A plain-language summary of the controls we build into Nora, and how to report a problem to us.
Last updated August 16, 2026
Video sessions run as encrypted peer-to-peer connections between participants. We do not record video or audio, and session links are tied to a specific session and time window.
We are a small team and we describe our controls honestly: Nora has not undergone a third-party security certification or audit. If your practice requires formal attestation, tell us what you need and we'll be straight with you about what we can and cannot provide today.
If you believe you have found a security issue, please tell us through our contact form with enough detail to reproduce it, and give us a reasonable window to respond before disclosing it publicly. Do not access, modify or download data that is not yours while testing, do not run denial-of-service or spam tests, and do not use automated scanners against live client data. We appreciate good-faith reports and will not pursue action against researchers who follow these guidelines.
If we become aware of a security incident affecting personal information, we investigate promptly, contain the issue, and notify affected account holders and, where required, the relevant privacy authorities in line with Canadian law.
Reach us through our contact form and we'll get back to you. This page describes Nora's own practices and is not legal advice for your practice.