NotAI Trust Center

Security and privacy transparency for the NotAI platform

This is the public record of how NotAI protects the data institutions entrust to us: our security controls, compliance posture, subprocessors, and the documentation behind them. Enterprise customers download restricted reports from the Documents section of the NotAI dashboard; everyone else can browse the public record or request access.

This trust center, and the entire NotAI marketing surface, sets zero cookies and loads zero third-party scripts. That is not a policy summary; it is a property of the pages themselves, and you can verify it directly in your browser's developer tools.

Compliance

SOC 2 Type II

An independent audit of our security, availability, and confidentiality controls. Our Type II attestation is refreshed annually.

Attested

GDPR

Our Data Processing Agreement with Standard Contractual Clauses is published, and customer data is pinned to the US or EU region chosen at signup.

DPA + SCCs

UK GDPR

UK data transfers are covered by the International Data Transfer Addendum incorporated in our published DPA.

IDTA

FERPA

We operate as a service provider, supporting each institution's obligations for education records in LMS deployments.

Service provider

COPPA

NotAI is deployed under a school-consent model and provides no direct-to-child service.

School consent model

NY Ed Law 2-d

Our Parents' Bill of Rights for data privacy and security is published on the marketing site.

Published

CCPA/CPRA

We process personal information as a service provider under our customers' instructions.

Service provider

EU AI Act

Our Article 50 transparency notice is published on the marketing site.

Art. 50 notice

Risk profile

  • Hosting

    Microsoft Azure. Primary service data is stored and processed in the US or EU region each customer chooses at signup and is not moved between regions. Limited ancillary data - billing and transactional-email metadata - is processed in the United States, as described in our privacy policy.

  • Data classification

    Confidential academic-integrity signals, processed on behalf of educational institutions.

  • Third-party dependence

    Five subprocessors: Microsoft Azure, Cloudflare, Constellix (DigiCert), Twilio SendGrid, and Stripe. See the full subprocessor list.

  • Business continuity

    Business continuity and disaster recovery planning, including recovery time and recovery point objectives, is covered by our SOC 2 Type II audit; the BC/DR summary is available to enterprise customers in the resource library.

  • Status

    Current control status, including monitoring and availability, is maintained on the controls page.

Controls

All controls

Infrastructure

How the platform and its data are protected at the infrastructure layer.

  • Encryption at rest Active

    All customer data is encrypted at rest; magic-link key material is protected with customer-managed keys in Azure Key Vault.

  • TLS-only transit Active

    All connections require TLS; unencrypted transport is not accepted.

  • WAF and DDoS protection Active

    Cloudflare provides WAF and DDoS protection at the edge, with Azure Front Door as failover.

Product security

Security properties built into the product itself.

  • Passwordless authentication Active

    Sign-in uses magic links; NotAI stores no passwords.

  • Region pinning Active

    Primary service data stays in the US or EU region chosen at signup and is not moved between regions; limited ancillary data (billing and transactional-email metadata) is processed in the United States, as described in our privacy policy.

  • Zero cookies, zero third-party scripts Active

    The marketing site and this trust center set no cookies and load no third-party scripts.

Secure development

Checks that run before code and content reach production.

  • Static analysis Active

    CodeQL scans run in CI on every build.

  • Dependency scanning Active

    Dependencies are scanned for known vulnerabilities in CI.

  • Pre-deploy scanning Active

    Builds are scanned for embedded secrets and analytics code before deployment.

Latest updates

All updates
  1. General

    NotAI Trust Center launched

    The NotAI Trust Center is now live: self-hosted on our own infrastructure, with zero cookies, zero third-party scripts, and restricted-document access tied to our existing enterprise authentication.

  2. Compliance

    SOC 2 Type II report available to customers

    NotAI maintains a SOC 2 Type II attestation, refreshed annually. The current report is available under NDA to authenticated enterprise customers.

Need the restricted documents?

Enterprise customers download restricted reports from the Documents section of the NotAI dashboard. Evaluating NotAI for procurement? Request access and we will arrange document grants under NDA.

Contact

Questions about anything on this site? Pick the right inbox and we will get back to you.

Security
[email protected]
Privacy and data protection
[email protected]
Trust documentation and questionnaires
[email protected]

To report a security issue, see our vulnerability disclosure policy.