--- title: "Noraina: Efficient Cloud infrastructure, disaster recovery and Cloudflare security" description: "Infrastructure sized to each workload in five European data centres, with replication, immutable backups, DNS failover, Cloudflare security and audit evidence." url: https://www.noraina.cloud/ language: en --- # Noraina > Noraina is a European infrastructure and security provider. We run your workloads on our own platform in five data centres in London, Dublin, Paris and Barcelona, with replication between any of them, immutable backups and DNS failover, protect your applications and staff with Cloudflare as an Authorized Service Delivery Partner, and produce the audit evidence for ISO 27001, ENS, PCI DSS, NIS2 and DORA. ## Products - [Efficient Cloud Instances](https://www.noraina.cloud/products/efficient-cloud-instances/): Virtual machines on Noraina's platform in five European data centres, replicated every five minutes to a second site. RPO of 5 minutes, RTO of 15 minutes. - [Efficient Cloud Egress](https://www.noraina.cloud/products/efficient-cloud-egress/): Pay less for data transfer out of AWS, Azure and Google Cloud without changing provider. Built for dynamic and long-tail content, from $0.031 per GB. - [Efficient Cloud Backup](https://www.noraina.cloud/products/efficient-cloud-backup/): Encrypted, immutable backups of your cloud instances outside your cloud provider, at in-region network cost. From €6 per agent plus €0.15 per GB a month. - [Efficient Cloud DNS (NorainaDNS)](https://www.noraina.cloud/products/efficient-cloud-dns/): Managed authoritative DNS on a global anycast network, with health-checked failover, API and Terraform. From $24 a month; multi-cloud DNS on Enterprise. ## Services - [Application security with Cloudflare Enterprise](https://www.noraina.cloud/services/application-security/): Cloudflare WAF, DDoS protection, bot management, API protection and complete logging, designed, deployed and operated by an Authorized Service Delivery Partner. - [Zero Trust and SASE with Cloudflare One](https://www.noraina.cloud/services/zero-trust-sase/): Replace VPNs with identity-based access, filter web and SaaS traffic and stop data leaks with Cloudflare One, plus managed SASE for small companies. - [Engineering and advanced consulting](https://www.noraina.cloud/services/engineering-consulting/): Architecture, migrations and hands-on guidance for teams building on Cloudflare Workers. Your team writes and owns the software; we show how and support it. - [Compliance engineering](https://www.noraina.cloud/services/compliance-engineering/): Gap reviews and evidence for ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR, connecting each control to the infrastructure and security services that support it. ## How customers combine our products - [Lower egress costs for an AWS application, with Cloudflare in front](https://www.noraina.cloud/architectures/cloud-egress-with-cloudflare/): An AWS application behind Cloudflare and Efficient Cloud Egress, so dynamic traffic no longer pays AWS internet egress rates. Also for Azure and Google Cloud. - [Replicated instances in two data centres, with DNS failover](https://www.noraina.cloud/architectures/replicated-instances-dns-failover/): Efficient Cloud Instances replicated between two Noraina data centres, with NorainaDNS health checks that move traffic to the second site when the first fails. - [Specialised servers in our data centres, protected by Cloudflare](https://www.noraina.cloud/architectures/specialised-servers-cloudflare/): GPU or high-core servers in a Noraina data centre, with Cloudflare application security in front of public access and Zero Trust for administration. - [A web stack with European providers only, with Bunny.net](https://www.noraina.cloud/architectures/european-stack/): Servers in Noraina's EU data centres with Bunny.net's CDN and Shield WAF in front, for companies that need every provider in the chain to be European. ## Noraina Tools - [Faro, billing and commitment alerts for Cloudflare Enterprise](https://www.noraina.cloud/tools/faro/): Faro tracks Cloudflare Enterprise usage across every product and account, forecasts spend and alerts you before you exceed a commitment. - [Analytics reports for Cloudflare](https://www.noraina.cloud/tools/analytics/): Generate a Cloudflare analytics report for all the zones in an account, as an HTML report or JSON data, signing in with Cloudflare or a read-only API token. - [SDNS, Cloudflare Zero Trust DNS for UniFi gateways](https://www.noraina.cloud/tools/sdns/): SDNS converts a Cloudflare Zero Trust DNS over HTTPS endpoint into an SDNS stamp, the format UniFi gateways need to use it as their DNS resolver. - [Sentinel, security alert analysis for Cloudflare](https://www.noraina.cloud/tools/sentinel/): Sentinel analyses Cloudflare security alerts with your traffic data and sends Slack a verdict, a severity and proposed WAF or rate limiting rules. - [Dynamic IPsec endpoints for Cloudflare WAN](https://www.noraina.cloud/tools/dynamic-ipsec/): Keeps Cloudflare WAN (Magic WAN) IPsec tunnels up at sites with a dynamic public IP by updating the tunnel endpoint when the address changes. - [Proxy read timeout editor for Cloudflare Enterprise](https://www.noraina.cloud/tools/proxy-timeout/): Review and change the proxy read timeout of every Cloudflare Enterprise zone in an account from one page, signing in with Cloudflare. ## Compliance Pick one to see which of its controls our services support, and the evidence you get for your auditor. - [ISO/IEC 27001:2022](https://www.noraina.cloud/compliance/iso-27001/): 15 controls supported - [Esquema Nacional de Seguridad (Real Decreto 311/2022)](https://www.noraina.cloud/compliance/ens/): 14 controls supported - [PCI DSS v4.0.1](https://www.noraina.cloud/compliance/pci-dss/): 9 controls supported - [NIS2 Directive (EU) 2022/2555](https://www.noraina.cloud/compliance/nis2/): 6 controls supported - [DORA Regulation (EU) 2022/2554](https://www.noraina.cloud/compliance/dora/): 4 controls supported - [GDPR (EU) 2016/679](https://www.noraina.cloud/compliance/gdpr/): 4 controls supported ## Credentials - ISO/IEC 27001 certified operations - Cloudflare partner since 2020, now an Authorized Service Delivery Partner (Powered+) in EMEA - AWS, Microsoft, Google Cloud, Wasabi and Bunny.net partner - Available on AWS Marketplace and Azure Marketplace - Member of the INEX (Dublin), LINX (London) and France-IX (Paris) internet exchanges - Genians partner for OT network security ## Contact - Email: info@norainacloud.com - Phone: +353 21 204 0104 - https://www.noraina.cloud/contact/ ## Frequently asked questions ### What does Noraina do? Noraina runs infrastructure for companies on its own platform in five data centres in London, Dublin, Paris and Barcelona: virtual machines sized to each workload, replication between sites, immutable backups and DNS with automatic failover, sold as the Efficient Cloud products. We also protect applications and staff with Cloudflare Enterprise and Cloudflare One as an Authorized Service Delivery Partner, help teams build on Cloudflare Workers, and map every service to the compliance controls it supports. ### Which certifications and regulations can Noraina help with? ISO/IEC 27001, the Spanish Esquema Nacional de Seguridad (ENS), PCI DSS, NIS2, DORA and GDPR. Our services support specific technical controls in each and produce the evidence your auditor asks for. Certification itself is granted by an accredited body. ### Where is my data stored? In the data centres you choose among our five sites: Equinix LD5 (London), Equinix DB3 (Dublin), Equinix PA2 and Telehouse TH3 (Paris) and Templus (Barcelona). Production and replica can be in any combination, for example both inside the EU, or in different countries. Backups go to Wasabi object storage in a separate location. ### How do we start working with Noraina? Write to us or use the gap review form and we reply within one working day. We start by understanding your infrastructure and requirements, and our engineers join from the first technical conversation, so the proposal you receive is one we have designed, not a price list. --- --- title: "Efficient Cloud products" description: "Efficient Cloud Instances, Egress, Backup and DNS: infrastructure products from Noraina that cut the cost of running on and around the big cloud providers." url: https://www.noraina.cloud/products/ language: en --- # Efficient Cloud products Efficient Cloud Instances, Egress, Backup and DNS: infrastructure products from Noraina that cut the cost of running on and around the big cloud providers. - [Efficient Cloud Instances](https://www.noraina.cloud/products/efficient-cloud-instances/): Virtual machines on Noraina's platform in five European data centres, replicated every five minutes to a second site. RPO of 5 minutes, RTO of 15 minutes. - [Efficient Cloud Egress](https://www.noraina.cloud/products/efficient-cloud-egress/): Pay less for data transfer out of AWS, Azure and Google Cloud without changing provider. Built for dynamic and long-tail content, from $0.031 per GB. - [Efficient Cloud Backup](https://www.noraina.cloud/products/efficient-cloud-backup/): Encrypted, immutable backups of your cloud instances outside your cloud provider, at in-region network cost. From €6 per agent plus €0.15 per GB a month. - [Efficient Cloud DNS (NorainaDNS)](https://www.noraina.cloud/products/efficient-cloud-dns/): Managed authoritative DNS on a global anycast network, with health-checked failover, API and Terraform. From $24 a month; multi-cloud DNS on Enterprise. --- --- title: "Efficient Cloud Instances" description: "Virtual machines on Noraina's platform in five European data centres, replicated every five minutes to a second site. RPO of 5 minutes, RTO of 15 minutes." url: https://www.noraina.cloud/products/efficient-cloud-instances/ language: en --- # Efficient Cloud Instances Efficient Cloud Instances are virtual machines on our own platform in five data centres in London, Dublin, Paris and Barcelona. Disks replicate every five minutes to a second site of your choice, for a recovery point of five minutes at a lower price than a standalone instance at the big cloud providers. ## What you get - High-performance instances with all-SSD storage and 25 Gb/s networking. - Optional replication every five minutes to another site, and managed backup of the instance with [Efficient Cloud Backup](https://www.noraina.cloud/products/efficient-cloud-backup/). - A direct public IP address for applications that do not work behind NAT. - Private IP addresses behind a managed firewall for everything that should not be public. - A control panel with KVM console access to diagnose an instance even when its network is down. - On-demand and reserved pricing. We operate the platform: hypervisors, storage, network, patching and monitoring. You keep full control of what runs inside your instances, or hand that to us as well. ## Five sites, any combination | Facility | City | | --- | --- | | Equinix LD5 | London | | Equinix DB3 | Dublin | | Equinix PA2 | Paris | | Telehouse TH3 | Paris | | Templus | Barcelona | Production and replica can go in any pair of sites. Two sites in Paris keep latency low and data in one country; Dublin and Barcelona keep it in the EU across two jurisdictions; London adds a site outside the EU when that is what you need. ## Recovery objectives | Objective | Value | | --- | --- | | Recovery point (RPO) | 5 minutes | | Recovery time (RTO) | 15 minutes from the decision to fail over | Replication health is monitored and reported, and failover is tested on a schedule with a signed report after every test, so your continuity plan is a procedure you can show an auditor. ## Close to Cloudflare and the big clouds Our network peers locally with Cloudflare and connects directly to AWS, Microsoft Azure and Google Cloud, so traffic to the edge, to R2 and to your other clouds takes short, direct routes. ## Pricing Instances are priced per configuration, on demand or reserved. [Tell us what you need](https://www.noraina.cloud/contact/) and we send a quote the same week. Prices exclude VAT. ## Frequently asked questions ### Where are Noraina's data centres? Noraina runs its platform in Equinix LD5 (London), Equinix DB3 (Dublin), Equinix PA2 (Paris), Telehouse TH3 (Paris) and Templus (Barcelona). ### What are the RPO and RTO of Efficient Cloud Instances? Disks replicate every five minutes, so the recovery point objective is five minutes. The recovery time objective is fifteen minutes, counted from the moment the decision to fail over is taken. ### Can I choose where my instance and its replica run? Yes. Replication works between any two of the five sites, so you can keep both copies in one country, both inside the EU, or deliberately in different countries, depending on what your regulator or customers require. ### Do Efficient Cloud Instances help with business continuity controls in ISO 27001 or ENS? Yes. A replicated second site with tested failover supports ISO/IEC 27001 controls 5.29, 5.30 and 8.14, and ENS measures op.cont.2 to op.cont.4. You receive the architecture description and failover test reports as evidence. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 5.29, 5.30, 8.14 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.cont.2, op.cont.3, op.cont.4 (https://www.noraina.cloud/compliance/ens/) - **NIS2**: 21.2.c (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.11, art.12 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: 32.1.b, 32.1.c (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-09 --- --- title: "Efficient Cloud Egress" description: "Pay less for data transfer out of AWS, Azure and Google Cloud without changing provider. Built for dynamic and long-tail content, from $0.031 per GB." url: https://www.noraina.cloud/products/efficient-cloud-egress/ language: en --- # Efficient Cloud Egress Efficient Cloud Egress cuts the cost of data transfer out of AWS, Microsoft Azure and Google Cloud without moving your applications. Our data centres connect directly to the three providers' networks, so we get the transfer pricing they reserve for their largest customers and pass it on to you. ## How it works Your application keeps running in AWS, Azure or Google Cloud. Efficient Cloud Egress instances in our data centres sit between it and your users: they fetch from your origin over the direct connection to the provider, cache what can be cached, and deliver to the internet from our network. You pay the provider's much lower private-transfer rate for the origin traffic, and we charge for delivery in credits. ## Built for dynamic and long-tail content CDNs are excellent at static files that many users request. They help much less with API responses, personalised pages or large catalogues where each object is requested rarely, which is exactly the traffic that drives most cloud transfer bills. Efficient Cloud Egress is designed for it: - Persistent connections to your origin and caching where the content allows it. - Request collapsing: cacheable objects are locked so only one request per object reaches your backend. - Serving stale content while it updates in the background, so users never wait for a slow origin. - Dynamic pages passed straight through when they cannot be cached. ## Two layers with Cloudflare Many customers with dynamic applications use both: Cloudflare in front for security and for static assets such as JavaScript, CSS and images, and Efficient Cloud Egress behind it for the dynamic traffic that would otherwise be billed by the cloud provider. As a Cloudflare partner we design and run both layers together. ## Included - Edge caching with unlimited purge. - HTTP/2 and your own TLS certificates. - Static and dynamic content. - Active/active instances in more than one region for resilience. - Easy failback to serving directly from the cloud. - Logs available to download. - Management from the web console, Ansible, Terraform or the API. - 24x7 support. ## Pricing Efficient Cloud Egress is priced in credits, with no commitment to a provider plan. All prices exclude VAT. | Usage | Credits | | --- | --- | | Data transfer | 1 credit per GB | | Efficient Cloud Egress instance | 0.5 credits per hour (about 365 per month) | | Credits bought | Price per credit (USD) | | --- | --- | | 512 | $0.050 | | 1,024 or more | $0.045 | | 10,240 or more | $0.040 | | 51,200 or more | $0.037 | | 102,400 or more | $0.035 | | 512,000 or more | $0.033 | | 1,048,576 or more | $0.031 | For example, 5 TB a month with one instance uses 5,120 + 365 = 5,485 credits; at $0.045 per credit that is about $247 a month. How much you save depends on your provider, region and volume, so [send us a recent bill](https://www.noraina.cloud/contact/) and we calculate it on your real traffic. ## Frequently asked questions ### How does Efficient Cloud Egress reduce data transfer costs? Noraina's data centres are directly connected to the AWS, Microsoft Azure and Google Cloud networks, which gives access to the transfer pricing those providers offer their largest customers. Your traffic leaves the cloud through Noraina's instances instead of the provider's internet egress, and we pass the lower price on. ### Do I have to move my application to use Efficient Cloud Egress? No. Your application stays where it is. Efficient Cloud Egress sits in front of it as a caching and delivery layer, and you can fail back to serving directly from the cloud at any time. ### Should I use Efficient Cloud Egress or Cloudflare? They solve different parts of the problem. Cloudflare R2 and CDN are the best fit for static content and for security. Efficient Cloud Egress is built for dynamic and long-tail content that a CDN rarely has in cache. Many customers use both, with Cloudflare for security and static assets and Efficient Cloud Egress for the dynamic traffic that would otherwise be billed by the cloud provider. ### How much does Efficient Cloud Egress cost? It is priced in credits. One credit covers 1 GB of transfer, and an instance uses 0.5 credits per hour, about 365 credits a month. Credits cost from $0.050 down to $0.031 each depending on the volume you buy. Last updated: 2026-10-06 --- --- title: "Efficient Cloud Backup" description: "Encrypted, immutable backups of your cloud instances outside your cloud provider, at in-region network cost. From €6 per agent plus €0.15 per GB a month." url: https://www.noraina.cloud/products/efficient-cloud-backup/ language: en --- # Efficient Cloud Backup Efficient Cloud Backup keeps a copy of your cloud instances and data outside your cloud provider, so a regional outage or a compromised account does not take your backups with it. Backups are encrypted with a key only you hold, locked against deletion, stored in the EU, and moving them costs what a transfer inside the same region would. ## When your cloud provider fails, where is your backup? Most cloud backups live with the same provider, and often in the same region, as the data they protect. That works until the region has an outage, the account is locked, or an attacker with administrator access deletes the snapshots along with everything else. Efficient Cloud Backup puts the copy somewhere else, at a cost that makes it reasonable to do so. ## Efficient on transfer Our backup endpoints sit in the same region as your primary data, so sending backups out costs what a transfer inside that region would. Restoring is included too: bring your data back to the same provider, to another provider or to your own premises without a separate bandwidth bill. ## Efficient on storage Prices are per protected GB, the size of what you back up, not the space the copies take. The GFS option keeps long retention with a fraction of the storage that daily copies for a year would need. ## Protected, encrypted, immutable - Encrypted before it leaves your systems, with a key neither Noraina nor the storage provider knows. - Stored in Wasabi object storage in the EU, with Object Lock so copies cannot be changed or deleted during retention. - Restore to the same cloud, another provider or on-premises. ## Two retention options | Option | What it keeps | Price per month | | --- | --- | --- | | Daily backup, 30 days | One backup a day for the last 30 days | €6 per agent + €0.15 per protected GB | | GFS backup | Daily copies for 15 days, weekly for 8 weeks, monthly for 12 months | €6 per agent + €0.20 per protected GB | Prices exclude VAT. GFS (grandfather, father, son) is the usual choice when a policy requires a year of retention: periodic full backups at three levels give long coverage with far less storage. ## Frequently asked questions ### Why back up outside my cloud provider? Backups at AWS, Azure or Google Cloud usually sit in the same provider and often the same region as the data they protect. A regional outage, a billing problem or an attacker with administrator access to the account can make both unavailable at once. Efficient Cloud Backup keeps the copy with a different provider. ### Isn't moving backups out of the cloud expensive? Normally yes, because of egress charges. Efficient Cloud Backup endpoints are in the same region as your primary data, so the network cost is the same as a transfer inside that region, and restore bandwidth is included in the price. ### Are the backups immutable? Yes. Backups are stored in Wasabi object storage with Object Lock (WORM), so during the retention period nobody can modify or delete them, including an attacker holding administrator credentials. ### Can Noraina read my backups? No. All data is encrypted before it is stored and the encryption key is not known to Noraina or to the storage provider. ### How much does Efficient Cloud Backup cost? The daily backup with 30 days of retention costs €6 per agent plus €0.15 per protected GB a month. The GFS backup, with 15 daily, 8 weekly and 12 monthly copies, costs €6 per agent plus €0.20 per protected GB a month. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 8.13, 8.24, 5.33 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: mp.info.6 (https://www.noraina.cloud/compliance/ens/) - **NIS2**: 21.2.c, 21.2.h (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.12 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: 32.1.a, 32.1.c (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-07 --- --- title: "Efficient Cloud DNS (NorainaDNS)" description: "Managed authoritative DNS on a global anycast network, with health-checked failover, API and Terraform. From $24 a month; multi-cloud DNS on Enterprise." url: https://www.noraina.cloud/products/efficient-cloud-dns/ language: en --- # Efficient Cloud DNS (NorainaDNS) NorainaDNS is managed authoritative DNS with automatic failover. Your domains are served from a global anycast network, health checks switch records to a secondary origin when the primary one fails, and you manage everything from a console, a REST API or a Terraform provider. The Enterprise plan adds a second, redundant multi-cloud DNS network, so DNS stops being a single point of failure. ## Authoritative DNS, managed for you NorainaDNS hosts your zones on a global anycast network, so queries are answered from a location close to each user. It supports A, AAAA, CNAME, TXT, MX, NS, SRV, CAA, PTR and SOA records, and imports and exports BIND zone files, so moving in or out takes minutes. ## Failover that follows your services Attach a health check to any dynamic record. Checks go to your origin directly, not through the CDN or WAF in front of it, so they report whether the origin itself is answering. When the primary origin fails, traffic moves to the secondary one, and it moves back when the primary recovers. Each record can use a routing policy that matches how your infrastructure is deployed: simple, failover, weighted or latency-based. ## No single point of failure in DNS Most architectures put a lot of effort into redundant servers, regions and CDNs, and then depend on one DNS provider. On the Enterprise plan, every change is applied in parallel to the anycast network and to a redundant multi-cloud network. Both answer for your domains, and if a change fails on one of them it is rolled back on both, so they never drift apart. ## Managed as code - A REST API with scoped API keys. - A published [Terraform provider](https://registry.terraform.io/providers/norainacloud/norainadns/latest) for zones, records and health checks. - Usage analytics for queries, health checks and zones, and an audit log of every change. - Sign-in with Google and optional two-factor authentication. ## Pricing All prices are in US dollars and exclude VAT. | Plan | Price | Includes | | --- | --- | --- | | Starter | $24 / month | 1 DNS zone, 3 health checks, 1,000,000 queries a month, automatic failover and traffic steering, usage analytics and audit log, REST API and Terraform provider, Google sign-in and two-factor authentication, onboarding and unlimited support | | Enterprise | Priced per customer | Everything in Starter, plus multi-cloud DNS, a 100% uptime SLA, telephone support, a dedicated onboarding engineer and volume pricing | Capacity beyond the Starter plan is billed by usage, metered hourly: | Item | Price | | --- | --- | | Additional zone | $3.00 / month | | Additional health check | $8.00 / month | | Queries | $1.40 / million | You can [sign up on norainadns.com](https://gcp.norainadns.com/signup) or [talk to us](https://www.noraina.cloud/contact/) about Enterprise. Product site: https://norainadns.com/ ## Frequently asked questions ### What is NorainaDNS? NorainaDNS, also called Efficient Cloud DNS, is managed authoritative DNS from Noraina. It serves your domains from a global anycast network, fails over automatically between origins when a health check fails, and is managed from a console, a REST API or a Terraform provider. The Enterprise plan adds a redundant multi-cloud DNS network. ### How much does NorainaDNS cost? The Starter plan is $24 a month and includes one DNS zone, three health checks and one million queries a month. Beyond that you pay $3 a month per additional zone, $8 a month per additional health check and $1.40 per million queries, metered hourly. Enterprise is priced per customer. Prices exclude VAT. ### How does the automatic failover work? You attach a health check to a record. Checks reach your origin directly, bypassing any CDN or WAF in front of it, so they show whether the origin itself is up. When the primary origin fails, NorainaDNS answers with the secondary one on every network at once, and switches back when the primary recovers. ### Why serve DNS from more than one network? DNS is the one dependency every request has, and in most architectures it depends on a single provider, so a DNS outage takes everything offline no matter how redundant the rest is. With the Enterprise plan, NorainaDNS keeps your zones on its anycast network and on a redundant multi-cloud network at the same time, so if one fails the other keeps answering. ### Who is NorainaDNS for? Teams that want DNS to follow the health of their services, such as applications in more than one data centre or cloud, or several CDNs in front of the same site, and companies whose domains must stay resolvable even if a whole DNS provider has an outage. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 5.29, 5.30, 8.14 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.cont.2, op.cont.4, mp.s.4 (https://www.noraina.cloud/compliance/ens/) - **NIS2**: 21.2.c (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.11 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: 32.1.b, 32.1.c (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-08 --- --- title: "Services" description: "Cloudflare application security, Zero Trust, engineering and compliance engineering, designed and operated by Noraina." url: https://www.noraina.cloud/services/ language: en --- # Services Cloudflare application security, Zero Trust, engineering and compliance engineering, designed and operated by Noraina. - [Application security with Cloudflare Enterprise](https://www.noraina.cloud/services/application-security/): Cloudflare WAF, DDoS protection, bot management, API protection and complete logging, designed, deployed and operated by an Authorized Service Delivery Partner. - [Zero Trust and SASE with Cloudflare One](https://www.noraina.cloud/services/zero-trust-sase/): Replace VPNs with identity-based access, filter web and SaaS traffic and stop data leaks with Cloudflare One, plus managed SASE for small companies. - [Engineering and advanced consulting](https://www.noraina.cloud/services/engineering-consulting/): Architecture, migrations and hands-on guidance for teams building on Cloudflare Workers. Your team writes and owns the software; we show how and support it. - [Compliance engineering](https://www.noraina.cloud/services/compliance-engineering/): Gap reviews and evidence for ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR, connecting each control to the infrastructure and security services that support it. --- --- title: "Application security with Cloudflare Enterprise" description: "Cloudflare WAF, DDoS protection, bot management, API protection and complete logging, designed, deployed and operated by an Authorized Service Delivery Partner." url: https://www.noraina.cloud/services/application-security/ language: en --- # Application security with Cloudflare Enterprise We put Cloudflare in front of your websites, APIs and applications, tune it to your traffic, and keep every log, so attacks are stopped and you can prove what happened. ## Protection in front of every application - Web application firewall with managed and custom rules. - DDoS mitigation for websites, APIs and, with Spectrum, other TCP and UDP services. - Bot management to separate real users from automated traffic. - API protection, including schema validation and discovery of undocumented endpoints. - Page Shield, which watches the scripts loaded on your pages, including payment pages, and alerts on unauthorised changes. ## Every log, kept Cloudflare Enterprise Logpush sends every request, security event and access decision to the destination you choose, for as long as your policy requires. That is the raw material for incident investigation and for the logging and monitoring controls of ISO 27001, ENS, PCI DSS and NIS2. ## Operated, not just installed We start from your real traffic, move rules from log mode to block mode with evidence, and stay on afterwards: monthly threat reviews, rule tuning and changes when your applications change. ## Frequently asked questions ### Is Noraina a Cloudflare partner? Yes. Noraina has been a Cloudflare partner since 2020 and is now an Authorized Service Delivery Partner in EMEA at Powered+ level. We design, deploy and operate Cloudflare Enterprise for our customers. ### How do we keep all Cloudflare logs for an audit? With Cloudflare Enterprise, Logpush streams HTTP requests, firewall events and Zero Trust logs to storage you control, such as R2, or to your SIEM. We configure the jobs and the retention to match your policy. ### Does Noraina manage the Cloudflare configuration after go-live? Yes. We monitor, tune rules, review threats monthly and handle changes, either as a managed service or as on-call support for your team. ### Does Cloudflare help with PCI DSS for an online shop? It supports several requirements. The WAF is the automated protection PCI DSS 6.4.2 asks for in front of public web applications, and Page Shield helps with 6.4.3 and 11.6.1 by keeping an inventory of payment page scripts and detecting changes. Your PCI scope and assessment remain your responsibility. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 8.15, 8.16, 8.20, 8.26 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.exp.8, op.mon.3, mp.s.2, mp.s.4, op.mon.1 (https://www.noraina.cloud/compliance/ens/) - **PCI DSS**: 10.2.1, 10.5.1, 4.2.1, 6.4.2, 6.4.3, 11.6.1 (https://www.noraina.cloud/compliance/pci-dss/) - **NIS2**: 21.2.b, 21.2.e (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.10, art.9 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: art.33, 32.1.b (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-06 --- --- title: "Zero Trust and SASE with Cloudflare One" description: "Replace VPNs with identity-based access, filter web and SaaS traffic and stop data leaks with Cloudflare One, plus managed SASE for small companies." url: https://www.noraina.cloud/services/zero-trust-sase/ language: en --- # Zero Trust and SASE with Cloudflare One We replace the VPN with access per application, verified on every request, and add web filtering and data loss prevention, so people work from anywhere and sensitive data stays where it should. ## Access per application, not per network Cloudflare Access checks who the user is and the state of their device before every connection to an application. There is no network to get lost in, and access is removed in one place when someone leaves. ## Safe browsing and SaaS Cloudflare Gateway filters DNS and web traffic for every user and device, blocks malicious destinations and controls which SaaS and AI tools can be used. ## Data that stays inside Data loss prevention profiles detect sensitive data in uploads and SaaS traffic and stop it before it leaves, with an incident record for every block. ## Managed SASE for small companies For teams under 100 users we run the whole service: onboarding, policies, the block page your people see, and triage of exceptions. ## Frequently asked questions ### What does Cloudflare Zero Trust replace? Mainly the corporate VPN. Instead of putting users on the network, Cloudflare Access grants access to each application after checking identity and device, and Gateway filters internet traffic wherever users are. ### Can Cloudflare One prevent data exfiltration? Yes. Data loss prevention profiles inspect uploads and traffic to SaaS and AI tools and block sensitive content such as national ID numbers, customer data or source code. ### Is there a managed option for small companies? Yes. Our managed SASE service is designed for companies with fewer than 100 users and runs on Cloudflare One Essentials or Advantage, operated by Noraina. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 5.15, 8.5, 8.12, 8.22, 8.23 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.acc.2, op.acc.4, op.acc.6, mp.s.3, mp.com.1 (https://www.noraina.cloud/compliance/ens/) - **PCI DSS**: 1.3.1, 7.2.1, 8.4.2 (https://www.noraina.cloud/compliance/pci-dss/) - **NIS2**: 21.2.i, 21.2.j (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.9 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: 32.1.b (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-07 --- --- title: "Engineering and advanced consulting" description: "Architecture, migrations and hands-on guidance for teams building on Cloudflare Workers. Your team writes and owns the software; we show how and support it." url: https://www.noraina.cloud/services/engineering-consulting/ language: en --- # Engineering and advanced consulting We help your engineers design, build and run software on Cloudflare's network, including AI applications at the edge. We are not a software factory. Your team writes and owns the code, and we teach the patterns, review the work and stay available for support. ## How we work We are not a software factory and we do not hand over turnkey applications. Software you depend on should be understood and maintained by your own team, so we work with your engineers rather than instead of them: - **Design together**: we review what you run today and design the target architecture with your team, on Cloudflare, our infrastructure or a mix of both. - **Show how it is done**: workshops and pair work on the first services, so your engineers learn the patterns for Workers, D1, KV, R2, Queues and AI Gateway on real code. - **Review, not replace**: your team writes the code; we review designs and pull requests and point out what will cause trouble in production. - **Support afterwards**: once it is running, we stay available for questions, reviews and difficult incidents. Your team keeps ownership. ## Architecture and migrations We plan and carry out migrations of DNS, CDN, security rules and storage to Cloudflare in steps you can roll back, and guide your team through moving application logic to Workers. ## Software at the edge Typical projects we help teams build: integrations between business systems, security automation that turns alerts into proposed firewall rules, and AI assistants connected to your data through Cloudflare AI Gateway. Our own tools for Cloudflare are built the same way, and we share what we learned building them. ## Frequently asked questions ### Does Noraina develop custom software for us? No, we do not deliver turnkey software. Your team builds and maintains it, and we work alongside them on the architecture, show how to build it on Cloudflare Workers, review the code and help when something gets difficult. That way the knowledge and the code stay with you. ### What can Noraina help our team build? Applications and integrations on Cloudflare Workers, D1, KV and R2, including AI assistants and agents connected to business systems, security automation and migration tooling. We help with the design, the first working version and the practices to run it in production. ### Can Noraina help migrate an existing platform to Cloudflare? Yes. We plan and carry out migrations of DNS, CDN, security rules and storage, with rollback at each step, and guide your team through moving application logic to Workers. ### What support do we get after the project? Your team owns the software, and we remain available for advice, code and architecture reviews, and help with incidents, as agreed in a support arrangement. Last updated: 2026-10-06 --- --- title: "Compliance engineering" description: "Gap reviews and evidence for ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR, connecting each control to the infrastructure and security services that support it." url: https://www.noraina.cloud/services/compliance-engineering/ language: en --- # Compliance engineering We look at the certification you are preparing, find the controls our infrastructure and security services can support, and give you the evidence your auditor will ask for. ## Start from the control, not the product Every framework asks for the same things in different words: continuity, backup, logging, access control, protection against attacks. We map each of our services to the specific controls it supports in ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR, so you can see the effect before you buy anything. ## Evidence included Each service comes with the records an auditor expects: configuration exports, retention settings, test reports and logs. ## What stays on your side Policies, risk assessment, training and management review are yours. We say so clearly in the gap review, and can introduce you to consultants we work with for the management-system part. ## Frequently asked questions ### Can Noraina certify my company in ISO 27001 or ENS? No supplier can. Certification is granted by an accredited certification body after auditing your whole management system. Noraina supports specific technical controls with its services and gives you the evidence for them. ### What is a gap review? A short engagement in which we compare the controls of the framework you are preparing with what you have today, and tell you which gaps our services close, which stay on your side and how long it will realistically take. ### Noraina holds ISO 27001. Why does that matter to us? Because our operations are audited against the same standard, the services we provide come with documented processes your auditor can rely on. Last updated: 2026-10-05 --- --- title: "Noraina Tools" description: "Software built by Noraina, grouped by what it is for: Cloudflare One, Cloudflare application security, and Cloudflare usage and reporting." url: https://www.noraina.cloud/tools/ language: en --- # Noraina Tools Software built by Noraina, grouped by what it is for: Cloudflare One, Cloudflare application security, and Cloudflare usage and reporting. ## Cloudflare One Tools for Zero Trust and WAN deployments on Cloudflare One, from office DNS filtering to IPsec tunnels at sites with a dynamic IP. - [SDNS, Cloudflare Zero Trust DNS for UniFi gateways](https://www.noraina.cloud/tools/sdns/): SDNS converts a Cloudflare Zero Trust DNS over HTTPS endpoint into an SDNS stamp, the format UniFi gateways need to use it as their DNS resolver. - [Dynamic IPsec endpoints for Cloudflare WAN](https://www.noraina.cloud/tools/dynamic-ipsec/): Keeps Cloudflare WAN (Magic WAN) IPsec tunnels up at sites with a dynamic public IP by updating the tunnel endpoint when the address changes. ## Cloudflare application security Tools for teams that protect websites and APIs with Cloudflare, from alert analysis to origin settings across many zones. - [Sentinel, security alert analysis for Cloudflare](https://www.noraina.cloud/tools/sentinel/): Sentinel analyses Cloudflare security alerts with your traffic data and sends Slack a verdict, a severity and proposed WAF or rate limiting rules. - [Proxy read timeout editor for Cloudflare Enterprise](https://www.noraina.cloud/tools/proxy-timeout/): Review and change the proxy read timeout of every Cloudflare Enterprise zone in an account from one page, signing in with Cloudflare. ## Cloudflare usage and reporting Tools to follow Cloudflare spend, commitments and analytics across every account and zone you manage. - [Faro, billing and commitment alerts for Cloudflare Enterprise](https://www.noraina.cloud/tools/faro/): Faro tracks Cloudflare Enterprise usage across every product and account, forecasts spend and alerts you before you exceed a commitment. - [Analytics reports for Cloudflare](https://www.noraina.cloud/tools/analytics/): Generate a Cloudflare analytics report for all the zones in an account, as an HTML report or JSON data, signing in with Cloudflare or a read-only API token. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. --- --- title: "Faro, billing and commitment alerts for Cloudflare Enterprise" description: "Faro tracks Cloudflare Enterprise usage across every product and account, forecasts spend and alerts you before you exceed a commitment." url: https://www.noraina.cloud/tools/faro/ language: en --- # Faro, billing and commitment alerts for Cloudflare Enterprise Faro is a billing dashboard for Cloudflare Enterprise. It tracks usage across every Cloudflare product, for every account you manage, forecasts spend and warns you before you go over a contracted commitment. ## What Faro does - **Connects in seconds**: sign in with Cloudflare through OAuth, no API tokens to manage. - **Tracks usage everywhere**: daily rollups across Workers, KV, R2, D1, Durable Objects, Queues, zones and more. - **Starts with history**: about 90 days are backfilled for every new account, so charts have context from day one. - **Alerts before you overspend**: threshold alerts on your commitments, delivered to Slack, email or a webhook. ## Who it is for Companies on Cloudflare Enterprise contracts with usage commitments, and partners who manage several Cloudflare accounts and need to see consumption across all of them. ## Getting Faro Faro comes with a 14-day free trial. [Talk to us](https://www.noraina.cloud/contact/) for pricing and onboarding. Open Faro: https://faro.noraina.cloud/ ## Frequently asked questions ### What does Faro do? Faro collects daily usage across Cloudflare products such as Workers, KV, R2, D1, Durable Objects, Queues and zones, for every account you manage, shows how it compares with your Enterprise commitments and sends an alert before you exceed them. ### How does Faro connect to Cloudflare? You sign in with your Cloudflare account through OAuth. There are no API tokens to create or rotate. ### Is there a free trial? Yes, 14 days without a credit card. After the trial, pricing depends on your account footprint. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. Last updated: 2026-10-06 --- --- title: "Analytics reports for Cloudflare" description: "Generate a Cloudflare analytics report for all the zones in an account, as an HTML report or JSON data, signing in with Cloudflare or a read-only API token." url: https://www.noraina.cloud/tools/analytics/ language: en --- # Analytics reports for Cloudflare Noraina's analytics report generator produces a report of Cloudflare traffic and security analytics for every zone in an account, as a shareable HTML report or as JSON data for your own tools. ## What it does Pick an account, and the generator collects the analytics of its zones into one report. Use it to review traffic and threats across many zones at once, to prepare a quarterly review, or to feed the numbers into your own reporting. ## Access - Sign in with your Cloudflare account, or - Use an API token with **Zone Read** and **Analytics Read** permissions, scoped to the account or to all zones. Access is read-only: the generator cannot change your configuration. ## Getting it [Talk to us](https://www.noraina.cloud/contact/) about using the report generator for your accounts. Open the report generator: https://cf-analytics.noraina.cloud/ ## Frequently asked questions ### What permissions does the analytics report need? Read-only access. Sign in with Cloudflare, or use an API token with Zone Read and Analytics Read permissions for the account or the zones you want in the report. ### What formats can the report be generated in? An HTML report you can read and share, or JSON data to process in your own tools. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. Last updated: 2026-10-06 --- --- title: "SDNS, Cloudflare Zero Trust DNS for UniFi gateways" description: "SDNS converts a Cloudflare Zero Trust DNS over HTTPS endpoint into an SDNS stamp, the format UniFi gateways need to use it as their DNS resolver." url: https://www.noraina.cloud/tools/sdns/ language: en --- # SDNS, Cloudflare Zero Trust DNS for UniFi gateways SDNS converts the DNS over HTTPS endpoint of a Cloudflare Zero Trust (Gateway) location into an SDNS stamp, so you can configure UniFi gateways to send every DNS query from your network through Cloudflare's filtering. ## What it does Paste the DNS over HTTPS endpoint of your Cloudflare Zero Trust location, and SDNS returns the matching SDNS stamp. Add that stamp as a custom DNS server on your UniFi gateway, and the whole network resolves through Cloudflare Gateway. ## When it helps - Offices and sites with devices that cannot run the WARP client: printers, cameras, IoT, guest devices. - Small teams that want Cloudflare DNS filtering at the network edge without extra hardware. ## Getting it [Talk to us](https://www.noraina.cloud/contact/) and we help you set up Zero Trust DNS filtering across your sites. Open SDNS: https://sdns.noraina.cloud/ ## Frequently asked questions ### Why do UniFi gateways need an SDNS stamp? UniFi gateways accept custom encrypted DNS servers as SDNS stamps, a compact sdns:// string that describes the resolver. Cloudflare Zero Trust gives you a DNS over HTTPS URL, so it has to be converted before UniFi can use it. ### What do I get by pointing a UniFi gateway at Cloudflare Zero Trust? Every device on the network, including ones that cannot run the WARP client, has its DNS queries filtered by your Cloudflare Gateway policies, logged in your Cloudflare account and encrypted on the way. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. Last updated: 2026-10-06 --- --- title: "Sentinel, security alert analysis for Cloudflare" description: "Sentinel analyses Cloudflare security alerts with your traffic data and sends Slack a verdict, a severity and proposed WAF or rate limiting rules." url: https://www.noraina.cloud/tools/sentinel/ language: en --- # Sentinel, security alert analysis for Cloudflare Sentinel is an alert analysis service for Cloudflare. It takes each security notification, adds the traffic and firewall data behind it, and sends your team a Slack message that says whether the alert matters, how severe it is and which WAF or rate limiting rules would stop it. ## What Sentinel does - **Receives your Cloudflare notifications**: you point a notification policy at Sentinel's webhook, and every alert is verified and checked for duplicates. - **Adds the data behind the alert**: traffic, firewall events, bot scores, WAF attack scores and the rules already in place, for the zone and time window of the alert. - **Separates noise from incidents**: a quick triage step filters false positives and background noise; real incidents get a full analysis. - **Tells you what to do**: a Slack message with the verdict, severity, what the attack looks like and proposed WAF or rate limiting rules ready to review. - **Sends a daily digest**: an optional daily security summary of the previous day's alerts and the rules still pending review. ## Who it is for Teams running Cloudflare Enterprise or Business who receive more security alerts than they can investigate, and who want each one explained in plain language with a recommended action. ## How it is delivered We set up and operate Sentinel for each customer: the read-only API token, the notification policies, the Slack channels and their filters. Analyses for one customer never use another customer's data. ## Getting Sentinel [Talk to us](https://www.noraina.cloud/contact/) about connecting Sentinel to your Cloudflare accounts. ## Frequently asked questions ### Which Cloudflare alerts can Sentinel analyse? HTTP DDoS and layer 3/4 DDoS attack alerts, security events alerts, traffic anomaly alerts, origin error rate alerts and bot detection alerts. Each one is analysed with the analytics of the zone and time window it refers to. ### Does Sentinel change our Cloudflare configuration? No. Sentinel uses a read-only API token. It proposes WAF and rate limiting rules in the Slack message, written against your existing rules, and your team decides whether to apply them. ### How does Sentinel cut down alert noise? A first model triages every alert as a false positive, harmless background noise or something that needs analysis, and only the last group gets a full analysis. Repeated alerts within a cooldown window are grouped, and each Slack channel can have its own severity threshold and alert categories. ### Which AI models does Sentinel use? Triage runs on Workers AI, and the full analysis uses Anthropic's Claude through Cloudflare AI Gateway. Each customer can set the language of the analysis and how cautious its recommendations should be. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. Last updated: 2026-10-06 --- --- title: "Dynamic IPsec endpoints for Cloudflare WAN" description: "Keeps Cloudflare WAN (Magic WAN) IPsec tunnels up at sites with a dynamic public IP by updating the tunnel endpoint when the address changes." url: https://www.noraina.cloud/tools/dynamic-ipsec/ language: en --- # Dynamic IPsec endpoints for Cloudflare WAN Our dynamic IPsec service keeps Cloudflare WAN (formerly Magic WAN) tunnels working at sites whose public IP address changes. When a tunnel degrades, it resolves the site's dynamic DNS name and updates the tunnel's customer endpoint in Cloudflare. ## What it does - **Listens to tunnel health alerts**: a Cloudflare WAN tunnel health notification tells the service when a tunnel degrades or recovers. - **Finds tunnels automatically**: tunnels are registered the first time an alert arrives; you only add the dynamic DNS name for sites that need it. - **Updates the endpoint**: while the tunnel is degraded, it checks the DNS name every few minutes and updates the customer endpoint when the IP has changed. - **Stops when the tunnel is healthy**: it checks tunnel health in Cloudflare analytics and stops once the tunnel has recovered, or after 24 hours. Every degradation, IP change and error is logged, so you can see what happened to each tunnel. ## Who it is for Companies connecting branch offices, shops or small sites to Cloudflare WAN over internet lines without a fixed IP address. ## Getting it We run the service and connect it to your Cloudflare account. [Talk to us](https://www.noraina.cloud/contact/) about your Cloudflare WAN sites. ## Frequently asked questions ### Why does a Cloudflare WAN IPsec tunnel go down when my IP changes? Each IPsec tunnel in Cloudflare WAN is configured with the public IP address of your end, the customer endpoint. If your internet provider assigns a new address, Cloudflare keeps sending to the old one and the tunnel stays down until someone updates it. ### How does the service know the new IP address? Your router or firewall keeps a dynamic DNS name up to date. When Cloudflare reports the tunnel as degraded, the service resolves that name and, if the address has changed, updates the tunnel's customer endpoint through the Cloudflare API. ### What permissions does it need in our Cloudflare account? An API token limited to your account with read and edit permission on IPsec tunnels, to update the endpoint, and read permission on account analytics, to check tunnel health. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. Last updated: 2026-10-06 --- --- title: "Proxy read timeout editor for Cloudflare Enterprise" description: "Review and change the proxy read timeout of every Cloudflare Enterprise zone in an account from one page, signing in with Cloudflare." url: https://www.noraina.cloud/tools/proxy-timeout/ language: en --- # Proxy read timeout editor for Cloudflare Enterprise Our proxy read timeout editor lists every Enterprise zone in a Cloudflare account with its current proxy read timeout, lets you change the zones you choose in one go, and revokes its access as soon as the changes are saved. ## What it does 1. Sign in with your Cloudflare account. There are no API tokens to create. 2. See every Enterprise zone in the account with its current proxy read timeout. 3. Mark the zones you want to change and set the new value for each one. 4. Save. The changes are applied, the result is shown zone by zone, and the access token is revoked. ## Who it is for Teams with many Enterprise zones who need to raise or align the proxy read timeout without changing each zone by hand in the dashboard or through the API. ## Getting it [Talk to us](https://www.noraina.cloud/contact/) if you need help with origin timeouts or other Cloudflare zone settings. Open the timeout editor: https://nct.noraina.cloud/timeout/ ## Frequently asked questions ### What is the proxy read timeout in Cloudflare? It is how long Cloudflare waits for your origin server to send a response before it returns a 524 error. The default is 100 seconds; Enterprise zones can raise it, which helps with slow reports, exports or long API calls. ### What values can I set with the editor? Any value from 100 to 6,000 seconds, zone by zone. Zones you do not mark for editing are left unchanged. ### What access does the editor keep to my Cloudflare account? None. You sign in with Cloudflare through OAuth, and the token is revoked as soon as you save, even if a change fails. Nothing is stored and no refresh token is issued. Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc. Last updated: 2026-10-06 --- --- title: "Reference architectures" description: "How customers combine Noraina products and Cloudflare: lower cloud egress costs, replicated instances with DNS failover, and protected specialised servers." url: https://www.noraina.cloud/architectures/ language: en --- # Reference architectures How customers combine Noraina products and Cloudflare: lower cloud egress costs, replicated instances with DNS failover, and protected specialised servers. - [Lower egress costs for an AWS application, with Cloudflare in front](https://www.noraina.cloud/architectures/cloud-egress-with-cloudflare/): An AWS application behind Cloudflare and Efficient Cloud Egress, so dynamic traffic no longer pays AWS internet egress rates. Also for Azure and Google Cloud. - [Replicated instances in two data centres, with DNS failover](https://www.noraina.cloud/architectures/replicated-instances-dns-failover/): Efficient Cloud Instances replicated between two Noraina data centres, with NorainaDNS health checks that move traffic to the second site when the first fails. - [Specialised servers in our data centres, protected by Cloudflare](https://www.noraina.cloud/architectures/specialised-servers-cloudflare/): GPU or high-core servers in a Noraina data centre, with Cloudflare application security in front of public access and Zero Trust for administration. - [A web stack with European providers only, with Bunny.net](https://www.noraina.cloud/architectures/european-stack/): Servers in Noraina's EU data centres with Bunny.net's CDN and Shield WAF in front, for companies that need every provider in the chain to be European. --- --- title: "Lower egress costs for an AWS application, with Cloudflare in front" description: "An AWS application behind Cloudflare and Efficient Cloud Egress, so dynamic traffic no longer pays AWS internet egress rates. Also for Azure and Google Cloud." url: https://www.noraina.cloud/architectures/cloud-egress-with-cloudflare/ language: en --- # Lower egress costs for an AWS application, with Cloudflare in front For companies with an application in AWS, Azure or Google Cloud whose data transfer bill is driven by dynamic content. Cloudflare protects the application and serves static assets; Efficient Cloud Egress delivers the dynamic traffic from our data centres, which fetch from your cloud over a direct connection at a much lower transfer rate. ## The problem The application runs in AWS. Cloudflare already caches its JavaScript, CSS and images, but the rest of the traffic is API responses, personalised pages and a large catalogue where each object is requested rarely. That traffic misses the cache, comes out of AWS through its internet egress, and is most of the data transfer bill. ## How the pieces fit 1. **Cloudflare** receives every request. The WAF, DDoS protection and bot management filter it, and static assets are served from Cloudflare's cache. 2. Requests that miss the cache go to **Efficient Cloud Egress** instances in our data centres, configured as Cloudflare's origin. They keep persistent connections to your application, cache what the content allows, collapse simultaneous requests for the same object into one, and pass dynamic pages straight through. 3. Efficient Cloud Egress fetches from your **origin in AWS** over our direct connection to the AWS network. AWS bills that traffic at its private transfer rate, and we bill delivery in credits. The same design works with Microsoft Azure and Google Cloud, which our data centres are also connected to. ## What you get - One security layer in front of the application, with every log kept through Cloudflare Logpush. - Lower transfer cost for the dynamic traffic, without changing the application or its provider. - Active/active Efficient Cloud Egress instances in more than one site, and a tested failback to serving directly from AWS. - One team that designs and runs both layers, as a Cloudflare Authorized Service Delivery Partner. ## Cost Efficient Cloud Egress is priced from $0.031 per GB, plus Cloudflare according to your plan; see the [Efficient Cloud Egress pricing](https://www.noraina.cloud/products/efficient-cloud-egress/#pricing). How much you save depends on your provider, region and volume, so [send us a recent bill](https://www.noraina.cloud/contact/) and we calculate it on your real traffic. ## Frequently asked questions ### Do I need to move my application out of AWS to lower egress costs? No. The application stays in AWS, Azure or Google Cloud. Efficient Cloud Egress sits between Cloudflare and your origin and fetches from it over a direct connection to the provider, so the origin traffic is billed at the provider's private transfer rate instead of its internet egress rate. ### Why use both Cloudflare and Efficient Cloud Egress? Cloudflare is the best fit for security and for static assets that many users request, which it serves from cache. Dynamic pages, API responses and long-tail content are rarely in a CDN cache, so they still reach your origin and still pay egress. Efficient Cloud Egress handles that part of the traffic. ### What happens if Efficient Cloud Egress has a problem? Cloudflare can send traffic straight to your cloud origin again by changing its origin setting, which is the failback path we configure from the start. You go back to paying the provider's egress rate for that traffic, and nothing else changes for your users. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 8.15, 8.16, 8.20, 8.26 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.exp.8, op.mon.3, mp.s.2, mp.s.4, op.mon.1 (https://www.noraina.cloud/compliance/ens/) - **PCI DSS**: 10.2.1, 10.5.1, 4.2.1, 6.4.2, 6.4.3, 11.6.1 (https://www.noraina.cloud/compliance/pci-dss/) - **NIS2**: 21.2.b, 21.2.e (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.10, art.9 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: art.33, 32.1.b (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-08 --- --- title: "Replicated instances in two data centres, with DNS failover" description: "Efficient Cloud Instances replicated between two Noraina data centres, with NorainaDNS health checks that move traffic to the second site when the first fails." url: https://www.noraina.cloud/architectures/replicated-instances-dns-failover/ language: en --- # Replicated instances in two data centres, with DNS failover For companies that need an application to keep running if a whole data centre fails, without building their own disaster recovery site. Instances run in one of our data centres and replicate every five minutes to a second one; NorainaDNS health checks send users to the second site when the first stops answering. ## How the pieces fit 1. **Efficient Cloud Instances** run the application in a primary data centre, for example Equinix DB3 in Dublin. Their disks replicate every five minutes to a second site you choose, for example Templus in Barcelona. 2. **NorainaDNS** serves the application's domain. Its records are failover records: the primary answer is the address in the first site, with a health check that reaches the application directly; the secondary answer is the address in the second site. 3. When the first site fails, the replica is started in the second site, and NorainaDNS answers with the secondary address as soon as the primary health check fails. 4. **Efficient Cloud Backup** keeps immutable copies outside our platform, for the failures replication cannot fix, such as deleted data or ransomware. Stateless parts of the application, such as web front ends, can run in both sites at once with weighted records, so only the stateful part waits for the failover. ## Failing back Once the replica has taken writes, the original site has to be resynchronised before traffic returns to it. We agree with you how failback is triggered, so the health check alone never sends users back to stale data. ## What you get - Production and replica in any two of our five sites: London, Dublin, Paris (two sites) and Barcelona. - Recovery point of five minutes and recovery time of fifteen minutes from the decision to fail over. - DNS that follows the health of each site, managed from the console, the API or Terraform. - Failover tests on a schedule with a signed report, as evidence for business continuity controls in ISO 27001, ENS, NIS2 and DORA. ## Cost NorainaDNS starts at $24 a month, with $8 a month for each additional health check; see the [NorainaDNS pricing](https://www.noraina.cloud/products/efficient-cloud-dns/#pricing). Instances and backup are quoted for your configuration: [tell us what you run](https://www.noraina.cloud/contact/) and we send a quote the same week. ## Frequently asked questions ### How do users reach the second data centre after a failover? The application's DNS records are failover records in NorainaDNS, with a health check on the primary site. When the health check fails, NorainaDNS answers with the address of the second site, so users reach the replica without anyone editing DNS during the incident. ### How much data can be lost when failing over to the second data centre? Disks replicate every five minutes, so the recovery point objective is five minutes. The recovery time objective is fifteen minutes from the decision to fail over. ### Is replication to a second data centre a backup? No. Replication copies every change, including a deletion or ransomware encryption, to the second site within minutes. That is why this architecture adds Efficient Cloud Backup, with immutable copies outside our platform that can be restored to a point in time. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 5.29, 5.30, 8.14, 8.13, 8.24, 5.33 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.cont.2, op.cont.3, op.cont.4, mp.info.6, mp.s.4 (https://www.noraina.cloud/compliance/ens/) - **NIS2**: 21.2.c, 21.2.h (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.11, art.12 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: 32.1.b, 32.1.c, 32.1.a (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-08 --- --- title: "Specialised servers in our data centres, protected by Cloudflare" description: "GPU or high-core servers in a Noraina data centre, with Cloudflare application security in front of public access and Zero Trust for administration." url: https://www.noraina.cloud/architectures/specialised-servers-cloudflare/ language: en --- # Specialised servers in our data centres, protected by Cloudflare For companies that need machines the big clouds price highly or cannot place where they need them, such as GPU servers or servers with many cores, in a European data centre of their choice. Public traffic reaches them only through Cloudflare's application security, and administrators connect through Cloudflare Zero Trust instead of a VPN or open SSH ports. ## The problem Some workloads need hardware that is expensive in the big clouds or not available in the region they must run in: GPUs for inference or rendering, servers with many cores for simulation or builds. Running that hardware yourself means a public IP address, open ports for users and for administrators, and a VPN to maintain. ## How the pieces fit 1. **The servers** run in the Noraina data centre you choose, with the configuration your workload needs. We operate the platform, network and firewall around them; you keep control of what runs inside. 2. **Public access** goes through Cloudflare. A Cloudflare Tunnel connects the server out to Cloudflare, so nothing listens on the internet. The WAF, DDoS protection, bot management and API protection filter every request first. 3. **Administrative access** goes through Cloudflare Access. SSH, RDP and management consoles are published as applications with policies based on identity and device posture, and every session is logged. 4. **Logs** from both paths are kept with Cloudflare Logpush in storage you control or in your SIEM. Our network peers locally with Cloudflare, so the path between the servers and the edge is short. ## What you get - The hardware your workload needs, in the European data centre and country you need. - No open inbound ports for users or administrators. - No VPN: access per application, verified on every connection and removed in one place. - A complete log of who accessed what, as evidence for access control and logging requirements. ## Cost Server configurations are quoted per workload, and Cloudflare depends on your plan. [Tell us what you need to run](https://www.noraina.cloud/contact/) and we send a proposal. ## Frequently asked questions ### Can I run GPU servers in a European data centre with Noraina? Yes. We place servers with the hardware your workload needs, such as GPUs or high core counts, in one of our data centres in London, Dublin, Paris or Barcelona, and run the platform around them. Tell us the workload and the site you need, and we propose a configuration and a price. ### How do we expose a service on our server without opening it to the internet? A Cloudflare Tunnel runs on the server and connects out to Cloudflare, so there are no open inbound ports. Users reach the service through Cloudflare, where the WAF, DDoS protection and bot management filter every request before it reaches the server. ### How do administrators connect to the servers without a VPN? Through Cloudflare Access. Each SSH, RDP or web console is an application with its own policy that checks the administrator's identity and device before every connection, and every session is logged. Access is removed in one place when someone leaves. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 8.15, 8.16, 8.20, 8.26, 5.15, 8.5, 8.12, 8.22, 8.23 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.exp.8, op.mon.3, mp.s.2, mp.s.4, op.mon.1, op.acc.2, op.acc.4, op.acc.6, mp.s.3, mp.com.1 (https://www.noraina.cloud/compliance/ens/) - **PCI DSS**: 10.2.1, 10.5.1, 4.2.1, 6.4.2, 6.4.3, 11.6.1, 1.3.1, 7.2.1, 8.4.2 (https://www.noraina.cloud/compliance/pci-dss/) - **NIS2**: 21.2.b, 21.2.e, 21.2.i, 21.2.j (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.10, art.9 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: art.33, 32.1.b (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-08 --- --- title: "A web stack with European providers only, with Bunny.net" description: "Servers in Noraina's EU data centres with Bunny.net's CDN and Shield WAF in front, for companies that need every provider in the chain to be European." url: https://www.noraina.cloud/architectures/european-stack/ language: en --- # A web stack with European providers only, with Bunny.net For companies whose regulator, customers or policy require every provider serving an application to be European. The servers run on our platform in our EU data centres, and Bunny.net, a CDN and edge security company based in Europe, delivers and protects the traffic with its CDN and its Shield web application firewall. ## The problem The application must be protected and delivered quickly, and the policy is that no provider in the chain is headquartered outside Europe. That rules out the big cloud providers and the most common CDN and WAF services, and leaves the work of putting together a European alternative that is as easy to run. ## How the pieces fit 1. **Bunny.net CDN** receives every request and serves cached content from its network, close to each user. 2. **Bunny Shield** filters the traffic before it reaches your servers: a web application firewall against the OWASP Top 10, SQL injection and cross-site scripting, DDoS protection, rate limiting, bot mitigation and access lists. 3. **Efficient Cloud Instances** run the application in one of our EU data centres, Dublin, Paris or Barcelona, and can replicate every five minutes to a second EU site. 4. **Administration** goes through private addresses behind our managed firewall, not through the internet. As a Bunny.net partner, we design the setup with you, configure Bunny.net and our platform together, and run both if you want us to. ## What you get - Delivery, web application protection and servers from European companies only. - Servers and data in the EU site you choose, with replication to a second EU site. - Caching rules that decide which content may be stored at the edge and which is always fetched from your servers. - One team that designs and runs the whole chain. ## Backups [Efficient Cloud Backup](https://www.noraina.cloud/products/efficient-cloud-backup/) stores its copies in the EU, encrypted before they leave your servers with a key that neither we nor the storage provider hold. The storage provider, Wasabi, is headquartered in the United States, so if your policy also covers who stores encrypted data, tell us and we agree a backup target with you. ## Cost Instances are quoted for your configuration, and Bunny.net is billed by usage according to its pricing. [Tell us what you run](https://www.noraina.cloud/contact/) and we send a proposal. ## Frequently asked questions ### Can I run a website with a CDN and a WAF using only European providers? Yes. We run the servers on our platform in Dublin, Paris or Barcelona, and put Bunny.net in front, a European company whose CDN caches and delivers content and whose Shield product adds a web application firewall, DDoS protection, rate limiting and bot mitigation. Noraina is an Irish company and a Bunny.net partner, so every provider in the chain is European. ### Does a European CDN keep my content inside Europe? Not by itself. Bunny.net is European, but like any CDN it serves cached copies from locations close to each user, including outside Europe. If some content must not be cached outside the EU, we design the caching rules so that it is passed through to your servers instead of being stored at the edge. ## Compliance Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. - **ISO 27001**: 5.29, 5.30, 8.14 (https://www.noraina.cloud/compliance/iso-27001/) - **ENS**: op.cont.2, op.cont.3, op.cont.4 (https://www.noraina.cloud/compliance/ens/) - **NIS2**: 21.2.c (https://www.noraina.cloud/compliance/nis2/) - **DORA**: art.11, art.12 (https://www.noraina.cloud/compliance/dora/) - **GDPR**: 32.1.b, 32.1.c (https://www.noraina.cloud/compliance/gdpr/) Last updated: 2026-10-08 --- --- title: "Compliance navigator: ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR" description: "See which controls of your certification or regulation Noraina products and services support, and the audit evidence each one produces." url: https://www.noraina.cloud/compliance/ language: en --- # Compliance navigator: ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR See which controls of your certification or regulation Noraina products and services support, and the audit evidence each one produces. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. Machine-readable dataset: https://www.noraina.cloud/compliance.json ## European by design For many regulated companies, where data lives and who runs the platform matter as much as any control. Noraina is a European company, our platform runs in European data centres, and your data stays in the site you choose. - Noraina Ltd is an Irish company, registered in Cork. Our contracts are under Irish law. - Our platform runs in five data centres in Europe, operated by our own team: Dublin, Paris (two sites) and Barcelona inside the EU, and London in the UK. - Your data stays where you put it. Our standard contract says we never transfer, store or process customer data outside the region you designate without your explicit consent. - Efficient Cloud Backup stores its encrypted copies in the EU, with a key that neither we nor the storage provider know. - We peer locally at INEX (Dublin), LINX (London) and France-IX (Paris). - Our services support controls in European regulations, ENS, NIS2, DORA and GDPR, as well as ISO 27001, and our own operations are ISO 27001 certified. Some of our services are built on providers headquartered outside Europe: Cloudflare, AWS, Microsoft Azure, Google Cloud and Wasabi. Each page says which one a service uses, and our privacy policy explains the safeguards for any transfer. ### A stack with no provider outside Europe When your requirement is that every provider in the chain is European, we build it from our platform and our partner Bunny.net: servers in our EU data centres, with Bunny.net's CDN and Shield web application firewall in front. https://www.noraina.cloud/architectures/european-stack/ ## ISO/IEC 27001:2022 International standard for information security management systems. References are Annex A control numbers. 15 controls supported. ### Efficient Cloud Instances with replication - Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities) - How we help: Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives. - Evidence you get: Architecture and RPO/RTO statement, replication health reports, signed records of failover tests. - Status: Mapping under review ### Efficient Cloud Backup - Control: 8.13 (Information backup); 8.24 (Use of cryptography); 5.33 (Protection of records) - How we help: Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials. - Evidence you get: Backup policy settings, Object Lock retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities) - How we help: Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure. - Evidence you get: NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history. - Status: Mapping under review ### Complete edge logging - Control: 8.15 (Logging); 8.16 (Monitoring activities) - How we help: Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define. - Evidence you get: Logpush job inventory, retention settings, example investigation queries. - Status: Mapping under review ### Application and DDoS protection - Control: 8.20 (Network security); 8.26 (Application security requirements) - How we help: WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application. - Evidence you get: Security configuration export, monthly threat reports, change history. - Status: Mapping under review ### Zero Trust access and data protection - Control: 5.15 (Access control rules); 8.5 (Secure authentication); 8.12 (Data leakage prevention); 8.22 (Segregation of networks); 8.23 (Web filtering) - How we help: Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools. - Evidence you get: Access policy export, DLP profiles and incidents, Gateway policy export, access logs. - Status: Mapping under review ## Esquema Nacional de Seguridad (Real Decreto 311/2022) Spain's mandatory security framework for the public sector and the companies that supply it. References are measures from Annex II of RD 311/2022. 14 controls supported. ### Efficient Cloud Instances with replication - Control: op.cont.2 (Continuity plan); op.cont.3 (Periodic continuity tests); op.cont.4 (Alternative means) - How we help: Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include. - Evidence you get: Continuity architecture document, failover test reports with dates and results. - Status: Mapping under review ### Efficient Cloud Backup - Control: mp.info.6 (Backups) - How we help: Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware. - Evidence you get: Backup scope and retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: op.cont.2 (Continuity plan); op.cont.4 (Alternative means); mp.s.4 (Denial-of-service protection) - How we help: On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage. - Evidence you get: NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history. - Status: Mapping under review ### Complete edge logging - Control: op.exp.8 (Activity logging); op.mon.3 (Surveillance) - How we help: Records user and system activity at the edge and feeds continuous monitoring. - Evidence you get: Log retention configuration and sample activity reports. - Status: Mapping under review ### Application and DDoS protection - Control: mp.s.2 (Protection of web services and applications); mp.s.4 (Denial-of-service protection); op.mon.1 (Intrusion detection) - How we help: Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts. - Evidence you get: Security configuration export and monthly threat reports. - Status: Mapping under review ### Zero Trust access and data protection - Control: op.acc.2 (Access requirements); op.acc.4 (Access rights management); op.acc.6 (Authentication of internal users); mp.s.3 (Web browsing protection); mp.com.1 (Secure perimeter) - How we help: Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs. - Evidence you get: Access and Gateway policy exports, authentication logs. - Status: Mapping under review ## PCI DSS v4.0.1 Security standard of the payment card industry for every system that stores, processes or transmits card data. References are PCI DSS requirement numbers; titles are our own summaries. 9 controls supported. ### Complete edge logging - Control: 10.2.1 (Audit logs enabled and active); 10.5.1 (Audit log history kept for at least twelve months) - How we help: Logpush sends every request, security event and access decision to storage you control, such as R2, retained for twelve months or more. - Evidence you get: Logpush job inventory, retention settings, sample log queries. - Status: Mapping under review ### Application and DDoS protection - Control: 4.2.1 (Strong cryptography for card data over public networks); 6.4.2 (Automated protection of public-facing web applications); 6.4.3 (Inventory and authorisation of payment page scripts); 11.6.1 (Detection of unauthorised changes to payment pages) - How we help: Cloudflare WAF is the automated solution in front of your public web applications, TLS is enforced at the edge, and Page Shield keeps an inventory of the scripts on your payment pages and alerts on unauthorised changes. - Evidence you get: WAF configuration and blocked-attack reports, TLS settings, Page Shield script inventory and change alerts. - Status: Mapping under review ### Zero Trust access and data protection - Control: 1.3.1 (Inbound traffic to the card data environment restricted); 7.2.1 (Access granted by role and need to know); 8.4.2 (Multi-factor authentication for access to the card data environment) - How we help: Systems in the card data environment are reachable only through Cloudflare Access, per role and with multi-factor authentication, with no inbound ports open to the internet. - Evidence you get: Access policy export, authentication logs, tunnel configuration. - Status: Mapping under review ## NIS2 Directive (EU) 2022/2555 EU directive on cybersecurity risk-management measures for essential and important entities. References are points of Article 21(2). 6 controls supported. ### Efficient Cloud Instances with replication - Control: 21.2.c (Business continuity) - How we help: A second site and tested failover are the disaster-recovery part of the measures NIS2 requires. - Evidence you get: Disaster-recovery plan inputs, failover test reports. - Status: Mapping under review ### Efficient Cloud Backup - Control: 21.2.c (Business continuity); 21.2.h (Cryptography and encryption) - How we help: Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware. - Evidence you get: Backup and retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: 21.2.c (Business continuity) - How we help: Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires. - Evidence you get: DNS architecture description, failover configuration, failover event history. - Status: Mapping under review ### Complete edge logging - Control: 21.2.b (Incident handling) - How we help: Complete logs are what make incident detection, analysis and reporting possible. - Evidence you get: Log inventory and the queries used in incident handling. - Status: Mapping under review ### Application and DDoS protection - Control: 21.2.e (Security in acquisition) - How we help: Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed. - Evidence you get: WAF rule history and threat reports. - Status: Mapping under review ### Zero Trust access and data protection - Control: 21.2.i (Access control policies); 21.2.j (Multi-factor authentication and secured communications) - How we help: Access control policies enforced per application, with multi-factor authentication and encrypted connections. - Evidence you get: Access policy export and authentication logs. - Status: Mapping under review ## DORA Regulation (EU) 2022/2554 EU regulation on digital operational resilience for the financial sector. References are articles of the regulation. 4 controls supported. ### Efficient Cloud Instances with replication - Control: art.11 (Response and recovery); art.12 (Backup) - How we help: A geographically separate recovery site with tested switchover supports your ICT response and recovery plans. - Evidence you get: RPO/RTO statement, switchover test reports, site and provider details for your ICT third-party register. - Status: Mapping under review ### Efficient Cloud Backup - Control: art.12 (Backup) - How we help: Backups held apart from your production systems and protected from change, with documented restoration procedures. - Evidence you get: Backup policy settings, retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: art.11 (Response and recovery) - How we help: Switches traffic to a secondary service automatically and, on the Enterprise plan, keeps critical domains resolvable through the failure of a single DNS provider, supporting the response and recovery arrangements DORA asks for. - Evidence you get: DNS architecture description, failover configuration, failover event history. - Status: Mapping under review ### Complete edge logging - Control: art.10 (Detection) - How we help: Edge logs and security events feed the mechanisms that detect anomalous activity. - Evidence you get: Log inventory, alerting rules, retention settings. - Status: Mapping under review ### Application and DDoS protection - Control: art.9 (Protection and prevention) - How we help: Protection and prevention controls at the edge for your customer-facing services. - Evidence you get: Security configuration export and threat reports. - Status: Mapping under review ### Zero Trust access and data protection - Control: art.9 (Protection and prevention) - How we help: Strong authentication and least-privilege access to ICT systems. - Evidence you get: Access policy export and access logs. - Status: Mapping under review ## GDPR (EU) 2016/679 EU regulation on the protection of personal data. References are articles of the regulation. 4 controls supported. ### Efficient Cloud Instances with replication - Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability) - How we help: Keeps systems that process personal data available and restorable after an incident in the primary site. - Evidence you get: Recovery test reports for your Article 32 documentation. - Status: Mapping under review ### Efficient Cloud Backup - Control: 32.1.a (Pseudonymisation and encryption); 32.1.c (Timely restoration of availability) - How we help: Encrypted backups that let you restore access to personal data in a timely manner. - Evidence you get: Encryption and restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability) - How we help: Automatic failover, and on the Enterprise plan a second authoritative DNS network, help keep services that process personal data available, and restore access quickly when a primary service fails. - Evidence you get: NS delegation showing both networks (Enterprise), failover configuration and event history. - Status: Mapping under review ### Complete edge logging - Control: art.33 (Breach notification) - How we help: Lets you establish what happened, and to which data, within the 72-hour notification window. - Evidence you get: Log retention configuration, investigation runbook. - Status: Mapping under review ### Application and DDoS protection - Control: 32.1.b (Confidentiality) - How we help: Keeps applications that process personal data available and protected against attack. - Evidence you get: Threat reports for your Article 32 documentation. - Status: Mapping under review ### Zero Trust access and data protection - Control: 32.1.b (Confidentiality) - How we help: Only authorised people reach personal data, and DLP blocks it from leaving through unapproved channels. - Evidence you get: Access policy export, DLP incident reports. - Status: Mapping under review --- --- title: "ISO 27001: controls supported by Noraina" description: "Which ISO 27001 controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit." url: https://www.noraina.cloud/compliance/iso-27001/ language: en --- # ISO 27001: controls supported by Noraina Any organisation that needs to show customers a certified security management system. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. ## ISO/IEC 27001:2022 International standard for information security management systems. References are Annex A control numbers. 15 controls supported. ### Efficient Cloud Instances with replication - Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities) - How we help: Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives. - Evidence you get: Architecture and RPO/RTO statement, replication health reports, signed records of failover tests. - Status: Mapping under review ### Efficient Cloud Backup - Control: 8.13 (Information backup); 8.24 (Use of cryptography); 5.33 (Protection of records) - How we help: Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials. - Evidence you get: Backup policy settings, Object Lock retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities) - How we help: Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure. - Evidence you get: NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history. - Status: Mapping under review ### Complete edge logging - Control: 8.15 (Logging); 8.16 (Monitoring activities) - How we help: Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define. - Evidence you get: Logpush job inventory, retention settings, example investigation queries. - Status: Mapping under review ### Application and DDoS protection - Control: 8.20 (Network security); 8.26 (Application security requirements) - How we help: WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application. - Evidence you get: Security configuration export, monthly threat reports, change history. - Status: Mapping under review ### Zero Trust access and data protection - Control: 5.15 (Access control rules); 8.5 (Secure authentication); 8.12 (Data leakage prevention); 8.22 (Segregation of networks); 8.23 (Web filtering) - How we help: Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools. - Evidence you get: Access policy export, DLP profiles and incidents, Gateway policy export, access logs. - Status: Mapping under review We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/iso-27001/#assessment --- --- title: "ENS: controls supported by Noraina" description: "Which ENS controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit." url: https://www.noraina.cloud/compliance/ens/ language: en --- # ENS: controls supported by Noraina Public bodies in Spain and any supplier providing them with ICT services. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. ## Esquema Nacional de Seguridad (Real Decreto 311/2022) Spain's mandatory security framework for the public sector and the companies that supply it. References are measures from Annex II of RD 311/2022. 14 controls supported. ### Efficient Cloud Instances with replication - Control: op.cont.2 (Continuity plan); op.cont.3 (Periodic continuity tests); op.cont.4 (Alternative means) - How we help: Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include. - Evidence you get: Continuity architecture document, failover test reports with dates and results. - Status: Mapping under review ### Efficient Cloud Backup - Control: mp.info.6 (Backups) - How we help: Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware. - Evidence you get: Backup scope and retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: op.cont.2 (Continuity plan); op.cont.4 (Alternative means); mp.s.4 (Denial-of-service protection) - How we help: On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage. - Evidence you get: NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history. - Status: Mapping under review ### Complete edge logging - Control: op.exp.8 (Activity logging); op.mon.3 (Surveillance) - How we help: Records user and system activity at the edge and feeds continuous monitoring. - Evidence you get: Log retention configuration and sample activity reports. - Status: Mapping under review ### Application and DDoS protection - Control: mp.s.2 (Protection of web services and applications); mp.s.4 (Denial-of-service protection); op.mon.1 (Intrusion detection) - How we help: Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts. - Evidence you get: Security configuration export and monthly threat reports. - Status: Mapping under review ### Zero Trust access and data protection - Control: op.acc.2 (Access requirements); op.acc.4 (Access rights management); op.acc.6 (Authentication of internal users); mp.s.3 (Web browsing protection); mp.com.1 (Secure perimeter) - How we help: Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs. - Evidence you get: Access and Gateway policy exports, authentication logs. - Status: Mapping under review We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/ens/#assessment --- --- title: "PCI DSS: controls supported by Noraina" description: "Which PCI DSS controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit." url: https://www.noraina.cloud/compliance/pci-dss/ language: en --- # PCI DSS: controls supported by Noraina Merchants, payment service providers and any company whose website or systems touch card payments. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. ## PCI DSS v4.0.1 Security standard of the payment card industry for every system that stores, processes or transmits card data. References are PCI DSS requirement numbers; titles are our own summaries. 9 controls supported. ### Complete edge logging - Control: 10.2.1 (Audit logs enabled and active); 10.5.1 (Audit log history kept for at least twelve months) - How we help: Logpush sends every request, security event and access decision to storage you control, such as R2, retained for twelve months or more. - Evidence you get: Logpush job inventory, retention settings, sample log queries. - Status: Mapping under review ### Application and DDoS protection - Control: 4.2.1 (Strong cryptography for card data over public networks); 6.4.2 (Automated protection of public-facing web applications); 6.4.3 (Inventory and authorisation of payment page scripts); 11.6.1 (Detection of unauthorised changes to payment pages) - How we help: Cloudflare WAF is the automated solution in front of your public web applications, TLS is enforced at the edge, and Page Shield keeps an inventory of the scripts on your payment pages and alerts on unauthorised changes. - Evidence you get: WAF configuration and blocked-attack reports, TLS settings, Page Shield script inventory and change alerts. - Status: Mapping under review ### Zero Trust access and data protection - Control: 1.3.1 (Inbound traffic to the card data environment restricted); 7.2.1 (Access granted by role and need to know); 8.4.2 (Multi-factor authentication for access to the card data environment) - How we help: Systems in the card data environment are reachable only through Cloudflare Access, per role and with multi-factor authentication, with no inbound ports open to the internet. - Evidence you get: Access policy export, authentication logs, tunnel configuration. - Status: Mapping under review We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/pci-dss/#assessment --- --- title: "NIS2: controls supported by Noraina" description: "Which NIS2 controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit." url: https://www.noraina.cloud/compliance/nis2/ language: en --- # NIS2: controls supported by Noraina Medium and large companies in sectors such as energy, transport, health, digital infrastructure and manufacturing, and their suppliers. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. ## NIS2 Directive (EU) 2022/2555 EU directive on cybersecurity risk-management measures for essential and important entities. References are points of Article 21(2). 6 controls supported. ### Efficient Cloud Instances with replication - Control: 21.2.c (Business continuity) - How we help: A second site and tested failover are the disaster-recovery part of the measures NIS2 requires. - Evidence you get: Disaster-recovery plan inputs, failover test reports. - Status: Mapping under review ### Efficient Cloud Backup - Control: 21.2.c (Business continuity); 21.2.h (Cryptography and encryption) - How we help: Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware. - Evidence you get: Backup and retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: 21.2.c (Business continuity) - How we help: Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires. - Evidence you get: DNS architecture description, failover configuration, failover event history. - Status: Mapping under review ### Complete edge logging - Control: 21.2.b (Incident handling) - How we help: Complete logs are what make incident detection, analysis and reporting possible. - Evidence you get: Log inventory and the queries used in incident handling. - Status: Mapping under review ### Application and DDoS protection - Control: 21.2.e (Security in acquisition) - How we help: Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed. - Evidence you get: WAF rule history and threat reports. - Status: Mapping under review ### Zero Trust access and data protection - Control: 21.2.i (Access control policies); 21.2.j (Multi-factor authentication and secured communications) - How we help: Access control policies enforced per application, with multi-factor authentication and encrypted connections. - Evidence you get: Access policy export and authentication logs. - Status: Mapping under review We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/nis2/#assessment --- --- title: "DORA: controls supported by Noraina" description: "Which DORA controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit." url: https://www.noraina.cloud/compliance/dora/ language: en --- # DORA: controls supported by Noraina Banks, insurers, investment firms, payment institutions and their critical ICT providers. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. ## DORA Regulation (EU) 2022/2554 EU regulation on digital operational resilience for the financial sector. References are articles of the regulation. 4 controls supported. ### Efficient Cloud Instances with replication - Control: art.11 (Response and recovery); art.12 (Backup) - How we help: A geographically separate recovery site with tested switchover supports your ICT response and recovery plans. - Evidence you get: RPO/RTO statement, switchover test reports, site and provider details for your ICT third-party register. - Status: Mapping under review ### Efficient Cloud Backup - Control: art.12 (Backup) - How we help: Backups held apart from your production systems and protected from change, with documented restoration procedures. - Evidence you get: Backup policy settings, retention configuration, restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: art.11 (Response and recovery) - How we help: Switches traffic to a secondary service automatically and, on the Enterprise plan, keeps critical domains resolvable through the failure of a single DNS provider, supporting the response and recovery arrangements DORA asks for. - Evidence you get: DNS architecture description, failover configuration, failover event history. - Status: Mapping under review ### Complete edge logging - Control: art.10 (Detection) - How we help: Edge logs and security events feed the mechanisms that detect anomalous activity. - Evidence you get: Log inventory, alerting rules, retention settings. - Status: Mapping under review ### Application and DDoS protection - Control: art.9 (Protection and prevention) - How we help: Protection and prevention controls at the edge for your customer-facing services. - Evidence you get: Security configuration export and threat reports. - Status: Mapping under review ### Zero Trust access and data protection - Control: art.9 (Protection and prevention) - How we help: Strong authentication and least-privilege access to ICT systems. - Evidence you get: Access policy export and access logs. - Status: Mapping under review We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/dora/#assessment --- --- title: "GDPR: controls supported by Noraina" description: "Which GDPR controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit." url: https://www.noraina.cloud/compliance/gdpr/ language: en --- # GDPR: controls supported by Noraina Any organisation processing personal data of people in the EU. > Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier. ## GDPR (EU) 2016/679 EU regulation on the protection of personal data. References are articles of the regulation. 4 controls supported. ### Efficient Cloud Instances with replication - Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability) - How we help: Keeps systems that process personal data available and restorable after an incident in the primary site. - Evidence you get: Recovery test reports for your Article 32 documentation. - Status: Mapping under review ### Efficient Cloud Backup - Control: 32.1.a (Pseudonymisation and encryption); 32.1.c (Timely restoration of availability) - How we help: Encrypted backups that let you restore access to personal data in a timely manner. - Evidence you get: Encryption and restore test records. - Status: Mapping under review ### Efficient Cloud DNS (NorainaDNS) - Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability) - How we help: Automatic failover, and on the Enterprise plan a second authoritative DNS network, help keep services that process personal data available, and restore access quickly when a primary service fails. - Evidence you get: NS delegation showing both networks (Enterprise), failover configuration and event history. - Status: Mapping under review ### Complete edge logging - Control: art.33 (Breach notification) - How we help: Lets you establish what happened, and to which data, within the 72-hour notification window. - Evidence you get: Log retention configuration, investigation runbook. - Status: Mapping under review ### Application and DDoS protection - Control: 32.1.b (Confidentiality) - How we help: Keeps applications that process personal data available and protected against attack. - Evidence you get: Threat reports for your Article 32 documentation. - Status: Mapping under review ### Zero Trust access and data protection - Control: 32.1.b (Confidentiality) - How we help: Only authorised people reach personal data, and DLP blocks it from leaving through unapproved channels. - Evidence you get: Access policy export, DLP incident reports. - Status: Mapping under review We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/gdpr/#assessment --- --- title: "About Noraina" description: "Irish infrastructure and security company: own platform in five European data centres, Cloudflare partner since 2020, ISO 27001 certified since 2021." url: https://www.noraina.cloud/about/ language: en --- # About Noraina Noraina is a European infrastructure and security provider. We run your workloads on our own platform in five data centres in London, Dublin, Paris and Barcelona, with replication between any of them, immutable backups and DNS failover, protect your applications and staff with Cloudflare as an Authorized Service Delivery Partner, and produce the audit evidence for ISO 27001, ENS, PCI DSS, NIS2 and DORA. ## Credentials - ISO/IEC 27001 certified operations - Cloudflare partner since 2020, now an Authorized Service Delivery Partner (Powered+) in EMEA - AWS, Microsoft, Google Cloud, Wasabi and Bunny.net partner - Available on AWS Marketplace and Azure Marketplace - Member of the INEX (Dublin), LINX (London) and France-IX (Paris) internet exchanges - Genians partner for OT network security ## Offices - Registered office: Unit 3D North Point House, North Point Business Park, Cork T23 AT2P, IE ## Certificates and policies Our ISO/IEC 27001 certificate, our CSA STAR Registry listing and the policies and contract terms that apply to our services. We update these documents when they change; check this page for the current version. - [ISO/IEC 27001:2022 certificate](https://www.noraina.cloud/documents/noraina-iso-27001-certificate.pdf): Certificate ES20240003, issued by Iscertia Evaluación & Certificación. Certified since 23 February 2021; the current certificate is valid until 22 February 2027. - [CSA STAR Registry listing](https://cloudsecurityalliance.org/star/registry/noraina-cloud): STAR Level 1: our Consensus Assessments Initiative Questionnaire (CAIQ), published in the Cloud Security Alliance registry. - [Privacy policy](https://www.noraina.cloud/documents/noraina-privacy-policy.md): What personal data Noraina collects, why, who processes it (Cloudflare, HubSpot, Google Workspace, Xero, Stripe, GoCardless), how long it is kept and your GDPR rights. ([PDF](https://www.noraina.cloud/documents/noraina-privacy-policy.pdf)) - [Cookies policy](https://www.noraina.cloud/documents/noraina-cookies-policy.md): The website uses no analytics or advertising cookies; only strictly necessary Cloudflare security cookies. ([PDF](https://www.noraina.cloud/documents/noraina-cookies-policy.pdf)) - [Terms](https://www.noraina.cloud/documents/noraina-terms.md): Terms and conditions for using the Noraina website. ([PDF](https://www.noraina.cloud/documents/noraina-terms.pdf)) - [Standard services supply agreement](https://www.noraina.cloud/documents/noraina-standard-services-supply-agreement.md): Our standard contract for services: proposal, service level table with availability penalties, and terms and conditions under Irish law. ([PDF](https://www.noraina.cloud/documents/noraina-standard-services-supply-agreement.pdf)) --- --- title: "Contact" description: "Talk to Noraina about infrastructure, Cloudflare security or the certification you are preparing. We reply within one working day." url: https://www.noraina.cloud/contact/ language: en --- # Contact Talk to Noraina about infrastructure, Cloudflare security or the certification you are preparing. We reply within one working day. - Email: info@norainacloud.com - Phone: +353 21 204 0104 - Registered office: Unit 3D North Point House, North Point Business Park, Cork T23 AT2P, IE --- --- title: "Privacy policy" description: "How Noraina Ltd collects, uses and protects personal data." url: https://www.noraina.cloud/documents/noraina-privacy-policy.md pdf: https://www.noraina.cloud/documents/noraina-privacy-policy.pdf language: en --- # Privacy policy Last updated 7 October 2026 This policy explains what personal data Noraina Ltd collects through www.noraina.cloud, our client area and our dealings with customers and prospective customers, why we use it, who we share it with and the rights you have under the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. ## 1. Who we are The controller of your personal data is Noraina Ltd, a private company limited by shares incorporated in Ireland under registration number 614532, with its registered office at Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23 AT2P, Ireland. For any question about this policy or your personal data, email [info@norainacloud.com](mailto:info@norainacloud.com). ## 2. Scope This policy covers personal data we decide how to use: visitors to our website, people who contact us or request an assessment, contacts at our customers, suppliers and partners, and users of our client area at dash.noraina.cloud. It does not cover data our customers store or process on our platform and services. For that data the customer is the controller and we act as its processor, under the terms of our services agreement and any data processing agreement signed with the customer. ## 3. What we collect and why | Data | Purpose | Legal basis (GDPR article 6) | | --- | --- | --- | | Contact and assessment forms: name, work email, company, your message and, for assessments, the framework, certification stage and target date you choose; the page you sent the form from | Replying to your request, preparing a proposal and following up on it | Steps taken at your request before entering into a contract (6(1)(b)) and our legitimate interest in answering business enquiries (6(1)(f)) | | Customer account and billing: names, business email and phone of customer contacts, company name, billing address, VAT number, order and invoice history | Providing the services you contract, support, invoicing and keeping accounting records | Performance of a contract (6(1)(b)) and legal obligations such as tax law (6(1)(c)) | | Payment details | Taking payment for our services. Card and direct debit details are entered directly with Stripe and GoCardless; Noraina never sees or stores your card number | Performance of a contract (6(1)(b)) | | Technical data: IP address, browser and device information, pages requested, date and time; signals collected by Cloudflare Turnstile when you submit a form | Delivering the website, protecting it and its forms against abuse and attacks, and investigating incidents | Our legitimate interest in running a secure website (6(1)(f)) | | Name, business email and company | Sending occasional emails about our products, services and events | Your consent, or for existing customers our legitimate interest under the soft opt-in of S.I. No. 336 of 2011. You can unsubscribe at any time | We only collect personal data you give us or that is generated when you use our website and services. We do not buy personal data and we do not use it for automated decision-making or profiling with legal or similarly significant effects. ## 4. Who we share it with We share personal data only with service providers that process it on our behalf and under our instructions, bound by a data processing agreement: - **Cloudflare, Inc.** hosts and delivers this website, protects it against attacks and provides Turnstile, the check that keeps automated spam out of our forms. - **HubSpot, Inc.** is our customer relationship management system. Messages sent through our forms are stored there. - **Google** (Google Workspace) provides our email, calendar and documents. - **Xero** is our accounting system, where invoices and customer billing details are kept. - **Stripe** and **GoCardless** process card payments and direct debits. For their own legal obligations, such as fraud prevention and anti-money-laundering checks, they act as independent controllers under their own privacy notices. Our client area at dash.noraina.cloud is operated by us. We may also disclose personal data to professional advisers such as auditors and lawyers, to public authorities when the law requires it, and to a buyer or successor in the event of a merger, acquisition or sale of all or part of our business, who will be bound by this policy. We do not sell personal data. ## 5. Transfers outside the European Economic Area Our HubSpot account stores its data in HubSpot's data centre in the European Union. Some of our providers, including Cloudflare, Google and HubSpot, are part of groups based in the United States and may access or process personal data outside the European Economic Area. Where they do, the transfer relies on the EU–U.S. Data Privacy Framework, under which these providers are certified, on an adequacy decision of the European Commission, or on the Commission's Standard Contractual Clauses included in their data processing agreements. ## 6. How long we keep it - Enquiries that do not lead to a contract: 24 months after our last contact with you. - Customer account data and contract records: for as long as the contract is in force and six years after it ends, the period in which contractual claims can be brought under Irish law. - Invoices and accounting records: six years from the end of the financial year they relate to, as Irish tax law requires. - Website and security logs: one month. - Marketing: until you unsubscribe or object. ## 7. Security We protect personal data with technical and organisational measures that are part of our information security management system, certified to ISO/IEC 27001:2022. Access is limited to employees, agents and providers who need it for the purposes above. No transmission over the internet is completely secure, so please keep your client area password private. ## 8. Your rights You have the right to: - access the personal data we hold about you and receive a copy; - have inaccurate data corrected and incomplete data completed; - have your data erased when there is no longer a reason for us to keep it; - restrict how we use it while a question about it is resolved; - receive data you gave us in a machine-readable format (portability); - object to processing based on our legitimate interests, and to direct marketing at any time; - withdraw your consent at any time, without affecting processing that took place before. To exercise any of these rights, email [info@norainacloud.com](mailto:info@norainacloud.com). We will answer within one month and may ask you to confirm your identity first. If you are not satisfied with our answer, you can complain to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland ([www.dataprotection.ie](https://www.dataprotection.ie/)), or to the supervisory authority of the EU country where you live or work. ## 9. Cookies Our website uses no analytics or advertising cookies and loads no third-party analytics or advertising scripts. The only third-party script is Cloudflare Turnstile, which runs on pages with a form. Our [cookies policy](https://www.noraina.cloud/documents/noraina-cookies-policy.pdf) lists the strictly necessary security cookies Cloudflare may set. ## 10. Children Our services are for businesses. We do not knowingly collect personal data from children. ## 11. Changes to this policy We publish any change to this policy on our website, with a new date at the top. If we plan to use personal data in a way that is significantly different from what this policy describes, we will tell you by email before we do so. ## 12. Contact Noraina Ltd, Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23 AT2P, Ireland. Email [info@norainacloud.com](mailto:info@norainacloud.com), phone +353 21 204 0104. --- --- title: "Cookies policy" description: "Which cookies www.noraina.cloud uses and how to manage them." url: https://www.noraina.cloud/documents/noraina-cookies-policy.md pdf: https://www.noraina.cloud/documents/noraina-cookies-policy.pdf language: en --- # Cookies policy Last updated 7 October 2026 www.noraina.cloud does not use analytics, advertising or tracking cookies, and Noraina does not set any cookies of its own. The only cookies you may receive are strictly necessary security cookies set by Cloudflare, which delivers and protects the website. ## 1. What is a cookie? A cookie is a small text file that a website stores in your browser and reads on later requests. Cookies can remember a choice, keep a session open, or track visits across websites. Similar technologies, such as browser storage and tracking pixels, are covered by this policy in the same way. ## 2. Cookies on our website We do not use Google Analytics, advertising networks, social media pixels or any other analytics or marketing tool, so no cookie or similar technology is used to measure your visit, profile you or show you advertising. Cloudflare may set the following cookies when its security features are triggered, for example when traffic looks automated or a request has to be checked: | Cookie | Set by | Purpose | | --- | --- | --- | | __cf_bm | Cloudflare | Tells people from bots, so that automated traffic can be blocked. | | cf_clearance | Cloudflare | Records that your browser has passed a security check, so you are not asked again on every page. | | _cfuvid | Cloudflare | Applies rate limits fairly to visitors who share an IP address. | Pages with a contact or assessment form also load Cloudflare Turnstile, which checks that the form is sent by a person and not by a bot. Turnstile collects technical signals from your browser for that check only, and does not read what you write in the form. It is described in Cloudflare's Turnstile privacy addendum at [www.cloudflare.com/turnstile-privacy-policy](https://www.cloudflare.com/turnstile-privacy-policy/). How long each cookie lasts is set by Cloudflare and described in its documentation. These cookies and checks are strictly necessary to keep the website secure, so the law does not require your consent for them and we do not show a cookie banner. They do not identify you to Noraina. ## 3. Our client area The client area at dash.noraina.cloud uses cookies to keep you signed in, remember your preferences and protect your account. They are strictly necessary for the service you request and are not used for analytics or advertising. ## 4. How to manage cookies You can block or delete cookies in your browser settings. If you block the Cloudflare security cookies, you may be asked to complete a security check more often, and some requests may be blocked. For more information about managing cookies, visit [www.aboutcookies.org](https://www.aboutcookies.org/). ## 5. Changes and contact If we start using other cookies, for example for analytics, we will update this policy first and, where the law requires it, ask for your consent before setting them. Our [privacy policy](https://www.noraina.cloud/documents/noraina-privacy-policy.pdf) explains how we handle personal data. For questions, email [info@norainacloud.com](mailto:info@norainacloud.com). --- --- title: "Terms" description: "Terms and conditions for using the Noraina website." url: https://www.noraina.cloud/documents/noraina-terms.md pdf: https://www.noraina.cloud/documents/noraina-terms.pdf language: en --- # Terms Terms and conditions for using the Noraina website ## 1. Terms and conditions Noraina provides the website to you on the basis of the following terms and conditions ("Terms and Conditions"). By accessing any page on this Website, you agree to be bound by these Terms and Conditions. These Terms and Conditions may be updated by Noraina from time to time by posting the updated Terms and Conditions without prior separate notification to you. You should check the Terms and Conditions each time you access the Noraina website to check for updates. ## 2. Noraina Website You will be able to obtain information about certain Noraina products and services on this Noraina Website and you may also submit queries to Noraina to receive more information. ## 3. Use The Noraina Website and any support are provided to you at no charge and are for your personal and non-commercial use. Any support provided to you is for information purposes only. Noraina reserves the right to make changes to the Noraina Website; or not reply to any queries; or not provide any support in connection with the Noraina Website. Noraina does not wish to receive confidential or proprietary information from you via the Noraina Website. Subject to Noraina’s obligation under the Privacy Policy please note that any information or material sent to Noraina via the Noraina website will be deemed to be not confidential. By sending Noraina any information or material, you grant Noraina an unrestricted, irrevocable licence to use, reproduce, display, perform, modify, transmit and distribute that material or information, and you also agree that Noraina is free to use any ideas, concepts, know-how or techniques that you send us for any purpose. You undertake not to post to or send via this website any materials that are or could reasonably be construed as: (i) defamatory, libellous, obscene, offensive, abusive, liable to incite racial hatred, discriminatory or blasphemous; (ii) in breach of any obligation of confidence or privacy or any trade secret; (iii) infringing the proprietary rights of any third party or for which you have not obtained all necessary licences and/or approvals; or (iv) violating any other law. You also agree not to transmit to or send via the website any materials which could reasonably be held to constitute or encourage conduct that would be considered a criminal offence, give rise to civil liability, or otherwise be contrary to the law of any country or other competent authority, or infringe the rights of any third party enforceable in any part of the world. Noraina reserves the right to remove any materials from the website where it reasonably suspects that such material is prohibited by this Section 3 or is otherwise inappropriate. Notwithstanding the foregoing, you acknowledge that Noraina has no control over content on the website provided by other users, neither does it purport to monitor the content of the website to ensure its accuracy, appropriateness or conformity with the principles outlined in these Terms and Conditions. You must not link to the Noraina Website other websites which are indecent or inappropriate, and you must forthwith remove any link if Noraina in its discretion so requests. You agree to indemnify Noraina and Noraina’s affiliates against any claim, demand, loss or damage suffered as a result of breach of this. ## 4. Disclaimer Noraina hereby excludes all conditions, warranties, representations or other terms concerning the supply or purported supply of, failure to supply or delay in supplying any service in connection with the Noraina Website or that the Noraina Website is accurate, complete or up-to-date, which might but for this Section 4 have effect between Noraina and you, or would otherwise be implied into or incorporated into these Terms and Conditions or any collateral contract, whether by statute, common law or otherwise. You understand and agree that you are using the Noraina Website at your sole risk and that Noraina does not warrant that the Noraina Website will meet your requirements or that the Noraina Website will be uninterrupted, error free or secure. Any content or services provided via the Noraina Website or in connection with the Noraina Website by Noraina is done so on an "AS IS" and on an "AS AVAILABLE" basis and Noraina makes no representations or endorsement of any kind, whether express or implied, with respect to the Noraina Website for the content or services included in, or made available in connection with, this Noraina Website. Noraina reserves the right at its sole discretion, to amend or withdraw any content or services offered as part of the Noraina Website. ## 5. Liability Noraina, any other party (whether or not involved in creating, producing, maintaining or delivering this Noraina Website), and any of Noraina group companies and the officers, directors, employees, shareholders or agents of any of them, exclude all liability and responsibility for any amount or kind of loss or damage that may result to you or a third party, (including without limitation, any direct, indirect, punitive or consequential loss or damages, or any loss of income, profits, goodwill, data, contracts, use of money, or loss or damages arising from or connected in any way to business interruption, and whether in tort (including without limitation negligence), contract or otherwise in connection with this Noraina Website in any way or in connection with the use, inability to use or the results of use of this Noraina Website, any websites linked to this Noraina Website or the material on such websites, including but not limited to loss or damage due to viruses that may infect your computer equipment, software, data or other property on account of your access to, use of, or browsing this Noraina Website or your downloading of any material from this Noraina Website or any websites linked to this Noraina Website. This shall not affect your statutory rights. Nothing in these Terms and Conditions shall exclude or limit Noraina’s liability for (i) death or personal injury caused by its negligence; (ii) fraud; or (iii) any liability which cannot be excluded or limited under applicable law. --- --- title: "Noraina Limited agreement for services" description: "Noraina Limited agreement for services: proposal, service level table and terms and conditions." url: https://www.noraina.cloud/documents/noraina-standard-services-supply-agreement.md pdf: https://www.noraina.cloud/documents/noraina-standard-services-supply-agreement.pdf language: en --- # Noraina Limited agreement for services Standard services supply agreement ## Proposal | | | | --- | --- | | Supplier | Noraina Limited, a private company limited by shares incorporated in Ireland under registration number 614532 having its registered office at Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, Ireland | | Customer | __________ | | Effective Date | __________ | | Term | __________ months / years From the Effective Date until terminated in accordance with this Agreement | | Services | The services provided by the Supplier to the Customer as set out in Schedule 1 | | Charges | The charges for the Services are invoiced monthly or upfront depending on the service | By signing the Agreement, the parties agree to the terms and conditions herein: **Supplier** For and on behalf of Noraina Limited Date: __________ **Customer** For and on behalf of __________ Date: __________ ## Service level table | Availability | Penalty | | --- | --- | | 100% – 99.97% | 0% monthly usage | | 99.96% – 99.91% | 5% monthly usage | | 99.9% – 99.6% | 10% monthly usage | | 99.5% – 99% | 25% monthly usage | | < 99% | 50% monthly usage | ## Terms and conditions ### 1. Definitions and interpretation **1.1** In these Terms and Conditions the following terms and expressions shall, unless the context otherwise requires, have the following meanings: | | | | --- | --- | | Agreement | the Proposal, the Service Level Table and these Terms and Conditions (including Schedule 1); | | Deliverables | all data, documents, products and materials developed by the Supplier or its agents and personnel as part of or in relation to the Services in any form, including without limitation computer programs, code, reports and specifications (including drafts); | | Efficient Cloud Egress | the use of optimized network connections to major cloud service providers; | | Intellectual Property Rights | patents, utility models, rights to inventions, copyright and neighbouring and related rights, moral rights, trademarks and service marks, business names and domain names, rights in get-up and trade dress, goodwill and the right to sue for passing off or unfair competition, rights in designs, rights in computer software, database rights, rights to use, and protect the confidentiality of, confidential information (including know-how and trade secrets) and all other intellectual property rights, in each case whether registered or unregistered and including all applications and rights to apply for and be granted, renewals or extensions of, and rights to claim priority from, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future in any part of the world; and | | Supplier IPRs | all Intellectual Property Rights subsisting in the Supplier, the Deliverables (until all Charges in respect of the deliverables are paid and title passes to Customer) or otherwise necessary or desirable to enable the Customer to receive and use the Services. | | Customer Data | All and any data or information, in whatever form including in writing, images, still and moving, and sound recordings held by the Supplier on behalf of the Customer in providing the Services. | ### 2. Supply of services **2.1** The Supplier shall supply the Services to the Customer in accordance with this Agreement. **2.2** The Supplier shall: a) ensure that it obtains, and maintains all consents, licences and permissions (statutory, regulatory, contractual or otherwise) it may require, and which are necessary to enable it to comply with its obligations in this Agreement; and b) ensure that the Deliverables, and all goods, materials, standards and techniques used in providing the Services are of the best quality and are free from defects in workmanship, installation and design. **2.3** The Customer shall: a) ensure that it obtains, and maintains all consents, licences and permissions (statutory, regulatory, contractual, or otherwise) it may require, and which are necessary to enable the Supplier to comply with its obligations in this Agreement; and b) provide to the Supplier in a timely manner all documents, information, items, and materials in any form (whether owned by the Customer or a third party) required by the Supplier in connection with the Services and ensure that they are accurate and complete in all material respects. ### 3. Title to deliverables Title to any (i) Deliverables that are goods; and (ii) goods or materials transferred to the Customer as part of the Services, shall pass to the Customer on payment of the relevant Charges, free from all liens, charges, and encumbrances. ### 4. Intellectual property **4.1** The Supplier shall retain ownership of all Supplier Intellectual Property Rights. **4.2** The Supplier may sub-license the rights granted hereunder to any of the Supplier’s affiliated companies and/or its customers. ### 5. Charges and payment **5.1** The Charges are set out in Schedule 1. The Charges may be revised by the Supplier from time to time. The Supplier will provide written notice of any revision to the Charges to the Customer, to the effect that any change shall come into force on the expiry of the period specified in the notice. **5.2** In consideration for the provision of the Services, the Customer shall pay the Supplier the Charges in the manner set out hereunder: **5.2.1** an initial €1.00 (or equivalent amount in other currencies) shall be paid by the Customer by credit card or debit card on or prior to the entry of this Agreement; **5.2.2** the Charges shall be paid by the Customer by credit card or debit card; **5.2.3** an additional amount, at the sole discretion of the Supplier, may be granted to the Customer, without the need of any payment by the Customer, to increase the Customer’s balance with the Supplier; **5.2.4** the Supplier shall deduct from the Customer’s balance the charges payable for Services provided; **5.2.5** on the reduction of the Customer’s balance to nil or a predefined threshold, an invoice shall be issued to the Customer which on payment will be credited to the Customer’s balance. **5.3** All amounts payable by the Customer exclude amounts in respect of value-added tax (VAT) which the Customer shall additionally be liable to pay to the Supplier at the prevailing rate (if applicable), subject to receipt of a valid VAT invoice. **5.4** The Supplier may, at its sole discretion, continue to provide Services to the Customer following the reduction of the Customer’s balance to nil, without prejudice to the Supplier’s right to stop the provision of the Services until such time as the Customer’s balance is put back on credit. ### 6. Liability **6.1** This Agreement sets out the full extent of Supplier’s obligations and liabilities in respect of the supply of the Service. In particular, there are no conditions, warranties, representations, or other terms, express or implied, that are binding on the Supplier except as specifically stated in this Agreement. Any condition, warranty, representation, or other terms concerning the supply of the Services by the Supplier which might otherwise be implied into, or incorporated in, this Agreement or any collateral contract, whether by statute, common law, or otherwise, is hereby excluded to the fullest extent permitted by law. **6.2** Subject to the conditions contained herein, the Supplier shall not be liable under or in connection with this Agreement for: (a) loss of income; (b) loss of business profits or contracts; (c) business interruption; (d) loss of the use of money or anticipated savings; (e) loss of information; (f) loss of opportunity, goodwill or reputation; (g) loss of, damage to or corruption of data; or (h) any indirect or consequential loss or damage of any kind howsoever arising and whether caused by tort (including negligence), breach of contract or otherwise. **6.3** The Supplier’s maximum aggregate liability under or in connection with this Agreement, or any collateral contract, whether in contract, tort (including negligence), or otherwise (including any liability for the acts or omissions of its employees or agents), shall be limited to a sum equal to the total Charges paid to the Supplier since the date of this Agreement or the last 6 month period prior to a liability claim, whichever is the lesser. **6.4** The Customer acknowledges and agrees that the Supplier shall have no liability whatsoever for damages or losses caused by any third-party products incorporated within the Services. **6.5** The service levels as set out in the Service Level Table shall apply to the provision of the Services, save when the Services are unavailable due to a non-redundant deployment. ### 7. Termination **7.1** Without affecting any other right or remedy available to it, either party may terminate this Agreement with immediate effect by giving written notice to the other party if: a) the other party commits a material breach of any term of this Agreement which breach is irremediable or (if such breach is remediable) fails to remedy that breach within a period of 30 days after being notified in writing to do so; b) the other party takes any step or action in connection with its entering administration, provisional liquidation or any composition or arrangement with its creditors (other than in relation to a solvent restructuring), being wound up (whether voluntarily or by order of the court, unless for the purpose of a solvent restructuring), having a receiver appointed to any of its assets or ceasing to carry on business; or c) the other party suspends, or threatens to suspend, or ceases or threatens to cease to carry on all or a substantial part of its business. **7.2** Either party may terminate this Agreement by giving the other party not less than 90 days’ notice in writing of its intention to do so. **7.3** Termination of this Agreement shall not affect any of the parties rights and remedies that have accrued as at termination, including the right to claim damages in respect of any breach of this Agreement that existed at or before the date of termination. **7.4** Any provision of this Agreement that expressly or by implication is intended to come into or continue in force on or after termination shall remain in full force and effect. ### 8. Security, privacy, and data retention **8.1** **Security.** The Supplier will maintain appropriate technical and organisational measures, internal controls, and data security routines intended to protect Customer Data against accidental loss or change, unauthorised disclosure or access, or unlawful destruction. Current information about the Supplier’s security practices will be provided on request. The Customer is wholly responsible for configuring its solution to ensure adequate security, protection, and backup of its data. **8.2** **Customer Data Location.** The Supplier or its affiliates or subcontractors will never transfer, store, or process Customer Data away from the designated Noraina Cloud region without Customer explicit consent. The Customer will obtain all necessary consents from its end users or any other party whose personal information or other data will be stored as part of the Services. **8.3** **Ownership of Customer Data.** Customer retains all rights, title, and interest in and to Customer Data. Supplier acquires no rights in Customer Data, other than the right to host Customer Data within the Services, including the right to use and reproduce Customer Data solely as necessary to provide the Services. **8.4** **Use of Customer Data.** The Supplier will use Customer Data only to provide the Services. This use may include troubleshooting to prevent, find, and fix problems with the operation of the Services. It may also include improving features for finding and protecting against threats to users. The Supplier will not use Customer Data or derive information from it for any advertising or other commercial purposes without Customer explicit consent. **8.5** **Third-party requests.** The Supplier will not disclose Customer Data to a third party (including law enforcement, other government entity, or civil litigant; excluding our subcontractors) except as Customer directs or unless required by law. Should a third party contact us with a demand for Customer Data, the Supplier will attempt to redirect the third party to request that data directly from the Customer. As part of this effort, the Supplier may provide the Customer’s basic contact information to the third party. If compelled to disclose Customer Data to a third party, Supplier will promptly notify Customer and provide a copy of the demand, unless legally prohibited from doing so. **8.6** **Subcontractors.** Supplier may hire other companies to provide services on Supplier’s behalf. Any such subcontractors will be permitted to obtain Customer Data only to deliver the services Supplier has retained them to provide. ### 9. General **9.1** **Force majeure.** Neither party shall be in breach of this Agreement nor liable for delay in performing, or failure to perform, any of its obligations under this Agreement if such delay or failure result from events, circumstances, or causes beyond its reasonable control including but not limited to natural disaster, pandemic, epidemic, sanctions, labour disputes. If the period of delay or non-performance continues for 4 weeks, the party not affected may terminate this Agreement by giving 15 days’ written notice to the affected party. **9.2** **Entire agreement.** This Agreement constitutes the entire agreement between the parties and supersedes and extinguishes all previous agreements, promises, assurances, warranties, representations, and understandings between them, whether written or oral, relating to its subject matter. **9.3** **Counterparts.** This Agreement may be entered into in any number of counterparts and by the Parties to it on separate counterparts, each of which when so executed and delivered shall be an original, but all the counterparts shall together constitute the one and the same agreement. **9.4** **Amendments.** Save for in respect of clause 5.1, no amendment, variation, or modification to this Agreement shall be made except in writing signed by all parties. **9.5** **Governing Law and Jurisdiction.** This Agreement and any dispute, issues, or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of Ireland. Each of the Parties to this Agreement hereby submits to the exclusive jurisdiction of the Irish Courts for any of the purposes of this Agreement including any claim whether contractual or non-contractual arising hereunder. ## Schedule 1 Services and charges | Service | Charges | | --- | --- | | | | | | | | | |