Skip to content

Security at Norbital

This page lists the controls built into the product. For deployment-specific controls, data residency, or a security review, contact us directly.

Separate tenant databases

Core provisions an isolated database for each organization.

Policy-based access

Collection grants, row conditions, field redaction, and app visibility apply to each request.

Recorded changes

Mutation logs, audit events, and record versions preserve who changed what and when.

Product controls

Tenant isolation

Core provisions a separate tenant database for each organization. Workspace requests resolve against the signed-in organization and tenant context.

Policy enforcement

Teams receive one governing policy. Policies control collection actions, row access, field redaction, and app visibility. The runtime evaluates them on each request.

Approvals and history

Sensitive writes can require approval. Norbital records mutations, audit events, and record versions so reviewers can see what changed and restore a prior version when required.

Release safety

Workspace changes build in a sandbox and apply to preview before production. Only a successful checkpoint can become the live release.

Responsible disclosure

If you discover a vulnerability, contact security@norbital.ai. We take responsible disclosure seriously. Include reproduction steps and the affected surface so we can review the report.