Security & Trust

Workforce intelligence only works when the data behind it is trusted.

NORM combines workspace isolation, least-privilege access, explicit sensitive-data controls, auditable evidence and deterministic calculation to protect the information behind workforce decisions.

We explain what we use, why we use it and which controls are actually implemented — without overstating protections or certifications that do not belong to NORM or Impulso Advisors.

Workspace isolationLeast privilegeExplicit sensitive-data accessRelease provenance
Trust model

Protection follows the data — and the decision.

NORM separates authentication, workspace membership, permissions, sensitive-response access, model evidence and release integrity instead of collapsing them into one broad admin concept.

01

Customer workspace boundaries

Tenant and project scope is carried through the application and database layer. Access is not based on obscurity or knowledge of a record identifier.

02

Least-privilege collaboration

Users receive roles and capabilities intentionally. Sensitive individual data remains behind an additional explicit permission boundary.

03

Evidence before interpretation

Completion, model readiness, workload evidence, confidence and deterministic norm output are kept distinct so management can see what an answer is built on.

04

Exact release provenance

NORM production is accepted only when the approved Git SHA, deployed commit and automated release evidence agree.

Trusted infrastructure

Built on independently audited providers.

Provider certifications and attestations apply within each provider's own compliance scope. They do not constitute SOC 2 or ISO certification of NORM or Impulso Advisors.

01
SUPABASE

Database · Authentication · Edge Functions

NORM uses Supabase for its PostgreSQL data layer, email/password authentication, authenticated data access and selected Edge Functions such as workspace invitations.

Provider security & compliance ↗
SOC 2 Type 2ISO/IEC 27001
02
NETLIFY

Application hosting · Delivery

NORM is built and served on Netlify. Production publishing is additionally protected by NORM's own exact-release approval gate and automated verification.

Provider security & compliance ↗
SOC 2 Type 2ISO/IEC 27001ISO/IEC 27018PCI DSS v4.0
03
OPENAI

Selected AI-assisted suggestions

NORM uses OpenAI API services only for selected assistive workflows, such as activity drafting and role-to-reference-library matching. The deterministic norm calculation does not depend on an LLM.

Provider security & compliance ↗
API business data not used for training by defaultSelected workflows only
04
RESEND

Authentication email delivery

Supabase Auth uses a verified NORM sender through Resend custom SMTP for confirmation, password recovery and workspace invitation emails.

Provider security & compliance ↗
SOC 2 Type IIGDPR
How we protect access

Knowing where data lives is not permission to see it.

Authorization is evaluated using authenticated identity, membership, scope and permission logic. Sensitive response access is deliberately narrower than general workspace administration.

01

Workspace-level separation

Customer data is scoped by tenant and project. Row Level Security and authenticated database/RPC checks reinforce workspace boundaries.

02

Role + explicit permissions

Membership roles and explicit permissions are separate controls. A job title or broad admin label does not silently grant every capability.

03

Sensitive response access

Individual response access requires a separate explicit permission. It is not automatically granted to ordinary administrators.

04

Authentication hardening

Production email/password authentication includes leaked-password protection, verified sender delivery, confirmation, recovery and invitation flows.

05

Audit and immutable evidence

Key lifecycle actions are recorded in audit data, while successful calculation runs and report snapshots preserve traceable evidence instead of overwriting history.

06

Release integrity

Production publishing is tied to an approved exact Git commit, automated verification and a production smoke check before the release is accepted.

AI & your data

AI can suggest. It cannot redefine the norm.

NORM keeps assistive AI workflows separate from the deterministic workforce calculation and from customer approval. AI output is input to a controlled workflow, not an automatic management decision.

AI MAY

Assist selected workflows

Generate activity drafts, propose role-to-reference-library matches and support selected analysis where the user initiates the workflow.

AI DOES NOT

Calculate or silently approve the norm

The norm FTE engine remains deterministic. AI does not bypass workspace permissions, replace workload/capacity evidence or silently turn a suggestion into accepted customer data.

OpenAI states that business/API data is not used to train its models by default. This page does not make a Zero Data Retention claim unless the relevant account-level control is separately verified.
Release integrity

The production release is a verifiable state, not a guess.

Approved exact Git SHA=Production deploy commit+Verify + production smoke
Unapproved main commits are blocked from publishing by the production release guard.
Security questions

Straight answers to the questions we expect.

Security information is reviewed as the production architecture, provider configuration and data flows evolve. For security, privacy or enterprise due-diligence questions, contact meet@impulsoadvisors.com. For a suspected vulnerability, put SECURITY at the beginning of the subject so it can be prioritized correctly.

Can another customer see my workspace data?

Not by simply knowing a URL or record identifier. Access is evaluated through authenticated identity, workspace membership, tenant/project scope and database-level authorization controls.

Can an administrator automatically see individual responses?

No. Sensitive individual-response access is a separate explicit permission and is intentionally not implied by an ordinary admin role.

Is NORM itself SOC 2 or ISO 27001 certified?

No such claim is made. Certifications and attestations shown on this page belong to the respective infrastructure providers and apply within each provider's own compliance scope.

Is my data used to train OpenAI models?

OpenAI states that business/API data is not used to train its models by default. NORM uses the API only in selected assistive workflows; deterministic norm calculation remains separate.

How is a production release controlled?

NORM compares the production build commit with an explicitly approved full Git SHA. Automated verification and a remote production smoke test provide additional release evidence.

How do I report a security vulnerability?

Email meet@impulsoadvisors.com with SECURITY at the beginning of the subject. Please do not send passwords, raw API keys, session cookies or unnecessary customer data. Reports are handled under the NORM vulnerability-disclosure and incident-response process.

Trust before rollout

Need to complete enterprise due diligence?

We can walk through NORM's architecture, access model, data flows and release controls with your IT, security or procurement team.

Security & due diligence