Security & compliance

Built for data that will sit in front of a tribunal.

Every Noor deployment is designed to satisfy the same scrutiny your firm applies to client files: UK residency, contractual training opt-out, cryptographic integrity, and published sub-processors.

UK data residency

All client data — messages, documents, transcripts, audit bundles — is stored and processed in AWS eu-west-2 (London). Never routed outside the UK, never served from a US CDN. Convex's EU region means even our application database stays in scope.

Encryption

TLS 1.3 in transit. AES-256 at rest. Signed keys managed by Convex with automatic rotation. Webhook signatures verified with constant-time HMAC-SHA256 on every inbound message.

No training on your data

Zero-retention agreements with every AI sub-processor. Anthropic ZDR is enforced contractually and technically — your clients' words are never used to train a model.

Retention

SRA's seven-year standard is our default. Configurable per firm: shorter for one-off consultations, longer for ongoing matters. Voice audio is deleted 90 days after transcription; the transcript is kept.

Audit posture

SOC 2 Type I on track for completion in 2026. DPIA collaboration is available today — we'll sit with your DPO for a call and supply every artefact your compliance review needs.

Incident response

24-hour breach notification to every affected firm, in writing, with a factual timeline and remediation steps. Named incident contact and escalation chain on file from day one.

Every party who sees a byte of your client data.

Each has a signed Data Processing Agreement under UK GDPR. If any changes, we give you 30 days' written notice before it takes effect on your tenant.

Party
Purpose
Location
DPA
Anthropic
LLM — translation + document OCR
UK / EU
Signed · v3.2
AWS
Document + voice storage (eu-west-2)
London
Signed · v4.1
Convex
Application database + real-time
eu-west-2
Signed · v1.9
Meta (WhatsApp Business)
Messaging channel
EU
Signed · v5.0
Resend
Transactional email (digest, notifications)
EU
Signed · v1.2

Questions about a specific sub-processor or a regional constraint? Talk to us— we're happy to walk your compliance team through each one.

Designed around the bodies you're authorised under.

SRA Code of Conduct 2019 retention defaults; Transparency in Innovation Notice 2025 alignment; client care disclosures built into every audit bundle.

IAA Code of Standards — caseworker authorisation levels honoured in role-based access controls; record-keeping exceeds the IAA minimum.

UK GDPR-aligned retention, UK GDPR-aligned data subject rights (access, erasure, portability) exposed as one-click caseworker actions.

Designed around the Law Society's Immigration & Asylum Section file-handling norms. Every export carries your firm's SRA / IAA / ICO numbers on the cover.

Want the full security brief?

We'll send a PDF brief plus the Data Processing Agreement template for your counsel to review. No form gating — just an email.