Security
UseNorth handles personal and professional information — names, roles, work email addresses, and the diagnostic responses that participants give in conditions they are meant to experience as honest and safe. The security model reflects that responsibility.
What is collected and why
| Data | Where stored | Why collected |
|---|---|---|
| Name, role, email, organisation | north_leads, north_responses | Credential issuance and session tracking |
| Scenario responses | north_responses (jsonb) | Scoring and team map generation |
| Reflection text | north_responses | Qualitative diagnostic input for the Brief |
| Archetype and scores | north_leads | Credential and Strategist Brief input |
| Session codes | north_sessions | Team session coordination |
| Cloud platform and constraints | execution_* tables | NORTH Build credential and team output |
No third-party analytics platform receives individual participant data.
Database security
Participant data is accessed through authenticated application endpoints. We run internal security testing and fix what we find. To report an issue, see Responsible disclosure below.
Direct database access (Supabase secret key, database password) is restricted to infrastructure operations and never touches client-side code.
Participant data handling
A participant's dimension scores are used to calculate their archetype and drive the adaptive Reckoning. Once the team threshold is reached, the session owner can open each participant's dimension profile. The Coalition Map itself shows pattern, not score.
It shows pattern, not score. Individual answers are not reconstructed from the map alone. For what a session owner can open, see the FAQ.
The document is generated for the consulting partner and marked confidential. Generated briefs are stored with the session so the organiser can view and export them.
The qualitative reflection responses are stored to enable the Strategist Brief. Excerpts can appear in the session owner's participant detail and in the brief.
Responsible disclosure
If you discover a security vulnerability in UseNorth, please report it privately before disclosing it publicly.
Include a description of the vulnerability, steps to reproduce, the potential impact, and any suggested remediation. We acknowledge receipt within 48 hours and respond with an assessment within 5 business days.
Please do not open a public GitHub issue for security vulnerabilities.
Frameworks we reference
NORTH Build maps constraints to ISO/IEC 42001 and NIST AI RMF. This is a mapping, not a certification. We process personal information under POPIA and, where applicable, GDPR; see our Privacy Policy.
This document is reviewed and updated with each significant change to data handling, infrastructure, or third-party integrations. Last reviewed: 1 August 2026.