CloudNorma
Cloud compliance made simple — and hosted in Canada. CloudNorma scans your Azure, AWS and GCP environments against the official CIS Benchmarks, Quebec's Law 25 and ISO 27001, links every gap back to its source recommendation and walks you through the fix.
The problem
A Quebec organisation hosting personal information in the cloud has to be able to prove it. Not merely assert it: demonstrate it, control by control, to an auditor or to a client who requires it in a tender.
In practice, that demonstration is assembled by hand. Azure portal screenshots, configuration exports, a spreadsheet trying to map each regulatory requirement to a technical setting. The work is redone at every audit, and goes stale the moment a resource changes.
What CloudNorma does
CloudNorma connects to your subscriptions in read-only mode, analyses your resources against the official frameworks, and produces a real-time compliance score — overall and per provider.
Every gap carries its source reference: not “your storage is misconfigured”, but “CIS Azure v6.0.0, recommendation 9.3.2.2”. Your auditor verifies at a glance, without reconstructing your reasoning.
Three remediation paths are offered for every gap: a ready-to-apply Terraform block, an Azure Policy definition, or step-by-step instructions in the portal. You pick according to your automation maturity.
Frameworks covered
| Framework | Scope |
|---|---|
| CIS Benchmarks | Azure v6, AWS v7, GCP v5 — 2026 editions |
| Law 25 | Protection of personal information, Quebec |
| ISO 27001 | Information security management system |
| GDPR | Personal data processing, Europe |
| HIPAA | Health data — Growth plans and above |
Working as a team
Single sign-on with Microsoft or Google, Admin, Analyst and Viewer roles, and assignment of each gap to an owner. Compliance stops being one person's file.
Three steps from sign-up to your first score
Create your workspace
A 30-day free trial, no credit card. Your organisation is ready in a minute.
Connect your cloud
A Quick Start script creates read-only access to your Azure, AWS or GCP environment. No expertise required.
Scan and fix
Real-time score, gaps linked to the official recommendations, and guided remediation all the way to compliance.
Let's talk about your cloud trajectory
Compliance audit, target architecture, governance automation, or simply picking the right solution — write to us and we'll reply within 48 hours.