Enterprise

Start free, and let the security review begin on day one.

Larger organizations do not buy from a page. They buy after a review. So this page is the review material: the record we produce, the access we hold, where it runs, and what we do not do.

The record

One order, one page, timestamps included.

An auditor asking "who approved this access, on what basis, and when was it executed?" gets one page rather than three systems. The reason is captured at request time, not reconstructed afterwards.

Request, reason, approval and every executed change on one record — the evidence an auditor asks for, already written.

Zero standing rights — for people.

The platform has them, and that is the entire point: the right moves from twelve people who can do anything at any time, to one service that can only do what an approved order asks for, with a full trail on every action.

This is the first thing a competent security buyer checks, so we put it in front rather than behind a call. The full permission list is on the security page, with grade and consent status.

Security, hosting and sub-processors
Graph permissions and admin consent status.

Regulated industries

What the rules actually say today.

Norway's digital security act took effect on 1 October 2025 and implements the original NIS directive. NIS2 has not been adopted in Norway and was not incorporated into the EEA agreement as of May 2026; adoption is expected during 2026. Anyone telling you that NIS2 requires something of your Norwegian entity today is selling you a deadline that does not exist.

What is real is the requirement to control who has access to what, and to be able to show it. That is an access management and evidence problem, and it is the one the product solves: no standing rights for people, a reason attached to every change, and an exportable trail.

We do not do access certification campaigns, attestation or segregation-of-duties analysis. If your program requires them, you will need a second tool, and we would rather say so here.

An example, anonymized

A Norwegian group in accounting and advisory.

23 companies, more than 1,000 employees, and three people in IT. One access picture across every legal entity, delegation per company, and cost allocated where it belongs. We name customers only with their written consent, so this one stays anonymous.

Read it, test it, then talk to us.

The order we recommend: start free in read-only, run the report against your own tenant, take the DPA and the permission list to your security team, and only then book a conversation about terms.