Security and data processing

Trust takes
more than a promise.

You handle confidential information. Here is the basis for assessing Nordivé: data flows, access, AI and the agreements behind the service.

Controls

Protection in layers.

Data handling & storage

What we store — and what we never store.

No content stored by us

Email content is not stored by Nordivé. Results are stored in the firm’s own OneDrive.

Stateless for client data

No database of email, documents or case content — it is processed in memory and discarded.

You stay in control

Nothing is sent without your explicit approval.

Data deletion on request

Account and usage data is deleted within 30 days of the agreement ending, and logs after 90 days.

AI & inference

How the legal AI runs.

AI inference in the EU

Terra and Sol in Azure OpenAI (EU data zone, Sweden) and Claude through AWS Bedrock (Ireland).

No storage by Bedrock

AWS Bedrock does not store requests or responses. Azure OpenAI processes them in the EU and may temporarily retain selected requests for abuse monitoring.

No training on your data

Your data is never used to train models.

Human oversight

All drafts are presented for review before use.

Infrastructure & encryption

Where data resides and how it is protected.

Backend in Norway East

Microsoft Azure, Norwegian data centre region.

Within the EU/EEA

No data transfers outside the EU/EEA.

Encrypted in transit

All traffic over TLS 1.2+.

Encrypted at rest

AES-256 for stored account and operational data.

Access control

Who can do what.

Microsoft SSO (Entra ID)

No new passwords — sign in with your existing account.

MFA under your firm’s policies

Two-factor authentication and conditional access are managed through your firm’s Microsoft 365.

Role-based access

Least privilege by default.

No shared accounts

All access is personal and traceable.

Legal & compliance

GDPR, confidentiality and responsibility.

Data processing agreement (Article 28)

Signed before onboarding.

You are the data controller

Nordivé is the data processor — you retain responsibility.

Confidentiality protected

Designed around lawyers’ duty of confidentiality.

Norwegian Bar Association guidelines

Built in line with industry requirements.

Operations & preparedness

Monitoring, incidents and uptime.

24/7 monitoring

Continuous infrastructure monitoring.

Incident response

Defined procedures with notification within the stated timeframes.

Uptime & SLA

Targets for availability and response times.

About certifications

Nordivé is not ISO 27001 or SOC 2 certified. Provider certifications do not constitute certification of Nordivé. Independent certification is planned from 50 paying customers.

Data flow

Know where your work is processed.

Email, documents and case content are processed in memory. Account and operational data, such as usage counters and cost logs, are stored separately. Content you send to support may also be stored; avoid including client information.

Analysis results are stored in the firm’s own OneDrive. The technical documentation describes local storage, OneDrive, encryption keys and data flows in detail.

01

Your firm’s Microsoft environment

Email, documents and identity.

02

Nordivé

Workflow and processing. Backend in Azure Norway East.

03

AI in the EU

Azure OpenAI in the EU data zone and AWS Bedrock in Ireland.

Read the technical documentation ↗

Nordwatch: work memory
under your control.

Nordwatch is a pilot connected to time tracking. When enabled, it reads screen text from selected work applications and permitted websites. Document titles, visible content and timestamps can provide a better basis for describing your work. The feature does not record audio.

What is stored on my device?

Work memory is encrypted and stored locally, with a key protected by the operating system. History is automatically cleared after up to seven days or when the 250 MB storage limit is reached. Screenshots are used to read text and then discarded. On Mac, you can choose to retain screenshots; they are then stored encrypted on your device.

What happens when I turn Nordwatch off?

You can turn screen memory off in the sidebar. This stops new captures but does not delete existing history. History can be deleted separately or through automatic cleanup. Time entries already created are retained. Regular time tracking and the timer can still be used.

What options are available for AI processing?

Without AI (default). Suggestions are generated on your device using fixed rules. No automatic switch to the cloud.

Sol in the cloud — not yet enabled for customers. Requires an explicit choice and firm-level activation. Selected text is masked locally before being sent through Nordivé to Sol on Microsoft Azure in the EU. Screenshots are not sent in this analysis workflow.

AI off. No AI analysis. Screen memory is controlled separately by “Remember screen work”.

Is masked text anonymous?

Not necessarily. Masking reduces exposure of names, contact details and identifiers, among other data, but does not guarantee anonymisation. Sensitive information may remain in the text. Descriptions you choose to add to a time entry follow Nordivé’s normal sync process.

What should I check before using a suggestion?

AI suggestions should be based on observations. Check the description, matter and duration before use. Nordwatch does not know what you are thinking, and screen observations alone are not proof of billable time. The pilot provides no documented guarantee of greater accuracy. Summaries and more precise source views are not advertised here as available.

Providers

Who is part of the service?

This overview is based on Nordivé’s published security documentation. The full list and contractual basis are reviewed before onboarding. Microsoft Azure, AWS and Microsoft Entra ID are covered by data processing agreements (DPAs). Terra and Sol run in Azure OpenAI’s EU data zone. Claude is used through Bedrock, which does not store requests.

ProviderRoleProcessing location
Microsoft AzureBackend and infrastructureNorway East
Microsoft Entra IDSign-inEU
Microsoft Azure OpenAIAI inference (Terra, Sol)EU data zone (Sweden)
AWS BedrockAI inference (Claude)Ireland
VercelWebsite and web application hostingEuropean nodes
Anthropic / ClaudeAI model through BedrockEU through AWS

Documentation

For your firm’s own assessment.

Questions and answers

What you should know.

How is confidentiality protected?

Email content is not stored by us, and AI providers do not use it for training. Results are stored in your firm’s own OneDrive. We sign a data processing agreement under GDPR Article 28 before onboarding, and you remain the data controller throughout.

Where is our data stored?

The entire backend runs in Norway East (Microsoft Azure). AI inference takes place in Azure OpenAI’s EU data zone (resource in Sweden) and AWS Bedrock in Ireland. Nothing leaves the EU/EEA, and email content is not stored by us.

Do you store email or client data?

No. We have no database of email, documents or case content — it is processed in memory and discarded. We store operational data: usage counters, a cost log per AI request, the access list, support threads you initiate, encrypted sign-in keys if you enable background analysis, and call data (numbers and durations) for 90 days if your firm connects its telephone system. Support is the one place client content may end up, because you can paste an email or attach a document to show us an issue. We ask you not to, but cannot prevent it, and we say so rather than promising it cannot happen.

Is data used to train AI models?

No. Your data is never used to train models, by us, Microsoft or AWS.

Where does AI inference run?

Terra and Sol run in Azure OpenAI’s EU data zone (resource in Sweden). Claude runs through AWS Bedrock in Ireland. AWS Bedrock does not store requests or responses, and Microsoft processes them in the EU.

Is data encrypted?

Yes. All traffic is encrypted in transit (TLS 1.2+), and stored account and operational data is encrypted at rest (AES-256).

How do users sign in?

Through Microsoft SSO (Entra ID), with MFA under your firm’s own rules — no new passwords, and all access is personal and traceable.

Who has internal access to the data?

Access is role-based under the principle of least privilege. There are no shared accounts, and no one receives access to client content without a genuine need.

Do you sign a data processing agreement?

Yes. A data processing agreement under GDPR Article 28 is signed before onboarding.

Who is the data controller?

You are. Nordivé is the data processor; you retain responsibility for personal data throughout processing.

Does data leave the EU/EEA?

No. The backend (Norway East) and AI inference (Azure OpenAI in the EU data zone and AWS Bedrock in Ireland) are within the EU/EEA. No transfers outside the EU/EEA.

Get to know Nordivé

See what you can capture.
And what you can make time for.

See how time tracking and email can fit
into your working day. We will show you the product.

Try free for 30 days