Hosting
Sovereign French hosting
Your documents are stored in Paris, on Scaleway, French infrastructure subject to French law. Not a server on American soil, unlike most fintechs.
No abstract talk. Every mechanism listed below is implemented in Noryo's code, documented, and we can discuss it openly with anyone who asks.
What we protect
Every protection below is implemented and active today. Not a roadmap, not a slogan.
Hosting
Your documents are stored in Paris, on Scaleway, French infrastructure subject to French law. Not a server on American soil, unlike most fintechs.
Bank connection
The connection to your bank goes through Atto, a provider authorised by the French Prudential Supervision Authority. Your credentials never leave your bank's own site, and Noryo has read-only access to the data you have authorised.
Transport
Every connection to noryo.app is encrypted with TLS 1.3 and HSTS preload (one year, included in the browsers' preloaded list), plus a content security policy that blocks injection and iframe-jacking attacks.
Storage
Every document you download is served through an AWS Signature V4 signed URL, valid for a few minutes only. No storage access key is ever exposed to your browser.
Authorisation
Before serving a document, Noryo checks three times: Supabase authentication, the RLS policy at database level, and the physical prefix of the file path. Even if someone guessed an identifier, access would be refused.
Bank webhook
When your bank sends a notification to Noryo, it is authenticated by an HS256-signed JWT verified in constant time. A unique identifier per event prevents any replay, and source IPs are filtered against Atto's allowlist.
iOS
On iPhone, Noryo locks with Face ID or Touch ID every time it opens. Your data is visible only with your face or your fingerprint.
iOS storage
On iPhone, your session tokens are stored in Apple's shared Keychain, protected by the Secure Enclave (A12 chip and above). Unreachable even on a modified phone without your unlock code.
Multi-device sync
When you sign in again on another device, your session travels encrypted with AES-256 GCM, the standard banks use for their own internal communications.
Isolation
Every row in the database is filtered inside the Postgres engine by an individual RLS policy. Even a bug in the code could not expose another user's data.
What we also say
Promising absolute security would be a lie. What you find above are the mechanisms in place, the ones we can document. If you find a flaw or something that looks wrong, write to us at security@noryo.app.
On a few specific points we are still hardening: certificate pinning on iOS (currently in reporting mode), two-factor authentication (TOTP, optional, already available in settings), and external certifications (ISO 27001, SOC 2) that we will work towards as we grow.
Our commitment: to keep publishing these changes here, rather than on a vague commercial page. You will know what we protect, and how.