Security / Technical documentation

See how
your data is protected.

Architecture, encryption, operations and the agreements behind Nordivé. Find our detailed security documentation here.

Back to the security overview

How your data is handled

Nordivé has no database for email content. The backend runs on Azure in Norway East and sends AI requests to language models in the EU — Azure OpenAI (EU data zone, resource in Sweden) and AWS Bedrock (Ireland). Email content passes through in transit only and is not stored by us. Analysis results are stored in the lawyer’s own OneDrive, in Nordivé’s app folder.

AI models and storage

Email is sorted and replies are drafted using the Terra and Sol language models in Microsoft Azure OpenAI, deployed in the EU data zone. Document analysis uses Anthropic’s Claude Sonnet 4.6 and Opus 4.6, delivered through AWS Bedrock in Ireland. This means:

  • Nordivé does not store requests. Neither does AWS Bedrock; Microsoft may temporarily retain requests flagged by abuse monitoring within the EU.
  • Correspondence and documents are never used to train AI models.
  • Logs contain only technical metadata — never the content of client communications.
  • All inference takes place in the EU — no transfer to the US.

Built on ISO 27001-certified infrastructure

Microsoft Azure (ISO 27001, SOC 2 Type II)
AWS Bedrock (ISO 27001, SOC 2 Type II)
Vercel (SOC 2 Type II)
GDPR (Art. 28)
Norwegian Bar Association guidelines

Nordivé is not yet independently ISO 27001 or SOC 2 certified — as an early-stage company, we plan to begin SOC 2 Type I when we reach 50 paying customers. What we deliver today is built on infrastructure that is certified: Microsoft Azure (Norway East) for the backend, AWS Bedrock for AI inference and Vercel for the frontend. Client content is never stored by Nordivé. What we do store (operational data such as usage counters and support) is kept in the same certified Azure environments — never in a separate, uncertified storage solution. Full audit reports from our providers can be shared on request through their respective trust portals.

Access control and sign-in

Sign-in uses Single Sign-On with existing Microsoft 365 accounts. Your firm’s existing access control rules, multi-factor authentication and conditional access policies also apply to Nordivé. No new passwords or accounts.

OAuth follows the PKCE standard (without exposing passwords to us). Refresh tokens are encrypted locally using AES-GCM 256 and automatically deleted after 8 hours of inactivity or explicit sign-out.

Token revocation at sign-out — clarification: Microsoft Graph (our Outlook integration) does not support public refresh-token revocation for SPA applications. When you sign out, Nordivé immediately deletes the local copy, but the underlying refresh token at Microsoft remains until its natural expiry (typically 14–90 days) or until your IT administrator invalidates it through the Azure AD console (Sign-in > Revoke sessions, or a Conditional Access policy). For Google Gmail mode, we revoke the token at Google (oauth2.googleapis.com/revoke) at sign-out.

Browser security

The frontend is delivered with a strict Content Security Policy that blocks external scripts and iframes. X-Content-Type-Options: nosniff prevents MIME spoofing, and Permissions-Policy prohibits camera, microphone and location access (we do not need them). All AI output is rendered through React JSX, which automatically escapes content — no dangerouslySetInnerHTML in the codebase.

Data processing agreement

Before onboarding, a data processing agreement is signed in accordance with GDPR Article 28. The law firm is the data controller and Nordivé is the data processor. The agreement specifies what data is processed, for how long, by whom and how. A template can be shared on request.

How we approach AI errors

Nordivé generates drafts only. Nothing is sent, saved or archived without the lawyer’s explicit approval. Responsibility for legal assessments always remains with the lawyer — we are a tool, not a replacement for professional judgement.

Questions about security?

We welcome specific questions from IT security or compliance teams. Email kontakt@nordive.ai and we will connect you directly with the team.

Certifications

Status and roadmap for compliance.

We take compliance seriously. Here is where we stand and what we are working towards.

Active
GDPR (Art. 28)
A data processing agreement is signed with every customer before production use. The law firm remains the data controller; Nordivé is the data processor.
Template available on request
Active
Norwegian Bar Association guidelines
We have used the Norwegian Bar Association’s guidance on artificial intelligence as a basis. Confidentiality is supported by processing content in the EU, not storing it at Nordivé and not using it for training. This is our own assessment, not an endorsement.
Self-assessment
Not started
SOC 2 Type I
Third-party audit of security controls (security, availability, confidentiality). Not yet initiated. Preparations will begin when we reach 50 paying customers, not before.
No report available
Not started
SOC 2 Type II
An operational audit over six months — confirming that controls actually work over time, not just on paper. A standard for enterprise legal technology.
No date set
Not started
ISO 27001:2022
An internationally recognised information security standard. A gap analysis has not started. Certification is an objective after SOC 2 Type II is in place.
No date set
Providers
ISO 27001 + SOC 2 (provider certifications)
All Nordivé infrastructure runs on certified third-party services: Microsoft Azure (ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II), AWS Bedrock (same), Vercel (SOC 2 Type II).
Audit reports available on request through the Trust Center

Subprocessors

The following third parties process customer data on Nordivé’s behalf. The list is updated when changes occur, and customers are notified 30 days before new subprocessors are introduced (see section 6.2 of the data processing agreement).

Subprocessor Service Data centre Certification
Microsoft Corporation Azure Functions, Azure OpenAI (Terra, Sol), Storage, Key Vault, Entra ID, Microsoft Graph (Outlook/OneDrive) Norway East (Oslo); Azure OpenAI in the EU data zone (Sweden) ISO 27001, ISO 27018, SOC 2 Type II
Amazon Web Services, Inc. AWS Bedrock (AI inference through Claude) eu-west-1 (Ireland), EU inference profile ISO 27001, SOC 2 Type II
Anthropic PBC Claude AI model (runs through AWS Bedrock, without request storage) Through AWS — no direct data access SOC 2 Type II
Vercel Inc. Frontend hosting (static content for app.nordive.ai) European nodes SOC 2 Type II

All data is processed in the EU/EEA. No transfers to third countries (the US, India or others) take place in normal operations. The full subprocessor list is available in the official document (Norwegian).

Encryption overview

All data is encrypted in transit and at rest. Storage keys are managed by Microsoft. For most files in OneDrive, Nordivé adds an encryption layer with a key derived from the user’s Microsoft ID; this layer is not end-to-end encryption.

Data type In transit At rest Key management
Email content (during analysis) TLS 1.2+ (Microsoft Graph → Nordivé → EU language model) Never stored by Nordivé n/a
Chat history TLS 1.2+ AES-GCM 256-bit in the customer’s own OneDrive Key derived from the user’s Microsoft OID (not end-to-end)
Vault documents TLS 1.2+ Remains in the customer’s OneDrive (AES-256, managed by Microsoft) Microsoft tenant-keys
Matters, templates, workflows TLS 1.2+ JSON in the customer’s OneDrive AppFolder Microsoft tenant-keys
OAuth tokens (refresh) TLS 1.2+ (PKCE) AES-GCM 256 in browser localStorage User-derived key
Backend logs TLS 1.2+ → Azure Monitor AES-256, Azure Storage Azure-managed (Microsoft-managed keys)

Vulnerability scanning

Dependencies and code are continuously scanned for known vulnerabilities, and the build stops on high-severity findings.

Automated vulnerability scanning
  • Dependabot — alerts on known vulnerabilities in JavaScript dependencies
  • npm audit is run manually before release. It is not a CI gate that stops the build
  • We do not have GitHub Advanced Security and do not run CodeQL. Source code is scanned for secrets using Gitleaks in the GitHub workflow, but this is not yet a requirement before merging
Development and releases

Nordivé is a small company. We describe our practices as they are, rather than as they might look at a larger organisation.

  • Changes are committed directly to main. We do not currently require pull requests with a reviewer
  • Type checks, unit tests and builds are run locally before each deployment, rather than as a CI gate. This means the gate is a person, not a machine
  • Deployment is from a clean git worktree at an explicit commit, never from a working copy. Marker strings are counted in the published bundle before and after to confirm the correct version is live
  • The desktop panel has a denylist that fails the build if the code uses an API capable of reading the screen, keystrokes or document content. This can be independently checked using strings on the binary
  • Rollback is performed by redeploying the previous commit
Bug bounty (under consideration for 2027)
  • We plan to launch a public bug bounty programme through HackerOne or Intigriti when our user base warrants it
  • Until then, responsible disclosure reports can be sent to kontakt@nordive.ai (subject: “Security report”)
  • Researchers who report in good faith and keep findings confidential will be acknowledged in a hall of fame (when launched)

Incident response

In the event of a security breach, we follow a defined process for detection, notification and remediation. The timeframes below reflect what we can meet with our current staffing.

ClassificationExampleInitial responseCustomer notification
P0 – CriticalConfirmed data loss, outage exceeding one hourSame dayWithout undue delay, within 24 hours if possible
P1 – HighExploited vulnerability, authentication failureWithin one business dayWithout undue delay, within 24 hours if possible
P2 – MediumDegraded performance, non-critical misconfigurationWithin two business daysBy email as needed
P3 – LowLogging irregularities, cosmetic issuesAt the next regular updateNone

For P0/P1 incidents that may affect personal data, we notify the data controller (the law firm) directly by email. The controller notifies the Norwegian Data Protection Authority within 72 hours under GDPR Article 33, and we assist with the required information. We do not have a dedicated status page.

Availability and uptime

The backend runs in Azure Norway East with automatic scaling. Uptime is a target, not a guarantee:

PlanAvailabilityMaintenanceStatus notification
All plans99.5% target (best effort)Advance notice where possibleEmail
Separate agreementContractual service level by written agreementAs agreedAs agreed

Recovery targets: RTO 24 hours (recovery time objective) and RPO 24 hours (recovery point objective) for configuration and code. Source code is held in GitHub. Operational data in Azure Storage is locally redundant in Norway East, without a separate backup. Client content is in the firm’s own OneDrive.

Compliance matrix

Requirements and frameworks addressed by Nordivé, and where to find documentation:

Requirement / frameworkWhat it coversStatusDocumentation
GDPR / Norwegian Personal Data ActPrivacy, data subject rights, data minimisationCompliant (self-assessed)Privacy policy (Norwegian)
Data processing agreement (GDPR Article 28)Controller–processor relationshipSigned with each customerTemplate on request
Lawyer’s duty of confidentialityClient confidentialityBuilt into the designSecurity architecture document
Norwegian Bar Association AI guidelinesUse of AI in legal practiceUsed as a basisSelf-assessment
NSM Basic Principles for ICT SecurityNorwegian security baselineUsed as a reference (self-assessed)Security architecture document
OWASP Top 10 / ASVS L2Web application securityBaselineInternal review
SOC 2 Type ISecurity controls (design)Not startedPlanned from 50 paying customers
SOC 2 Type IISecurity controls (operational)Not startedNo earlier than 12 months after Type I
ISO 27001:2022Information security managementNot startedAfter SOC 2 Type II

Official documents

The following documents describe Nordivé’s security and privacy practices in detail. They are updated when material changes occur; the current version is shown in the header.

PDF
Security architecture
Technical description of data flows, encryption, authentication and subprocessors. Version 2.5.
v2.5 · 11 pp.
(Norwegian)
PDF
Privacy policy
Personal data we process, purposes, retention and rights under GDPR. Version 2.5.
v2.5 · 10 pp.
(Norwegian)
PDF
List of subprocessors
Complete list of third parties processing customer data, with data residency and certification. Version 2.4.
v2.4 · 6 pp.
(Norwegian)
PDF
Schrems II Transfer Impact Assessment
Per-provider risk assessment of US-owned subprocessors (Microsoft, AWS, Anthropic, Vercel) under EDPB Recommendations 01/2020. Version 1.2.
v1.2 · 7 pp.
(Norwegian)
PDF
Security statement
Overall security policy — access control, logging, incident response and personnel. Version 2.4.
v2.4 · 7 pp.
(Norwegian)
PDF
Terms of use
General terms for the Nordivé service, including limitation of liability and user obligations. Version 2.3.
v2.3 · 6 pp.
(Norwegian)
PDF
Storage and cookies
Cookies and local storage (localStorage) used by Nordivé. Version 2.5.
v2.5 · 8 pp.
(Norwegian)
DPA
Data processing agreement (DPA)
Standard contractual terms under GDPR Article 28(3), based on the Norwegian Data Protection Authority’s unofficial template. Signed individually with each law firm — contact us for a template.
SOC
SOC 2 Type I report
Third-party audit of security controls. No report is available; preparations start at 50 paying customers.
Not started

Internal security

Security starts with the people building and operating Nordivé. We have the following internal controls:

Employee access control
  • Two people currently have access to production. We state this plainly, because “least privilege” and “CTO approval” mean little with so few people
  • Production access requires multi-factor authentication on the Microsoft account
  • We have no database of client content. Email, documents and meeting notes are processed in memory and stored in the firm’s own OneDrive. The backend can still read and write to the app folder on the user’s behalf when background analysis is enabled, and you may choose to include client information in a support thread
  • As the team grows, onboarding and offboarding procedures will be introduced and described here once they exist
Device and endpoint security
  • The computer used for development and operations has disk encryption (FileVault)
  • We do not currently have MDM, centrally managed antivirus or remote device wiping
Background checks and training
  • We do not currently conduct background checks, regular security training or phishing exercises
  • Confidentiality agreements and training procedures will be introduced before new people are given access
Secrets and key management
  • API keys and credentials are stored as encrypted application settings in Azure or in Azure Key Vault — never in source code
  • We do not currently have scheduled, automatic key rotation
  • Secrets must not appear in logs or in code sent to the browser
  • Source code is scanned for secrets using Gitleaks in the GitHub workflow

Report a security issue

Have you discovered a vulnerability or suspect a security issue? We acknowledge reports within 48 hours.

Responsible disclosure

Send details to kontakt@nordive.ai with the subject “Security report”. Include:

  • A description of the vulnerability and where it was observed
  • Steps to reproduce the issue
  • Potential impact if exploited
  • Any proof-of-concept attachments

We commit not to take legal action against researchers who report in good faith and keep findings confidential until remediation. A bug bounty programme is under consideration for 2027.

Get to know Nordivé

See what you can capture.
And what you can make time for.

See how time tracking and email can fit
into your working day. We will show you the product.

Try free for 30 days