Skip to content
NORUM

Trust

NORUM works to the published regulations

You are choosing a supplier that will hold your formulas and generate the panels that go on your packaging. That decision deserves specifics rather than badges, so this page is specifics — including the parts that are not finished.

Labelling

Generated to FDA labelling regulations

Nutrition Facts, Supplement Facts, serving sizes and allergen declarations are calculated from 21 CFR 101.9, 101.12 and 101.36 — parsed from the published text, not typed from memory and never produced by a language model.

Every citation below is checked against the eCFR API and carries the date it was last confirmed.

Signatures

Built to 21 CFR Part 11

Every signature carries a printed name, a time, and what the person meant by it. It is bound to a fingerprint of exactly what was signed, it needs you to confirm who you are again, and it can never be edited or deleted — by anybody, including us.

The table below sets each element beside the rule that asks for it.

Security

Built to the FTC Safeguards Rule

The security programme is built against the controls of 16 CFR 314.4: access control enforced in the database, multi-factor authentication, monitoring and logging, disposal, a designated Qualified Individual and a written incident response plan.

We publish the section-by-section map, including the sections that are not in place.

Electronic signatures

A signature on a specification is the record an auditor opens first. NORUM builds one to the elements 21 CFR Part 11 names for the signature itself, and says plainly which parts of Part 11 nobody but the manufacturer can supply.

What the rule asks forWhat NORUM records
21 CFR 11.50A signed record shows the printed name, the date and time, and the meaning of the signature.All three are stored, all three are required, and the meaning is chosen from a list — authored, reviewed, approved, released, rejected, verified, acknowledged. A signature with no stated meaning is refused, because "approved" and "I have read this" are different acts.
21 CFR 11.70Signatures are linked to their records so they cannot be excised, copied or transferred.Each signature carries the SHA-256 of the exact content signed. Move it to another record and the checksums disagree, visibly — and NORUM will tell you in words that the signature no longer covers what you are looking at.
21 CFR 11.200A signature uses at least two distinct identification components.Signing asks you to confirm who you are again — your password or your authenticator code — within ten minutes of the signature. An open session is not a deliberate act, and NORUM refuses a signature made on a stale one.
21 CFR 11.10(e)A secure, computer-generated, time-stamped audit trail that does not obscure what came before.Signatures are append-only: there is no way to edit one and no way to delete one, for anybody, including us. Changing your mind means signing again with a different meaning; the first signature stays.

And the parts NORUM cannot supply

Part 11 also requires system validation for your intended use, written procedures holding people accountable for signatures made under their name, training records, and control over how credentials are issued and revoked. Those belong to the manufacturer. A supplier who tells you their software makes you Part 11 compliant is describing something software cannot do.

NORUM's signatures are not qualified electronic signatures under eIDAS either — there is no certificate and no trust service provider behind them. Under ESIGN and UETA in the United States, what makes an electronic signature enforceable is intent, consent, association with the record and retention, and those are what is built here.

The regulations NORUM reads

Every rounding rule, daily value and reference amount comes from the published text, parsed by a script. None of it is typed from memory or from a screenshot, and none of it comes from a language model — a regulated number that originated in a model is a number nobody can trace to a source.

Loading the citation list…

How your data is kept apart from everybody else's

Isolation is in the database, not in a query

Every table carrying a workspace id has PostgreSQL row-level security, forced — which means even the table owner obeys the policies. A test runs on every schema change and fails the build if any table ships without it.

Every change is recorded

Who changed what, when, and what it was before. Your audit trail is yours to read from inside your own workspace, without asking NORUM for an export.

A regulated number never comes from a model

AI reads a supplier specification and proposes values. A person reviews them before anything is applied, and no AI output reaches a panel unreviewed. The rounding rules themselves come from the published regulation.

Documents are immutable once released

A released specification pins every input to the version it was read at, with a checksum. Re-running the engine on the same inputs produces the same document years later — which is what makes an audit answerable.

Two-step sign-in

Available on any account, and required for a NORUM operator who has enrolled one. It is a code from an authenticator app rather than a text message, because a phone company can be talked into handing over a number.

A shared link is a link, not a copy

Send a specification to a customer and it expires, can carry a passphrase, records who opened it, and can be revoked. The link itself is stored only as a fingerprint, so a copy of our database is not a copy of your documents.

Nobody at NORUM can open your formulas

Every support console eventually grows a "log in as this customer" button. NORUM does not have one and is not going to. A NORUM operator sees your company name, your plan, and how many products you have — never what is in them. That boundary is enforced by the database, not by a screen, and every cross-tenant read an operator makes is written to a log with no delete policy on it: the person who could tidy it away is exactly the person it exists to record.

If you want somebody at NORUM to look at a problem, you grant it from your own settings, for a reason you type, for hours rather than days. It appears in your audit trail, you can revoke it, and even then it opens error messages and a log of what kind of record was touched — not a formula, a specification or a document.

What NORUM does not claim

This is the section most vendors leave out, which is why it is here.

NORUM is not "FDA approved", and neither is any labelling software.
The FDA does not approve software that generates labels. Any vendor telling you otherwise is describing something that does not exist, and repeating it in your own materials would put you at risk rather than them.
NORUM does not guarantee your label is compliant.
It calculates from the published rules and shows its working. The manufacturer remains responsible for the accuracy and regulatory compliance of what goes on the package. That responsibility cannot be transferred to a supplier, whatever a contract says.
NORUM is not "FTC Safeguards compliant".
Compliance under that Rule is a written programme with a named individual accountable for it, a risk assessment, staff training and vendor oversight. NORUM implements several of the technical controls the Rule names — access control, monitoring, multi-factor authentication, disposal — and our own map says six of fifteen sections are in place. We publish the map rather than the conclusion.
NORUM signatures are not qualified electronic signatures.
They carry no certificate and no trust service provider, so they are not qualified or advanced signatures under eIDAS. They implement the elements 21 CFR Part 11 names for the signature itself — printed name, time, meaning, linkage, two components, append-only — and Part 11 compliance as a whole is a programme, not a feature.
NORUM has not had a penetration test.
Dependency advisories are checked on every build and the authorisation logic has 278 database assertions behind it. Neither is somebody trying to break in, and we will not describe them as though they were.
Nothing pages anybody at 2am.
Problems are recorded and wait to be seen rather than waking somebody up. A failure overnight is found in the morning. If you need a supplier with a 24-hour on-call rota, NORUM is not one yet.
NORUM does not issue GS1 identifiers.
It generates and validates barcodes from numbers you already hold. A GS1 company prefix comes from GS1, at their fee, and NORUM neither resells nor marks that up.

Where the detail is

The security programme is written down rather than summarised. If you are assessing NORUM as a supplier, ask for these and read them — they are candid about what is missing.

  • Multi-tenancy and row-level security — the threat model, and what is assumed hostile.
  • The FTC Safeguards map — section by section, including the nine that are not built.
  • The incident response plan — and the gaps it names in itself.
  • The platform console study — what an operator may touch, and what they may never.

How NORUM works