NormControl
Trust & security

Written for your security reviewer.

Factual and specific, no marketing language. Every claim below is true today and kept synchronized with the product.

01

Single-tenant, in your subscription

NormControl is not SaaS. Each customer deploys their own instance into their own Azure subscription via the Marketplace. Compute, database and key management run under your governance, your Azure policies and your cost controls.

02

All data in your own database

Every record and every uploaded file lives in a PostgreSQL server inside your deployment. There is no vendor object store, no shadow copy, no CDN with your documents.

03

Zero telemetry

The application sends nothing to the vendor: no usage analytics, no error reporting, no license pings. The only outbound traffic goes to Microsoft/Azure (identity, entitlement, Marketplace billing).

Outbound endpointPurpose
login.microsoftonline.comIdentity (Entra ID)
marketplaceapi.microsoft.comEntitlement and metered billing
*.azure.comAzure platform services within your tenant
Simplified view; the full table lives in the operations runbook (§9).
04

The vendor is locked out

The deployment is a Managed Application: the vendor holds a read-only nomination required by the platform and cannot access your data or change your deployment. Optional just-in-time access exists only if you enable it: per incident, with your explicit approval, time-boxed and logged in your own audit trail. Decline it and there is no access path at all.

05

Network posture

By default the database and key vault have no public endpoints (private networking inside your deployment). Application access can be restricted to your own IP ranges. Sign-in via your own Microsoft Entra ID (SSO) with your conditional access policies, or local accounts.

06

Backups in your hands

Continuous point-in-time restore on your own database server, plus one-click portable backups and in-product restore. You can take your data out at any moment; the export is a standard PostgreSQL dump.

07

Keyless by design

Optional AI and email run on Azure services in your own subscription via managed identity: no API keys to store, rotate or leak. Every AI action requires human approval and is audit-logged.

08

Vendor compliance posture

GDPR-compliant (see the privacy statement). The vendor processes no customer deployment data at all, which makes the processor question refreshingly short. Dutch legal entity (Citizar), Dutch law per the terms.

09

Private and air-gapped deployment

Besides the Marketplace, we also deliver NormControl for self-managed deployment, including fully air-gapped installations. Without a connection to Azure, the Marketplace billing and Entra ID SSO described above do not apply. Get in touch for the terms.