Publisher
This site is published by Norva SAS, a simplified joint-stock company registered in Rennes, France, with share capital of €120,000.
Registered office: 12 Quai Duguay-Trouin, 35000 Rennes, France. Registration number: RCS Rennes 000 000 000. Intra-community VAT: FR00000000000.
Publication director: Camille Roze. Contact: hello@norva.com.
Hosting
This site is served as static files from infrastructure located within the European Union. No visitor data is transferred outside the EU by the site itself.
Client telemetry processed under a managed service agreement is held separately, on SecNumCloud-qualified infrastructure in France, under the terms of that agreement.
Privacy policy
We collect as little as the site can function on. There is no advertising network, no behavioural tracking and no third-party analytics script on these pages.
When you submit the contact form, we process the details you provide for the sole purpose of replying to your enquiry. The lawful basis is legitimate interest in responding to a business request. We keep enquiries for twenty-four months, then delete them.
When you subscribe to the threat briefing, we process your email address on the basis of your consent. Every message includes a one-click unsubscribe link, and unsubscribing deletes the record.
You have the right to access, rectify, erase, restrict and port your data, and to object to its processing. Write to privacy@norva.com and we will respond within one month. You may also lodge a complaint with the CNIL.
Cookies
This site sets no cookies. It stores nothing in local storage beyond what your browser does on its own.
Because no non-essential storage is used, no consent banner is required. If that changes, a banner will appear before anything is stored, not after.
Terms of use
The content of this site is provided for information. It does not constitute a security assessment of your environment, and nothing here should be read as advice specific to your circumstances.
Editorial content, written material and the visual design of this site are the property of Norva SAS. You may quote from published articles with attribution and a link. Reproduction of a full article requires written permission.
Engagements are governed exclusively by the signed contract and the rules of engagement attached to it. Prices published on this site are indicative starting points and are not an offer.
Responsible disclosure
If you find a vulnerability in infrastructure operated by Norva, report it to security@norva.com. Encrypt anything sensitive to our disclosure key first.
We acknowledge reports within two working days and aim to remediate within ninety days, keeping you informed as we go. We will credit you publicly if you want that, and stay quiet if you do not.
We will not pursue legal action against researchers who act in good faith, stay within the scope of our own systems, avoid degrading service, and do not access, modify or retain data belonging to other people.
Please do not test client environments. They are not ours to authorise, and doing so falls outside this policy.