Normos is the forensic evidence layer for ISO 27001 and SOC 2 compliance — not a GRC checklist tool, and not another AI-powered compliance assistant. Most compliance platforms either help you manage a GRC programme (policies, risk registers, remediation tickets) or use AI to draft evidence and summarise controls. Normos does neither. It connects read-only to your GitHub organisation and runs 21 deterministic detectors across five domains — Identity, Code, Access Control, Supply Chain, and Non-Human Identity — every 24 hours, with zero AI inference in the detection path. Same inputs always produce the same output, and every finding is independently verifiable, not self-attested. Every scan is SHA-256 hashed and chained to the one before it, creating a tamper-evident forensic record that grows daily — the difference between "we believe our controls were operating" and "here is cryptographic proof they were." AuditChain™, our token-gated auditor portal, lets auditors verify that chain directly at a dedicated read-only URL — no shared login, verified via a one-time code. The Normos Readiness Score™ combines deterministic scan evidence with signed management assertions across 13 canonical controls — a single, defensible number reflecting verified state, not a self-reported checklist percentage. Normos never stores source code, commit history, or user lists — only findings, per our Zero-Footprint Evidence Generation™ architecture. Even in a breach, there is nothing sensitive to lose. Built for engineering-led SaaS companies — Seed to Series A, GitHub-native, usually without a dedicated CISO — needing real evidence without a compliance team or AI-drafted evidence. Pricing is public: Starter £9,600/yr, Enterprise £24,000+/yr, both with full ISO 27001 and SOC 2 coverage, no per-framework upcharges, backed by a 30-day guarantee. Try the free scan at normos.io/free-github-scan — connect one repo, no signup, no credit card, results shown once and discarded.
Read morePricing
Platforms Supported
Organization Types Supported
API Support
Modes of Support
Internal Controls Management
Reporting & Analytics
Audit Management
Allows to complete audits and inspections on timeRisk Management
Monitors and manages financial risks such as foreign exchange, interest rate, counterparty and liquidity risks.Compliance Management
Helps in making an assessment of risks, ensures policy comprehension and that policies/procedures are being followedPolicy & Document Management
Workflow Automation
Automatically execute mundane and repetitive processes or workflow so that employees can focus on productive workFree Trial
Not available
No Credit Card Required, Get Started for Free
Starter Custom
£9,600/year, billed in GBP via UK bank transfer (BACS). All 21 detectors across 5 domains, daily automated scanning, ISO 27001 + SOC 2 evidence packages, SHA-256 forensic hash chain, Normos Readiness Score, automated Assurance Letter PDF. Includes AuditChain core suite - token-gated, OTP-verified auditor portal with findings list, evidence download, hash chain display, domain breakdown, scan history timeline, and evidence freshness indicators. 1 active auditor invite, 3 user seats, 12 months scan history retention. 30-day value guarantee.
Enterprise Custom
£24,000+/year, billed in GBP via UK bank transfer (BACS). Same forensic detection engine as Starter, plus signed management assertions across 13 controls (SHA-256 hashed, AAL2-signed) and the full AuditChain suite: control-to-finding mapping, finding trend charts, printable audit summary PDF, framework filter (ISO 27001/SOC 2), and full scan history with chain hashes - the complete forensic evidence suite a Big 4 auditor expects. Unlimited seats and auditor invites, custom MSA and DPA, dedicated onboarding, priority access to Phase 2 features.
98% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
97% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
97% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
96% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
94% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
93% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
90% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
90% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
86% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
84% SW Score The SW Score ranks the products within a particular category on a variety of parameters, to provide a definite ranking system. Read more
Homepage Hero
AuditChain
Free GitHub Scan ...
Trust Centre
Pricing Comparison
What is forensic compliance evidence?
Cryptographically verifiable proof that your security controls are operating as intended — not a screenshot or self-reported checklist. Every Normos scan is deterministic, timestamped, SHA-256 hashed, and tamper-evident, proving what was found, when, and that it hasn’t been altered since.
How does Normos generate evidence automatically?
Normos connects to your GitHub organisation via read-only OAuth and runs 21 deterministic detectors every night at 02:00 UTC across five domains — Identity, Code, Non-Human Identity, Access Control, and Supply Chain. No manual uploads, no screenshots. You wake up to a scan completion email with your Normos Readiness Score.
Does Normos store my source code?
No. Normos connects read-only, analyses everything in memory, and stores only the findings — never source code, commit history, user lists, or business data. Even in a breach, there is nothing sensitive to lose, because nothing sensitive was ever kept.
What is a SHA-256 forensic hash chain?
Each scan record is hashed and linked to the one before it, making the evidence tamper-evident — any change to a past record invalidates every hash after it. Auditors can independently verify the integrity of the entire evidence history.
What is the Normos Readiness Score?
A weighted readiness metric combining deterministic scan evidence (60%) and signed management assertion coverage (40%) into a single, defensible number from 0 to 100 — available on every plan.
Can Normos detect things my auditor won’t find manually?
Yes. Detectors like Review Collusion Risk (closed-loop PR review patterns), Machine Credential Sprawl (deploy keys, OAuth installs), and CI/CD Workflow Security (fork PR injection, wildcard permissions) surface findings that are statistically invisible to a human auditor and are not checked by questionnaire-based tools.
How quickly can I get audit-ready with Normos?
Most customers produce their first cryptographically chained evidence package within 24 hours of connecting GitHub. OAuth setup takes under 10 minutes; the first scan runs that night.
What is an Assurance Letter?
A board-ready PDF generated automatically after every scan, summarising your Normos Readiness Score, verified controls, active management assertions, and the forensic hash chain reference — not a certification, but forensic proof of current posture.
What GitHub permissions does Normos require?
Four read-only OAuth scopes: read:user, read:org, repo, and admin:org (used solely to identify members without MFA enabled). No write access is requested or used at any point.
How does Normos handle data under UK GDPR?
Normos is ICO-registered (ZC158944) and processes only the minimum data necessary — findings, scan metadata, and account information — stored in Supabase EU Ireland.
What happens to my data if I leave Normos?
All data is permanently deleted within 30 days of account closure, with written confirmation. You can export your evidence package and Assurance Letter at any time beforehand.
Which compliance frameworks does Normos support?
ISO 27001:2022 and SOC 2 today, both included in every plan at no extra cost. Cyber Essentials, CE+, DORA, and AI-aware detection are planned for Phase 2, followed by NIS2, SOC 2 Type II, and PCI DSS v4 in later phases.
Why are ISO 27001 and SOC 2 both included at no extra cost?
The two frameworks share roughly 80% of the same controls, and Normos generates both evidence packages from the same scan — charging twice for the same data would be a tax on compliance, not a service.
How does Normos handle management assertions?
Assertions are cryptographically hashed statements confirming controls that can’t be detected automatically — policies, background screening, physical access. Each is SHA-256 hashed, requires AAL2 MFA, and expires after 12 months.
What is AuditChain, and what does my auditor see?
AuditChain is Normos’s forensic evidence portal for external auditors — token-gated, OTP-verified, read-only access at audit.normos.io. All plans include the Readiness Score, findings list, evidence PDF, and hash chain; Enterprise adds control-to-finding mapping, trend charts, and framework filtering. Tokens expire after 7 days and can be revoked instantly.
Why do auditors prefer Normos evidence?
Auditors are increasingly sceptical of screenshot-based evidence, which can be fabricated or selectively curated. Normos evidence is produced by a deterministic rule every time, hashed at the moment of detection, and independently verifiable through a dedicated auditor portal — not a shared login to your internal dashboard.
Does Normos work alongside my existing ISO 27001 consultant?
Yes. Normos handles continuous technical evidence generation automatically, freeing your consultant to focus on policy, risk assessment, and audit preparation rather than manually collecting screenshots.
What does Normos cost, and is there a guarantee?
Starter is £9,600/year, Enterprise is £24,000+/year, both billed annually in GBP with full ISO 27001 and SOC 2 coverage and no per-framework upcharges. Both plans include a 30-day value guarantee.
How is Normos different from Vanta or Drata?
Vanta and Drata automate questionnaires and collect evidence via screenshots and integrations. Normos generates forensic evidence instead — deterministically produced, SHA-256 hashed, and tamper-evident — and includes ISO 27001 and SOC 2 in every plan rather than charging per framework.
Is Normos suitable for small teams?
Yes. Normos is built for engineering-led SaaS companies roughly 10–200 employees, whether pursuing ISO 27001 or SOC 2 for the first time, or already certified and needing continuous evidence between audits. Setup takes under 10 minutes via GitHub OAuth.
What is Normos used for?
Normos is GRC Platforms. Normos offers the following functionalities:
Learn more about Normos features.
What are the top alternatives for Normos?
Here`s a list of the best alternatives for Normos:
Does Normos provide API?
No, Normos does not provide API.
Vendor Details
Founded : 2026Social Media Handles
Not available
This research is curated from diverse authoritative sources; feel free to share your feedback at [email protected]
Looking for the right SaaS
We can help you choose the best SaaS for your specific requirements. Our in-house experts will assist you with their hand-picked recommendations.
Want more customers?
Our experts will research about your product and list it on SaaSworthy for FREE.