion, model readiness, workload evidence, confidence and deterministic norm output are kept distinct so management can see what an answer is built on.
NORM production is accepted only when the approved Git SHA, deployed commit and automated release evidence agree.
Provider certifications and attestations apply within each provider's own compliance scope. They do not constitute SOC 2 or ISO certification of NORM or Impulso Advisors.
NORM uses Supabase for its PostgreSQL data layer, email/password authentication, authenticated data access and selected Edge Functions such as workspace invitations.
Provider security & compliance ↗NORM is built and served on Netlify. Production publishing is additionally protected by NORM's own exact-release approval gate and automated verification.
Provider security & compliance ↗NORM uses OpenAI API services only for selected assistive workflows, such as activity drafting and role-to-reference-library matching. The deterministic norm calculation does not depend on an LLM.
Provider security & compliance ↗Supabase Auth uses a verified NORM sender through Resend custom SMTP for confirmation, password recovery and workspace invitation emails.
Provider security & compliance ↗Authorization is evaluated using authenticated identity, membership, scope and permission logic. Sensitive response access is deliberately narrower than general workspace administration.
Customer data is scoped by tenant and project. Row Level Security and authenticated database/RPC checks reinforce workspace boundaries.
Membership roles and explicit permissions are separate controls. A job title or broad admin label does not silently grant every capability.
Individual response access requires a separate explicit permission. It is not automatically granted to ordinary administrators.
Production email/password authentication includes leaked-password protection, verified sender delivery, confirmation, recovery and invitation flows.
Key lifecycle actions are recorded in audit data, while successful calculation runs and report snapshots preserve traceable evidence instead of overwriting history.
Production publishing is tied to an approved exact Git commit, automated verification and a production smoke check before the release is accepted.
NORM keeps assistive AI workflows separate from the deterministic workforce calculation and from customer approval. AI output is input to a controlled workflow, not an automatic management decision.
Generate activity drafts, propose role-to-reference-library matches and support selected analysis where the user initiates the workflow.
The norm FTE engine remains deterministic. AI does not bypass workspace permissions, replace workload/capacity evidence or silently turn a suggestion into accepted customer data.
Security information is reviewed as the production architecture, provider configuration and data flows evolve. For security, privacy or enterprise due-diligence questions, contact meet@impulsoadvisors.com. For a suspected vulnerability, put SECURITY at the beginning of the subject so it can be prioritized correctly.
Not by simply knowing a URL or record identifier. Access is evaluated through authenticated identity, workspace membership, tenant/project scope and database-level authorization controls.
No. Sensitive individual-response access is a separate explicit permission and is intentionally not implied by an ordinary admin role.
No such claim is made. Certifications and attestations shown on this page belong to the respective infrastructure providers and apply within each provider's own compliance scope.
OpenAI states that business/API data is not used to train its models by default. NORM uses the API only in selected assistive workflows; deterministic norm calculation remains separate.
NORM compares the production build commit with an explicitly approved full Git SHA. Automated verification and a remote production smoke test provide additional release evidence.
Email meet@impulsoadvisors.com with SECURITY at the beginning of the subject. Please do not send passwords, raw API keys, session cookies or unnecessary customer data. Reports are handled under the NORM vulnerability-disclosure and incident-response process.
We can walk through NORM's architecture, access model, data flows and release controls with your IT, security or procurement team.