Background visualisation: separate systems (ERP, CRM, HR, finance, planning, e-mail) being connected into one flow through the Novaro core.
Data layer · AI agents · Compliance
One layer above your systems.Everything provable.
One measure counts for every standard · enter once, continuous insight.
The connecting layer above your systems, the AI agents working on top of it, and compliance as the first product. Built and hosted in Europe.
Your data is locked inside systems that don't know each other.
Every package keeps its own version of the truth. Anyone who wants the whole picture retypes it.
Every new system solves something and makes the rest more complicated.
And at the first critical question (audit, tender, regulator) nobody can show where a figure came from.
That is not a people problem, and not a software problem either. A layer is missing.
This is what that layer looks like →An ecosystem of three layers.
The bottom layer is the core: without connected data the rest does nothing. What sits on top is what that layer makes possible.
Schematic view of the ecosystem as three stacked planes: at the bottom and widest the connecting layer, above it the AI agents, and on top our own solutions.
The connecting layer
Above your ERP, CRM, HR and finance package sits one layer where the data comes together. Your systems stay where they are; we don't replace them.
Ask one question instead of searching each system separately, with the origin of every value visible next to it.
AI agents on that layer
On the connected data we put agents that take over work: researching requests, preparing case files, flagging anomalies.
Recurring lookup work disappears, and every step an agent takes can be read back afterwards.
Our own solutions
On that same layer we build our own software. There is nothing to buy there yet: the first product is still in development. When it arrives, you are not adding another isolated package, but something that already knows your own data.

Provable is a mechanism here.
We keep what we measured apart from what we think of it. That distinction sits inside our products, and it applies to this page too.
carries its source
A fact without provenance is an opinion with confidence. Every fact states where it comes from and when it was established.
The language models behind our agents run at Mistral, inside Europe. There is no path to a US provider.
carries its caveat
Interpreting is fine, as long as it is labelled as interpretation, with what is not yet settled stated alongside. That saves you the reverse engineering later.
Every figure on this site passes a gate.
Every number in the delivered pages passes a gate on every build: it is in the figure register with a source and a measurement date, it can be recounted from its own surroundings, or it falls into a named exemption. If that does not hold, the build fails and the text does not ship.

From recording the standard to implementing it.
The first product on the layer. For organisations that have to comply with NIS2, ISO 27001 or DORA: not a register that tracks how far behind you are, but a system that turns the requirement into work.
- Per requirement the text of the standard itself, not a paraphrase whose origin you cannot check.
- Per requirement what you must do, who you assign to it and which evidence an auditor accepts.
- One implemented measure counts towards every standard in which that requirement returns.
Illustration from the product: one compliance requirement, unfolded: the text of the standard with the FACT stamp, what has to happen, who owns it and which evidence an auditor accepts.
NIS2, article 21 · directive (EU) 2022/2555
Appropriate measures to manage the risks posed to the security of network and information systems, including policies on risk analysis.
- What you do
- Adopt a risk analysis and review it annually
- Who
- Role: information security owner
- Evidence that counts
- Adopted analysis document with its decision date
What "appropriate" means depends on your size and sector; the product proposes an answer and marks it as interpretation.
Announced
What comes after compliance on the layer.
Compliance is what we are building now and what we release first. The workspace and the planners follow, on that same layer. We put no date next to them for as long as we cannot make it, and nowhere on this site will you find them among the things that already exist today.
The second track: we'll build it inside your organisation too.
Alongside our own products we do consultancy and custom work on the same layer: implementation, integrations and AI automation in your own environment. One question is enough to start.
You talk to the peoplewho build it.
Whoever sits at your table also sits in the architecture and in the code, and stays accountable once it runs. On this site we name roles and not people; that is a choice, not an omission.
Anchored in Europe
Our environment runs on European infrastructure that we manage ourselves, and the models behind the agents run at a European provider. Your data does not leave that area because it happens to suit a vendor.

Who is at the table
- Architecture
- Designs the connecting layer and makes sure every integration stays traceable back to its source.
- Engineering
- Builds the layer, the agents and the products. The same people you speak to at the table.
- Security & compliance
- Translates standards into measures and keeps the evidence in order, for clients and for ourselves.
- Operations
- Runs the European infrastructure everything sits on, and stays reachable after go-live.
Where the layer would start for you.
One conversation is enough to know where the layer would start for you and what the first step returns. No obligation, no quote process up front.
Book an introductionA personal reply within one working day.




