NORTHN SECURITY
One page for your security review: the money, the data, the AI
The page to forward to whoever signs off on new vendors. The whole model, in plain language.
Northn never holds your funds
Escrow sits at a regulated, licensed institution.
Nothing trains on client work
Your engagements and evidence never become training data.
Nothing records silently
Capture happens inside an open window, and asks first.
AT A GLANCE
FOR YOUR REVIEWER- FUNDS
- Regulated institution. Never Northn's balance sheet.
- RELEASE
- Client approval, a verified event, or a ruling.
- DATA
- Encrypted in transit and at rest. One tenant per firm.
- RECORD
- Append-only, hash-linked. Digest anchored on a public ledger.
- AI
- Your keys, your provider agreement. No training.
- CAPTURE
- Only inside a step's window. Bounded, prompted.
Don't take our word for the record.
Verify one →FOLLOW THE MONEY
Where funds live, and what can move them
- 1
Client funds
Acceptance moves the milestone amount into escrow at a regulated institution.
- 2
Held, with rules
Every dollar carries its release condition. No one at Northn can move it by hand.
- 3
A trigger fires
Approval, a verified event, or a ruling. The engine sends one signed instruction. No work content.
- 4
Settles same day
Funds move on the rails the parties chose. The engine decides when; the institution moves the money.
CAN RELEASE FUNDS
- The client approves
- The record verifies a named event
- An arbitrator rules
CANNOT
- Anyone at Northn
- A model, however confident
- A timer, or silence
Release conditions are sealed into the record before any evidence exists. A trigger only fires if the record still verifies.
DATA PROTECTION
How your data is protected
Encrypted, everywhere
In transit and at rest — records, evidence, and deliverables in escrow alike.
Isolated tenants
Every firm is a separate tenant. Clients see their engagement only.
Least-privilege access
Role-based, granted on need. Release, dispute, and payout actions are audit-logged.
Sealed, anchored outside us
An append-only, hash-linked history. Its digest lives on a public ledger, so a receipt checks without trusting Northn.
Capture windows, not surveillance
The device records only while a step's window is open, and asks first. Never a running camera.
Deletion & retention
Personal data is deletable on request. Records persist only as long as the parties who relied on them need them.
YOUR CODE & CREATIVE WORK
Proof travels.
The work stays home.
Integrations are read-only and metadata-first. Northn doesn't host your code; what moves is the proof that work happened.
TRAVELS TO NORTHN
- Hashes of every file and capture
- Commit, ticket, and file-version metadata — read-only
- Verdicts, refusal codes, and timestamps
- Deliverables in escrow: encrypted, versioned, handed off with payment
STAYS WITH YOU
- Your source code and repositories
- Your API keys and model provider agreement
- Write access to any of your tools or spend
- Anything outside an open capture window
AI, ON YOUR TERMS
Intelligence without surrender
The referee judges evidence against sealed criteria. It never moves money, and it never trains on you.
Your keys, your agreement
Bring your own API keys. AI runs under your provider agreement, as much or as little as you decide.
No training on client work
Engagements, evidence, and deliverables are never used to train models.
AI advises. Triggers move money.
Nothing releases on a timer or on silence — only on a trigger both sides agreed to, and only if the record still verifies.
The referee refuses
When evidence can't settle a criterion, it says so with a named code and the milestone waits. “Not assessed” is never a pass.
Verdicts are reconstructable
The exact question and evidence the referee saw are sealed before it answers. Replay it, get the same hash.
Agents leave a trace
When an AI agent produces part of a deliverable, its tool calls, inputs, and outputs are sealed as evidence like human work.
Ask us the hard questions first.
We'd rather walk your security team through it before you commit than after. Good-faith security research is welcome: security@northn.dev.
See also our Privacy Policy, Terms of Service, and the mechanism-by-mechanism Verification page.