Normos

Normos

Runs automated agents that continuously check your systems against ISO 27001 and SOC 2 requirements and generate timestamped proof, instead of you scrambling for screenshots the week before an audit.

🔗 Visit Normos
📁 Security & Privacy🗣️ English📅 July 30, 2026

Description

Compliance audits usually mean weeks of manual evidence-gathering — screenshots, exported logs, manually filled spreadsheets — right before an auditor shows up, and that evidence can be stale or inconsistent by the time it's reviewed. Normos calls itself a "forensic compliance evidence platform": autonomous "Sleuth Agents" run continuously against ISO 27001 and SOC 2 controls, generating deterministic, timestamped, notarized proof instead of relying on manually collected screenshots.

It offers a free GitHub repository scan with no signup as an entry point, letting a team see real compliance gaps before committing to anything. The full platform includes a Trust Centre for sharing compliance status externally, and is explicitly positioned as a layer that slots in alongside a company's existing policies and risk register rather than replacing them. Structured pricing data on the site lists an annual offer around £9,600. It's UK-based (Normos Technologies Ltd, London).

💬 Our review

The short version: "stop taking screenshots" is a real, specific complaint from anyone who has prepared for a SOC 2 or ISO 27001 audit, and automating continuous, timestamped evidence collection instead of manual last-minute scrambling is a legitimate improvement if it actually integrates cleanly with your existing systems.

Against a broader GRC platform like Vanta or Drata, which cover a wide swath of compliance frameworks and workflow automation beyond evidence collection, Normos's narrower "forensic proof" angle is specifically about notarized, tamper-evident evidence generation rather than end-to-end compliance program management — worth clarifying which problem you actually have before choosing. At roughly £9,600/year, it's priced in line with mid-market compliance tooling, and the free GitHub scan is a low-risk way to see concrete findings on your own repos before committing to that spend.

💰 Pricing

PaidAround £9,600/year per site structured data. Free GitHub scan available with no signup.

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
💳 Payant

Environ 9 600 £/an (données structurées du site) ; scan GitHub gratuit sans inscription en entrée

👥 Target audienceEntreprises visant ou maintenant une conformité ISO 27001 / SOC 2 voulant des preuves automatisées et continues
🗣️ Languagesen
🌍 Target countriesWorldwide
👍

Pros

Preuves de conformité générées automatiquement et horodatées, pas de captures d'écran manuelles

Scan GitHub gratuit sans inscription pour voir des lacunes réelles

Se positionne comme complément aux politiques existantes, pas un remplacement

👎

Cons

Prix annuel significatif (~9 600£) pour une PME

Portée plus étroite qu'une plateforme GRC complète comme Vanta/Drata

Entreprise récente, moins établie que les leaders du secteur

❓ Frequently asked questions

What is Normos in one sentence?
Is there a free option?
Does it replace my compliance policies?
How much does the full platform cost?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?