Security overview
v1.0 · July 2026TLS 1.3 for every connection, AES-256 for everything stored. Encryption keys are held in the EU, in hardware-backed key management, rotated on schedule.
Default: a dedicated, single-tenant environment in Stockholm (eu-north-1). For sensitive clients: full on-premises deployment — the platform runs inside your infrastructure and data never leaves your environment.
Identity via verified work email with MFA (authenticator app). Internally: role-based, least-privilege access; every access to client data is logged and available to you upon request.
The following subprocessors process personal data to deliver Round Table: Supabase (EU, AWS Stockholm eu-north-1) — authentication and database; Vercel — application hosting and cookieless analytics; Anthropic — hosted model inference for the EU cloud tier; Resend — transactional email; Microsoft — calendar holds for booking. Sessions delivered on the sovereign-cloud tier (Sweden) run on NorseAI's private cloud at Evroc AB, where Evroc AB acts as infrastructure subprocessor for that tier. On-premises and air-gapped deployments (client premises) do not send session content to the hosted model provider. Any change of subprocessor requires 30 days' prior written notice and gives you a right to object. Infrastructure and subprocessors are covered by continuous monitoring and defined incident response.
All agents in a session are disclosed as such (EU AI Act Art. 50). A moderator — a human in the loop — supervises every live session. Your data is never used to train models.
Found a vulnerability? security@norse-ai.com. We acknowledge within 2 business days and do not pursue good-faith research.
Questions? Write to privacy@norse-ai.com. This summary does not replace the signed agreement for your engagement.
← Back to norse-ai.com