Noryo security

We talk openly about what we protect. And how.

No abstract talk. Every mechanism listed below is implemented in Noryo's code, documented, and we can discuss it openly with anyone who asks.

What we protect

Ten concrete mechanisms, verifiable in the code.

Every protection below is implemented and active today. Not a roadmap, not a slogan.

Hosting

Sovereign French hosting

Your documents are stored in Paris, on Scaleway, French infrastructure subject to French law. Not a server on American soil, unlike most fintechs.

Bank connection

Read-only PSD2, ACPR-authorised partner

The connection to your bank goes through Atto, a provider authorised by the French Prudential Supervision Authority. Your credentials never leave your bank's own site, and Noryo has read-only access to the data you have authorised.

Transport

TLS 1.3, HSTS preload, strict CSP

Every connection to noryo.app is encrypted with TLS 1.3 and HSTS preload (one year, included in the browsers' preloaded list), plus a content security policy that blocks injection and iframe-jacking attacks.

Storage

Single-use download URLs, cryptographically signed

Every document you download is served through an AWS Signature V4 signed URL, valid for a few minutes only. No storage access key is ever exposed to your browser.

Authorisation

Triple check before your documents are served

Before serving a document, Noryo checks three times: Supabase authentication, the RLS policy at database level, and the physical prefix of the file path. Even if someone guessed an identifier, access would be refused.

Bank webhook

Bank notifications authenticated by signature

When your bank sends a notification to Noryo, it is authenticated by an HS256-signed JWT verified in constant time. A unique identifier per event prevents any replay, and source IPs are filtered against Atto's allowlist.

iOS

Native Face ID biometric lock

On iPhone, Noryo locks with Face ID or Touch ID every time it opens. Your data is visible only with your face or your fingerprint.

iOS storage

Secrets in Apple's Secure Enclave

On iPhone, your session tokens are stored in Apple's shared Keychain, protected by the Secure Enclave (A12 chip and above). Unreachable even on a modified phone without your unlock code.

Multi-device sync

AES-256 GCM encrypted syncing

When you sign in again on another device, your session travels encrypted with AES-256 GCM, the standard banks use for their own internal communications.

Isolation

Data isolation at database level

Every row in the database is filtered inside the Postgres engine by an individual RLS policy. Even a bug in the code could not expose another user's data.

What we also say

No fintech is invulnerable. We know that.

Promising absolute security would be a lie. What you find above are the mechanisms in place, the ones we can document. If you find a flaw or something that looks wrong, write to us at security@noryo.app.

On a few specific points we are still hardening: certificate pinning on iOS (currently in reporting mode), two-factor authentication (TOTP, optional, already available in settings), and external certifications (ISO 27001, SOC 2) that we will work towards as we grow.

Our commitment: to keep publishing these changes here, rather than on a vague commercial page. You will know what we protect, and how.