← back to norji.co.uk
Trust & Security
Last updated: 25 April 2026.
NORĴI processes your emails, calendars, and business data to help you work faster. Here is how we protect it.
Encryption
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Sensitive credentials like OAuth tokens get an additional layer of application-level Fernet encryption on top of the disk-level encryption, with multi-key rotation supported.
Your data isn't AI training fuel
We never use your data to train AI. Your emails remain yours. Anthropic's published API terms exclude API inputs and outputs from the training of their models, and we use the API under those terms. We do not hold a separately negotiated enterprise agreement, and we do not claim one.
We don't sell your data
We never sell your data. Full stop. Not aggregated, not anonymised, not "shared with partners".
Authentication without password sharing
We use OAuth to connect to your email and calendar. You authenticate against Google or Microsoft directly. NORĴI never sees and never stores your account passwords.
Access is restricted
NORĴI is currently a single-engineer company. One person has production access, protected by hardware two-factor authentication, and every access is audit-logged. There is no support team with a shared login, because there is no support team. If that changes, this page changes with it.
You control your data
Export everything with /export-my-data. Delete it completely with /wrap. Your data, your rules.
Compliance roadmap
No certifications today. SOC 2 Type I is targeted for Q4 2026, Type II the following year. The underlying controls (encryption at rest and in transit, audit logging, access management, backups) are in place now and described on this page. We won't claim a certification we haven't earned.
GDPR
NORĴI is
built to UK GDPR requirements. Our DPA and sub-processor list are published, and no independent body has assessed us, so we describe the controls rather than assert a verdict. Exercise any of your rights, access, rectification, deletion, portability, objection, restriction, by emailing
privacy@norji.co.uk.
Found a security issue?
Hosting region
NORĴI's primary infrastructure is hosted by Railway, with Vercel serving this website. We are re-verifying the exact Railway region and will state it here precisely rather than approximately. Where data is processed outside the UK, transfers are covered by Standard Contractual Clauses and the UK Addendum, as set out in our Data Processing Agreement. If the region changes, we'll update this page and notify customers per our privacy policy.
Sub-processors
There is one canonical sub-processor list and it lives in the DPA sub-processor annex. It names every third party in the data path, what it does, where it sits, and the safeguard governing each cross-border transfer. This page does not restate it, so the two cannot drift apart.