Skip to content
NORTH
Use casesDemoEvidence
PricingAbout
Start free →
NORTHStart free →
Use casesDemoEvidence
PricingAbout
Trust

Security

UseNorth handles personal and professional information — names, roles, work email addresses, and the diagnostic responses that participants give in conditions they are meant to experience as honest and safe. The security model reflects that responsibility.

What is collected and why

DataWhere storedWhy collected
Name, role, email, organisationnorth_leads, north_responsesCredential issuance and session tracking
Scenario responsesnorth_responses (jsonb)Scoring and team map generation
Reflection textnorth_responsesQualitative diagnostic input for the Brief
Archetype and scoresnorth_leadsCredential and Strategist Brief input
Session codesnorth_sessionsTeam session coordination
Cloud platform and constraintsexecution_* tablesNORTH Build credential and team output

No third-party analytics platform receives individual participant data.

Key management

Client-side

The Supabase publishable key is designed for browser exposure. It is committed to .env.example as a placeholder format. The actual production key is set in Vercel environment variables and .env.local (gitignored).

Server-side only

GOOGLE_AI_API_KEY is used exclusively in server-side API routes (e.g. /api/strategist-brief). It is not exposed to the client, not included in any client-side bundle, and not logged.

RESEND_API_KEY lives in Supabase Edge Function secrets — set via the Supabase dashboard, never in source code, never as a fallback value.

Database security

Participant data is served only through authenticated API endpoints; we run continuous external security review of those endpoints. Last completed: August 2026.

Direct database access (Supabase secret key, database password) is restricted to infrastructure operations and never touches client-side code.

Participant data handling

Scores stay in aggregate

A participant's dimension scores are used to calculate their archetype and drive the adaptive Reckoning. In team outputs they appear only as aggregate pattern on the Coalition Map, which shows pattern, not score.

The Coalition Map is directional

It shows pattern, not score. Individual responses cannot be reverse-engineered from the map.

The Strategist Brief is confidential

The document is generated for the consulting partner and marked confidential. The input data (Coalition Map, Tension Map) is stored but the generated Brief text is ephemeral.

Reflections inform the Brief

The qualitative reflection responses are stored to enable the Strategist Brief. They do not appear in team session outputs.

Responsible disclosure

If you discover a security vulnerability in UseNorth, please report it privately before disclosing it publicly.

Contact: info@usenorth.xyz
Subject line: Security disclosure — [brief description]

Include a description of the vulnerability, steps to reproduce, the potential impact, and any suggested remediation. We acknowledge receipt within 48 hours and respond with an assessment within 5 business days.

Please do not open a public GitHub issue for security vulnerabilities.

Compliance

POPIAGDPRISO/IEC 42001NIST AI RMF 1.0

This document is reviewed and updated with each significant change to data handling, infrastructure, or third-party integrations. Last reviewed: 1 August 2026.

NORTH · 2026
AboutUse casesSectorsArchetypesMethodologyEvidenceBriefRescore DeltaPricingPartner programmeContactSecurityFAQPrivacyTerms