Norma for the enterprise

Norma for the enterprise

When the auditor asks who wrote it, you will have an answer

Norma records which rule fired, on which line, in which commit, by which author, at which timestamp, and which version of the rule was in force at the time. Across every repository and every AI editor your teams use.

Norma records which rule fired, on which line, in which commit, by which author, at which timestamp, and which version of the rule was in force at the time. Across every repository and every AI editor your teams use.

The accountability gap

The accountability gap

Your organization now ships code written by professional engineers, business builders and autonomous agents. Your control framework was designed for the first group. The evidence trail your auditors expect does not exist for the other two.

Three questions most enterprises currently cannot answer:

Three questions most enterprises currently cannot answer:

What proportion of our production codebase was authored by a model?

Which policy was in force when that code was approved, and who approved that policy?

Can we produce the evidence for a specific finding from eighteen months ago?

Every finding is evidence

Every finding is evidence

Nobody assembles this. The agent calls Norma, Norma records what was verified and what was fixed, and the entry is written as the work happens.

rule sb-exposed-service-role-key-1.0 · supabase-quality-hub-agent 1.0 · src/lib/admin-client.ts:15

rule sb-exposed-service-role-key-1.0 · supabase-quality-hub-agent 1.0 · src/lib/admin-client.ts:15

rule NORMA-SEC-204 · v3.42 · supabase/policies.sql:12

commit 8f41c2a · merged · author j.moreno + Claude Code · 2026-06-14 09:31 UTC

commit 8f41c2a · merged · author j.moreno + Claude Code · 2026-06-14 09:31 UTC

commit 8f41c2a · merged · author j.moreno + Claude Code · 2026-06-14 09:31 UTC

disposition fixed · export PDF · CSV · JSON

disposition fixed · export PDF · CSV · JSON

disposition fixed · export PDF · CSV · JSON

Every rule change is logged: who changed it, when, what changed, who approved it, what the previous version said, with diffs and rollback. Every write off is logged with the reason and the approver. Exportable in PDF, CSV and JSON, with read only share links for auditors. Retention configurable per customer.

Every rule change is logged: who changed it, when, what changed, who approved it, what the previous version said, with diffs and rollback. Every write off is logged with the reason and the approver. Exportable in PDF, CSV and JSON, with read only share links for auditors. Retention configurable per customer.

What the regulation asks for, and what Norma produces

What the regulation asks for, and what Norma produces

Regulation

Regulation

What it asks for

What it asks for

What Norma produces

What Norma produces

EU AI Act

Human oversight, technical documentation, record keeping and traceability for high risk AI systems

Human oversight, technical documentation, record keeping and traceability for high risk AI systems

Provenance on AI authored code, policy versions in force, oversight records, exportable technical evidence

Provenance on AI authored code, policy versions in force, oversight records, exportable technical evidence

ISO/IEC 42001

A managed AI management system with defined controls and evidence of operation

A managed AI management system with defined controls and evidence of operation

Documented policy library, approval workflow, versioning, evidence of continuous enforcement

Documented policy library, approval workflow, versioning, evidence of continuous enforcement

DORA

ICT risk management and change control for financial entities

ICT risk management and change control for financial entities

Change level evidence on every code change, enforced pre production controls, audit trail

Change level evidence on every code change, enforced pre production controls, audit trail

NIS2

Risk management measures and supply chain security for in scope entities

Risk management measures and supply chain security for in scope entities

Secret exposure detection, authorization and access control checks, evidence of enforced policy

Secret exposure detection, authorization and access control checks, evidence of enforced policy

SOC 2

Evidence that controls operated over a period

Evidence that controls operated over a period

Continuous scan history and rule level evidence across the period

Continuous scan history and rule level evidence across the period

ISO/IEC 27001

Secure development policy and its operation

Secure development policy and its operation

Enforced secure development rules with per finding evidence

Enforced secure development rules with per finding evidence

GDPR

Data protection by design, records of processing

Data protection by design, records of processing

In memory processing by default, no business or transactional data accessed, DPA with EU standard contractual clauses

In memory processing by default, no business or transactional data accessed, DPA with EU standard contractual clauses

Quality Clouds is ISO 27001:2022 certified and SOC 2 Type II attested. These mappings describe the evidence Norma produces for your own compliance program. They are not a compliance certification of your systems.

Your standard, not ours

Your standard, not ours

A regulated bank’s definition of production ready is not a SaaS startup’s. Norma holds the standard your organization sets, and enforces it identically in every editor, every repository and every scan.

Data handling

Data handling

Code processed in memory by default. Persistence opt in and configurable per customer. Metadata and code structure only, never business or transactional data. ISO 27001:2022 certified, SOC 2 Type II attested.

Code processed in memory by default. Persistence opt in and configurable per customer. Metadata and code structure only, never business or transactional data. ISO 27001:2022 certified, SOC 2 Type II attested.

One log in, one policy library

One log in, one policy library

The same policy library governs your repositories, your ServiceNow instances and your Salesforce orgs. One log in, one standard, one audit trail across all of it.

The same policy library governs your repositories, your ServiceNow instances and your Salesforce orgs. One log in, one standard, one audit trail across all of it.

Bring the evidence question to us

Bring the evidence question to us