Skip to content
NORTH
Use casesDemoWhat NORTH surfaces
PricingAbout
Run the diagnostic →
NORTHRun the diagnostic →
Use casesDemoWhat NORTH surfaces
PricingAbout
Trust

Security

UseNorth handles personal and professional information — names, roles, work email addresses, and the diagnostic responses that participants give in conditions they are meant to experience as honest and safe. The security model reflects that responsibility.

What is collected and why

DataWhere storedWhy collected
Name, role, email, organisationnorth_leads, north_responsesCredential issuance and session tracking
Scenario responsesnorth_responses (jsonb)Scoring and team map generation
Reflection textnorth_responsesQualitative diagnostic input for the Brief
Archetype and scoresnorth_leadsCredential and Strategist Brief input
Session codesnorth_sessionsTeam session coordination
Cloud platform and constraintsexecution_* tablesNORTH Build credential and team output

No third-party analytics platform receives individual participant data.

Database security

Participant data is accessed through authenticated application endpoints. We run internal security testing and fix what we find. To report an issue, see Responsible disclosure below.

Direct database access (Supabase secret key, database password) is restricted to infrastructure operations and never touches client-side code.

Participant data handling

Scores in team outputs

A participant's dimension scores are used to calculate their archetype and drive the adaptive Reckoning. Once the team threshold is reached, the session owner can open each participant's dimension profile. The Coalition Map itself shows pattern, not score.

The Coalition Map is directional

It shows pattern, not score. Individual answers are not reconstructed from the map alone. For what a session owner can open, see the FAQ.

The Strategist Brief is confidential

The document is generated for the consulting partner and marked confidential. Generated briefs are stored with the session so the organiser can view and export them.

Reflections inform the Brief

The qualitative reflection responses are stored to enable the Strategist Brief. Excerpts can appear in the session owner's participant detail and in the brief.

Responsible disclosure

If you discover a security vulnerability in UseNorth, please report it privately before disclosing it publicly.

Contact: info@usenorth.xyz
Subject line: Security disclosure — [brief description]

Include a description of the vulnerability, steps to reproduce, the potential impact, and any suggested remediation. We acknowledge receipt within 48 hours and respond with an assessment within 5 business days.

Please do not open a public GitHub issue for security vulnerabilities.

Frameworks we reference

NORTH Build maps constraints to ISO/IEC 42001 and NIST AI RMF. This is a mapping, not a certification. We process personal information under POPIA and, where applicable, GDPR; see our Privacy Policy.

This document is reviewed and updated with each significant change to data handling, infrastructure, or third-party integrations. Last reviewed: 1 August 2026.

© 2026 UseNorth (Pty) Ltd
AboutUse casesSectorsArchetypesMethodologyPre-mortem guideWhat NORTH surfacesArtefact libraryBriefRescore DeltaPricingPartner programmeContactSecurityFAQPrivacyTerms