Scorecard/Noma Security

Noma Security

Data gathering in process

Data security platform protecting AI/ML pipelines and data workflows across the enterprise AI lifecycle.

HQIL
Est2023
Size11-50
EU AI ActLimited Risk
nomasecurity.com
Score
41.1 / 100
Evidence
4 items

Developing safety practices - core foundations in place with room for improvement.

Strengths:Technical Safety
Weaknesses:Governance Maturity, Risk Assessment, Regulatory Readiness, External Engagement
Focus Areas
data securityml pipeline securityai governancedata privacy

Security Assessment

Security-relevant indicators for vendor evaluation

Security Posture
47
TS-01dim: 52
Red Teaming & Pre-deployment Testing
Adversarial testing before deployment
TS-05dim: 52
Robustness & Adversarial Resilience
Resistance to adversarial attacks
RA-01dim: 42
Sector-Specific Risk Assessment
Risk analysis for deployment context
RA-03dim: 42
Dual-Use & Misuse Risk
Dangerous capability awareness
RA-07dim: 42
Incident History & Track Record
Past incidents and response quality
EE-04dim: 22
Vulnerability Disclosure Program
Bug bounty or CVE reporting process
Incident History
Noma Security incident records sourced from AIAAIC Repository and public reporting.
Integration: AIAAIC, OECD AI Incidents Monitor
Third-Party Audits
External audit reports, SOC 2 attestations, and ISO certifications verified where published.
Sources: Company filings, registry lookups
CVE & Disclosures
Known vulnerabilities and security advisories from NVD, GitHub Security Advisories, and vendor pages.
Sources: NVD, GHSA, vendor disclosure pages

Dimension Breakdown

GM
Governance Maturitymedium
Published policies, corporate structure, safety mandate, whistleblowing, executive commitment.
38
1 evidence items
GM-01
TS
Technical Safetymedium
Benchmarks, adversarial robustness, fine-tuning safety, watermarking, model cards, research output.
52
1 evidence items
TS-04
RA
Risk Assessmentlow
Dangerous capability evaluations, thresholds, external testing, bug bounty, halt conditions.
42
1 evidence items
RA-01
RR
Regulatory Readinesslow
ISO 42001, EU AI Act compliance, GPAI obligations, international commitments, incident reporting.
40
1 evidence items
RR-05
EE
External Engagementmedium
Survey participation, research support, transparency, behavior specs, open-source contributions.
22

Social Impact & Safety Profile

Limited

Noma Security focuses on data security and ML pipeline protection. Securing AI training and deployment pipelines has social impact implications through preventing data poisoning and model manipulation, but the company has not published specific social impact policies.

data securitypipeline integrity

Need a detailed report for Noma Security?

Subscribe to express interest in indicator-level evidence, peer benchmarking, and regulatory gap analysis - or reach out to request a full company overview brief.