Trust Center
We are building an enterprise-ready reporting platform where companies can confidently prepare reports and future corporate disclosures. Numbra is an early-stage company, but we are building with the expectations of enterprise customers in mind from day one.
Trust principles for annual reporting software
Everything we build is guided by four core principles.
Security for annual reporting software
Security is embedded throughout the product lifecycle, from architecture and development to deployment and operations.
Secure software development practices, including code review, keeping software dependencies up to date and addressing identified security vulnerabilities
Least-privilege access
Encryption in transit and at rest
Multi-factor authentication (MFA)
Monitoring, backup and continuous improvement
Responsible AI in corporate reporting
Artificial intelligence should improve reporting, not reduce accountability. AI is applied to reduce repetitive work while responsibility remains with the reporting company.
Human review remains essential
Customers retain ownership and control of their data
AI supports professional judgement, it does not replace it
Numbra uses models from leading AI providers, including OpenAI, for selected AI assisted reporting workflows
GDPR and data protection
Protecting customer information is a fundamental responsibility. Numbra is committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR).
Privacy by design
Data minimization and purpose limitation
Secure processing and controlled access
Defined retention practices and DPAs available on request
Governance for listed-company reporting
Numbra is designed to support structured reporting processes and help organizations produce reporting that is both efficient and trustworthy.
Clear ownership and accountability
Controlled workflows and auditability
Version history
Transparent review and approval processes

Cloud infrastructure and operational security
Numbra is being developed as a modern cloud-native SaaS platform. The cloud infrastructure follows industry-standard security practices including identity-based access controls, logging and monitoring. The architecture is designed to support encrypted communications and storage, controlled access and consistent security controls across environments.
Infrastructure principles
Secure cloud hosting
Encrypted communications (TLS) and encrypted storage
Identity and access management
Operational monitoring
Backup and disaster recovery procedures
Security roadmap
Security is a continuous process, not a one-time milestone.
Current focus
Trust Center · Information Security Policy · GDPR aligned privacy framework · Secure software development · Data Processing Agreement (DPA)
Next
Independent security review · Expanded security documentation · Penetration testing · Formal incident response and recovery procedures · ISO/IEC 27001 alignment
Future
Continued maturity of our Information Security Management System (ISMS)
· Evaluation of formal ISO/IEC 27001 certification based on customer requirements and company growth
Transparency and customer due diligence
As Numbra grows, we will continue to expand this Trust Center with additional information covering security, privacy, governance, compliance and the use of AI models and customer data.
hi@numbra.no