Security at Norbital
This page lists the controls built into the product. For deployment-specific controls, data residency, or a security review, contact us directly.
Core provisions an isolated database for each organization.
Collection grants, row conditions, field redaction, and app visibility apply to each request.
Mutation logs, audit events, and record versions preserve who changed what and when.
Product controls
Tenant isolation
Core provisions a separate tenant database for each organization. Workspace requests resolve against the signed-in organization and tenant context.
Policy enforcement
Teams receive one governing policy. Policies control collection actions, row access, field redaction, and app visibility. The runtime evaluates them on each request.
Approvals and history
Sensitive writes can require approval. Norbital records mutations, audit events, and record versions so reviewers can see what changed and restore a prior version when required.
Release safety
Workspace changes build in a sandbox and apply to preview before production. Only a successful checkpoint can become the live release.
Responsible disclosure
If you discover a vulnerability, contact security@norbital.ai. We take responsible disclosure seriously. Include reproduction steps and the affected surface so we can review the report.