Trust
Security your review board can sign.
How we vet the people we send you, how we handle your data while we are inside your systems, and what we commit to when we build AI in a regulated environment.
Last updated September 4, 2026
Most AI programs stall at the security review, not at the model. This page sets out how Norton vets the people we send you, how we handle your data while we are inside your systems, and what we commit to when we build AI in a regulated environment — so your security, privacy and risk teams can start the conversation with facts instead of a questionnaire.
Vetted before you meet them
Fewer than four percent of applicants pass the four-step Production Gate. Everyone you interview has already been through it.
Inside your controls
Our engineers work in your environment, on your accounts, under your policies, with the least access that lets them do the job.
Your data stays yours
We do not use client data to train models, and we do not move it out of your environment without written instruction.
The people we send you
Norton is a staffing and consulting firm before it is anything else, so the first control is who walks through your door.
- The Production Gate. Four steps: a ground-truth review of a system the engineer actually shipped, checked against references; an applied build against a messy dataset scored with our eval set; a test for cost and safety thinking; and a working session with a Norton lead from your industry. Fewer than four percent get through. It is described in full on our homepage.
- Identity and background. We confirm identity and right to work, and we run background screening appropriate to the role and the client's requirements before deployment. Where your industry demands a specific level of screening — financial services, healthcare, public sector — tell us during scoping and we will meet it or tell you we cannot.
- Confidentiality. Every Norton engineer signs confidentiality and intellectual-property terms with us before an engagement starts, and signs whatever additional agreements you require on top.
- Employment. Our engineers are US-based and work in US time zones, most as W-2 employees. You are told the employment basis of anyone we propose.
- Replacement. Every placement carries a written twenty-one-day review against the plan we agreed at the start. If it is not working, we replace the engineer at no cost.
Your data on an engagement
The default is simple: your data stays in your environment, and our engineers come to it.
- Your systems, your accounts. Engineers work on client-issued accounts and, where you require it, client-issued devices, inside your network, identity and logging controls. Access is scoped to what the work needs and revoked when it ends.
- No extraction by default. We do not copy client data to Norton systems, personal accounts or personal devices. Where an engagement genuinely requires data to leave your environment, it happens only on your written instruction, through a channel you approve, and under the terms of our agreement.
- Least privilege on production. Access to production data and production systems is requested explicitly, granted by you, time-bound where possible, and logged on your side where your tooling records it.
- Your policies apply. On your engagement, your acceptable-use, data-classification, change-management and incident-response policies govern our engineers' work. Where our practice is stricter, we keep ours as well.
- Subcontracting. We do not subcontract engagement work to third parties or offshore delivery centers without your written consent.
- At the end. When an engagement closes we return or destroy client material in our possession, confirm access has been revoked, and hand over documentation, evaluation sets and runbooks so your team can carry the system forward.
How we build AI responsibly
AI systems fail in ways traditional software does not. These are the practices our delivery pods bring by default, not extras you have to ask for.
- Your data does not train anyone's model. We do not use client data, prompts or outputs to train or fine-tune models for Norton's benefit or anyone else's, and we configure the AI services we use on your behalf so the provider does not train on your data either. Any exception is yours to grant, in writing, for a named purpose.
- Model and vendor choice is yours. We work with the model providers and the deployment pattern your risk posture allows, including in-tenant and private deployments, and we document the data flows for each one so your review has something concrete to look at.
- Quality defined before the first prompt. Every use case gets an evaluation set and a written definition of acceptable quality before build starts, and the evals run in CI so regressions surface before users find them.
- Security built for LLM systems. Our AI Security Engineers threat-model prompt injection, tool and agent permissions, retrieval poisoning, data leakage through outputs, and model supply-chain risk. We use the OWASP Top 10 for LLM applications as a floor.
- Guardrails and a human in the loop. Consequential actions run behind approval, tool access is scoped, and outputs are constrained and monitored. We do not ship agents with unbounded permissions.
- Traceability. Prompts, models, retrieval sources and configuration are versioned, and inference is logged so an answer can be explained after the fact — the record your auditors, your regulator and your incident review will ask for.
- Governance that survives contact with legal. Our AI Governance Advisors maintain the model inventory, impact assessments and documentation in a form a regulator or auditor recognizes, mapped to the framework you use, such as the NIST AI Risk Management Framework or ISO/IEC 42001.
- Cost and dependency in the open. Cost at scale, latency and vendor lock-in are estimated before build, not discovered in month four.
Our own systems
- Company accounts require multi-factor authentication, and access to candidate and client records is limited to the Norton people whose work requires it.
- This website is static, served over TLS by a managed hosting platform. It sets no cookies and runs no analytics or advertising trackers — see our Privacy policy.
- Messages and résumés submitted through the site are delivered into monitored company mailboxes and stored in our candidate records. We ask you not to send sensitive personal information through the forms.
- Norton people are trained on confidentiality, phishing and client-data handling, and we review access when someone changes role or leaves.
Security reviews and questionnaires
We expect to be reviewed, and we would rather do it early than a week before the start date. Send us your vendor security questionnaire, your standard assessment format — CAIQ, SIG or your own — your data processing terms or your AI supplier addendum, and we will complete them, tell you plainly what we do and do not have in place, and put your team on a call with the Norton lead who will actually be accountable for the engagement.
Certifications, attestations and insurance evidence relevant to a specific engagement are shared on request during procurement. If your requirements go beyond what we hold today, we will say so rather than paper over it, and propose how the engagement can meet the requirement inside your own certified environment.
Bring your security, privacy and procurement people to the scoping call. It is the cheapest hour in the whole engagement.
Incidents and vulnerability reporting
If a Norton engineer becomes aware of a security or privacy incident affecting your data, we escalate it to your named contact without delay and follow your incident-response process, alongside our own obligations under our agreement with you.
If you believe you have found a vulnerability in this website or in something Norton operates, email hello@nortondigitalconsulting.com with enough detail to reproduce it. Please give us a reasonable chance to fix it before disclosing it publicly, and do not access, modify or delete data that is not yours while testing. We will acknowledge your report, keep you posted, and credit you if you would like us to. We will not pursue good-faith research that follows these rules.
Talk to us
Norton Digital Consulting
100 Chesterfield Business Parkway, Suite 209, Chesterfield, MO 63005
Security, privacy and vendor reviews: hello@nortondigitalconsulting.com
314-456-7856