Security overview

Verified boundaries, stated without certification claims.

This page describes controls visible in the approved architecture and current public-site implementation. Norraz holds no verified ISO 27001 certification, SOC 2 audit, penetration-test assurance or other independent assurance.

Private records are not a public data source.

The public site does not query internal Decision Review tables. Published Reviews are separate sanitized snapshots returned through an allowlisted server API and re-serialized by the public-site proxy.

Internal IDs, raw evidence, evidence gaps, reviewer notes, AI-review data, scores, service-role data and administration fields are excluded from the public contract.

Server-side boundary

The upstream Decision Intelligence URL remains server-side. No Supabase or service-role credential is provided to the browser.

Publication eligibility

Only eligible Published snapshots are returned. Withdrawn or ineligible records are omitted and direct slug requests return not found.

Preview isolation

Fixtures are permitted only in non-production when explicitly enabled. Production fixture mode is prohibited.

Analytics

Google Analytics is off by default and the external tag is not requested before explicit consent.

Customer-data AI boundary

Identifiable, confidential or sensitive customer data is prohibited from personal, consumer or otherwise unapproved AI services.

Security reporting

Reports may be sent to security@norraz.se, a verified and monitored Norraz alias.

Start with minimum necessary information.

Do not submit credentials, special-category personal data, personal blame statements, export-controlled material, confidential technical drawings or other sensitive project records through public forms.

Detailed handling, access, retention and provider requirements must be agreed before private material is supplied.

Commercial assurance remains incomplete.

Applicable hosting, communications, analytics, payment, data-processing and AI-service controls remain subject to contractual, privacy, security and configuration verification.

These dependencies prevent commercial go-live approval. Preview validation does not constitute Production assurance.

Send a concise security report.

Include the affected public URL, observed behaviour and a safe reproduction description. Do not include live credentials or unnecessary personal data.