One workspace. Every control you need.
Your merchants experience the platform. You run it. NORBr gives you a single, structured workspace to manage team access, authentication policies, branding, domains, and your compliance posture. Every operational change is a configuration. Everything your platform needs to stay governed, secure, and audit-ready.
Book a demo
Configure every operational lever.
Running a payment platform means managing more than payments. It means managing people, access, brand consistency, authentication standards, and regulatory obligations. NORBr consolidates every operational lever in one workspace, configurable without development, auditable by design.
Workspace identity, domains and branding
User management and role assignment
TeamSpaces for granular access scoping
SSO (SAML 2.0), passkeys and MFA policies
Password policy and session rules
Financial and compliance profile




Enterprise teams don't use passwords the same way. Some want SSO through their corporate identity provider. Others want passwordless login. Some compliance frameworks require MFA regardless of how the user authenticated. NORBr lets you set the exact policy your organization and your auditors need. You choose the methods. You set the requirements. The platform enforces them.
Enable your primary login methods
Choose from email/password, SSO via SAML 2.0 with your corporate IdP (Azure AD, Okta, or any SAML-compliant provider), or passkey sign-in via WebAuthn/FIDO2. At least one method must remain active at all times. You can run multiple simultaneously.
Set your MFA requirements
Require MFA for all local logins. Enforce it even for SSO users when your corporate IdP does not enforce it itself. Passkeys are the default second factor for MFA and cannot be disabled — they provide phishing-resistant authentication using the user's device.
Configure your password policy
Set a minimum password length. Compromised passwords are automatically blocked using breach detection. Passwords never expire automatically. When MFA is disabled, the minimum length requirement increases to 15 characters.
Set session rules
Define how long a session stays active. Set a separate duration for remembered sessions. Rules apply to all users in the workspace unless overridden at a downstream scope.
Enable TOTP fallback (post-launch)
Authenticator app codes are available as a fallback MFA method when passkeys are unavailable. This option is in the product roadmap and will be available after the initial launch.
When your prospects ask about security, the answer shouldn't require a deck. NORBr holds a current PCI DSS Attestation of Compliance (AOC) and is GDPR-compliant by design. That means your platform inherits a compliance foundation that would take years and significant internal investment to build independently. For your enterprise merchants and acquisition conversations with regulated partners, that's not a footnote. It's a commercial advantage.


One workspace. Every access control and authentication policy configured by you. Enforced by NORBr.