Trust · Security & Data
Your data, kept where you decide.
Deployment models, data residency, the separation between your data and the platform’s intelligence, and where Norvan stands on certifications.
Last updated · 4 September 2026
Placeholder
TODO: security review — residency options, the isolation description, and certification statuses need confirming by the team before this page is relied on.
01Deployment models
Nous runs the way your data policy requires. The same platform, three ways to deploy it:
Cloud
The standard, fastest path to go live.
On-Premise · Nous Fortress
Your data never leaves your walls. Built for regulated and sovereignty-sensitive industries — mining, pharma, finance, government.
Hybrid
Start in the cloud, move on-premise as you scale.
02Data residency
Where your data lives is agreed before go-live and written into the client agreement.
- Malaysia — Default residency for cloud deployments served from our Malaysian headquarters. Data stays in-country.
- Your chosen region — Cloud deployments can be pinned to another region where a client’s regulator or policy requires it. Agreed per contract.
- Your own infrastructure — On-premise (Nous Fortress) and hybrid deployments keep client data on infrastructure the client owns and controls.
03How client data and platform intelligence are separated
Data sovereignty is core to how Norvan is architected. The intelligence layer is built so that a company’s data and the platform’s intelligence are kept properly separated and protected, with deployment options — including fully on-premise — for organizations with strict data-residency or regulatory requirements.
In practice: each client’s data is held in its own isolated store; the platform’s shared intelligence (the engines, the measurement model, the way Nous reasons) never contains a client’s records; and what Nous learns from one client’s data is not used to serve another client. Access inside Norvan is limited to the people running your deployment, and is logged.
TODO: security review — confirm the isolation model description against the current architecture before publishing.
04Certifications
We list status honestly. Nothing below is presented as certified until a certificate or report exists.
- ISO/IEC 27001 (information security)plannedScoping for the Malaysian operating entity. No certificate has been issued.
- SOC 2 Type IInot startedWill follow ISO 27001. No report exists today.
- PDPA 2010 (Malaysia) alignmentin progressPersonal data handling documented in the Privacy Policy; formal review pending.
TODO: confirm each status with leadership and update this list as certifications progress.
05Questions
Security questionnaires and data-processing terms go to info@norvan.io. Personal data collected on this website is covered by the Privacy Policy.