NotAI Trust Center
Security and privacy transparency for NotAI
This is the public record of how NotAI protects the data institutions entrust to us: our security controls, compliance posture, subprocessors, and the documentation behind them. NotAI customers download restricted reports from the Documents section of the NotAI dashboard; everyone else can browse the public record or request access.
This trust center, and the entire NotAI marketing surface, sets zero cookies and loads zero third-party scripts. That is not a policy summary; it is a property of the pages themselves, and you can verify it directly in your browser's developer tools.
Compliance
SOC 2 Type II
An independent audit of our security, availability, and confidentiality controls. Our Type II attestation is refreshed annually.
AttestedGDPR
Our Data Processing Agreement with Standard Contractual Clauses is published, and customer data is pinned to the US or EU region chosen at signup.
DPA + SCCsUK GDPR
UK data transfers are covered by the International Data Transfer Addendum incorporated in our published DPA.
IDTAFERPA
We operate as a service provider, supporting each institution's obligations for education records in LMS deployments.
Service providerCOPPA
NotAI is deployed under a school-consent model and provides no direct-to-child service.
School consent modelNY Ed Law 2-d
Our Parents' Bill of Rights for data privacy and security is published on the marketing site.
PublishedCCPA/CPRA
We process personal information as a service provider under our customers' instructions.
Service providerEU AI Act
Our Article 50 transparency notice is published on the marketing site.
Art. 50 noticeRisk Profile
-
Hosting
Microsoft Azure. Primary service data is stored and processed in the US or EU region each customer chooses at signup and is not moved between regions. Limited ancillary data - billing and transactional-email metadata - is processed in the United States, as described in our privacy policy.
-
Data classification
Confidential academic-integrity signals, processed on behalf of educational institutions.
-
Third-party dependence
Six subprocessors: Microsoft Azure, Cloudflare, Constellix (DigiCert), Twilio (SendGrid), Stripe, and Google LLC. See the full subprocessor list.
-
Business continuity
Business continuity and disaster recovery planning, including recovery time and recovery point objectives, is covered by our SOC 2 Type II audit; the BC/DR summary is available to enterprise customers in the resource library.
-
Status
Current control status, including monitoring and availability, is maintained on the controls page.
Controls
All controlsInfrastructure
How the platform and its data are protected at the infrastructure layer.
-
Encryption at rest
Active
All customer data is encrypted at rest; magic-link key material is protected with customer-managed keys in Azure Key Vault.
-
TLS-only transit
Active
All connections require TLS; unencrypted transport is not accepted.
-
WAF and DDoS protection
Active
Cloudflare provides WAF and DDoS protection at the edge, with Azure Front Door as failover.
Product Security
Security properties built into the product itself.
-
Passwordless and federated authentication
Active
Sign-in uses magic links, SSO, and LTI launch; NotAI stores no passwords.
-
Region pinning
Active
Primary service data stays in the US or EU region chosen at signup and is not moved between regions; limited ancillary data (billing and transactional-email metadata) is processed in the United States, as described in our privacy policy.
-
Zero cookies, zero third-party scripts
Active
The marketing site and this trust center set no cookies and load no third-party scripts.
Secure Development
Checks that run before code and content reach production.
-
Static analysis
Active
Static analysis runs in CI on every change.
-
Dependency scanning
Active
Dependencies are scanned for known vulnerabilities in CI.
-
Pre-deploy scanning
Active
Builds are scanned for embedded secrets and analytics code before deployment.
Featured Documents
All documentsSOC 2 Type II Report
The independent service auditor's report on our security controls. The attestation is refreshed annually; the current report is available under NDA.
Penetration Test Summary
Executive summary of independent penetration testing of the platform, shared under NDA.
HECVAT Full
HECVAT Full questionnaire response for higher-education vendor security reviews.
HECVAT Lite
HECVAT Lite questionnaire response for streamlined vendor reviews, regenerated continuously from live evidence by an automated compliance pipeline.
Accessibility Conformance Report
Our accessibility conformance report (a VPAT-convention ACR) covering WCAG 2.1 Levels A and AA, regenerated continuously from live evidence by an automated compliance pipeline.
Subprocessor List
Every third party that processes customer data on our behalf, with purpose, data categories, location, and safeguards.
Latest Updates
All updates-
Compliance
Accessibility Conformance Report and HECVAT Lite Now Public Downloads
The Accessibility Conformance Report (VPAT) and the HECVAT Lite questionnaire response are now public downloads in the resource library, regenerated continuously from live evidence by an automated compliance pipeline.
-
General
NotAI Trust Center Launched
The NotAI Trust Center is now live: self-hosted on our own infrastructure, with zero cookies, zero third-party scripts, and restricted-document access tied to our existing enterprise authentication.
-
Compliance
SOC 2 Type II Report Available to Customers
NotAI maintains a SOC 2 Type II attestation, refreshed annually. The current report is available under NDA to authenticated enterprise customers.
Need the Restricted Documents?
NotAI customers download restricted reports from the Documents section of the dashboard, and the most sensitive documents require an enterprise plan. Evaluating NotAI for procurement? Request access; approved reviewers receive document grants under NDA, and requests from non-customers are handled at our discretion.
Contact
Questions about anything on this site? Pick the right inbox below.
- Security
- [email protected]
- Privacy and data protection
- [email protected]
- Trust documentation and questionnaires
- [email protected]
To report a security issue, see our vulnerability disclosure policy.