NotAI Trust Center
Security and privacy transparency for the NotAI platform
This is the public record of how NotAI protects the data institutions entrust to us: our security controls, compliance posture, subprocessors, and the documentation behind them. Enterprise customers download restricted reports from the Documents section of the NotAI dashboard; everyone else can browse the public record or request access.
This trust center, and the entire NotAI marketing surface, sets zero cookies and loads zero third-party scripts. That is not a policy summary; it is a property of the pages themselves, and you can verify it directly in your browser's developer tools.
Compliance
SOC 2 Type II
An independent audit of our security, availability, and confidentiality controls. Our Type II attestation is refreshed annually.
AttestedGDPR
Our Data Processing Agreement with Standard Contractual Clauses is published, and customer data is pinned to the US or EU region chosen at signup.
DPA + SCCsUK GDPR
UK data transfers are covered by the International Data Transfer Addendum incorporated in our published DPA.
IDTAFERPA
We operate as a service provider, supporting each institution's obligations for education records in LMS deployments.
Service providerCOPPA
NotAI is deployed under a school-consent model and provides no direct-to-child service.
School consent modelNY Ed Law 2-d
Our Parents' Bill of Rights for data privacy and security is published on the marketing site.
PublishedCCPA/CPRA
We process personal information as a service provider under our customers' instructions.
Service providerEU AI Act
Our Article 50 transparency notice is published on the marketing site.
Art. 50 noticeRisk profile
-
Hosting
Microsoft Azure. Primary service data is stored and processed in the US or EU region each customer chooses at signup and is not moved between regions. Limited ancillary data - billing and transactional-email metadata - is processed in the United States, as described in our privacy policy.
-
Data classification
Confidential academic-integrity signals, processed on behalf of educational institutions.
-
Third-party dependence
Five subprocessors: Microsoft Azure, Cloudflare, Constellix (DigiCert), Twilio SendGrid, and Stripe. See the full subprocessor list.
-
Business continuity
Business continuity and disaster recovery planning, including recovery time and recovery point objectives, is covered by our SOC 2 Type II audit; the BC/DR summary is available to enterprise customers in the resource library.
-
Status
Current control status, including monitoring and availability, is maintained on the controls page.
Controls
All controlsInfrastructure
How the platform and its data are protected at the infrastructure layer.
-
Encryption at rest
Active
All customer data is encrypted at rest; magic-link key material is protected with customer-managed keys in Azure Key Vault.
-
TLS-only transit
Active
All connections require TLS; unencrypted transport is not accepted.
-
WAF and DDoS protection
Active
Cloudflare provides WAF and DDoS protection at the edge, with Azure Front Door as failover.
Product security
Security properties built into the product itself.
-
Passwordless authentication
Active
Sign-in uses magic links; NotAI stores no passwords.
-
Region pinning
Active
Primary service data stays in the US or EU region chosen at signup and is not moved between regions; limited ancillary data (billing and transactional-email metadata) is processed in the United States, as described in our privacy policy.
-
Zero cookies, zero third-party scripts
Active
The marketing site and this trust center set no cookies and load no third-party scripts.
Secure development
Checks that run before code and content reach production.
-
Static analysis
Active
CodeQL scans run in CI on every build.
-
Dependency scanning
Active
Dependencies are scanned for known vulnerabilities in CI.
-
Pre-deploy scanning
Active
Builds are scanned for embedded secrets and analytics code before deployment.
Featured documents
All documentsSOC 2 Type II report
The independent service auditor's report on our security controls. The attestation is refreshed annually; the current report is available under NDA.
Penetration test summary
Executive summary of independent penetration testing of the platform, shared under NDA.
HECVAT Full
HECVAT Full questionnaire response for higher-education vendor security reviews.
HECVAT Lite
HECVAT Lite questionnaire response for streamlined vendor reviews.
Accessibility report (VPAT)
Accessibility conformance report covering WCAG 2.1 and Section 508 for the dashboard and student-facing surfaces.
Subprocessor list
Every third party that processes customer data on our behalf, with purpose, data categories, location, and safeguards.
Latest updates
All updates-
General
NotAI Trust Center launched
The NotAI Trust Center is now live: self-hosted on our own infrastructure, with zero cookies, zero third-party scripts, and restricted-document access tied to our existing enterprise authentication.
-
Compliance
SOC 2 Type II report available to customers
NotAI maintains a SOC 2 Type II attestation, refreshed annually. The current report is available under NDA to authenticated enterprise customers.
Need the restricted documents?
Enterprise customers download restricted reports from the Documents section of the NotAI dashboard. Evaluating NotAI for procurement? Request access and we will arrange document grants under NDA.
Contact
Questions about anything on this site? Pick the right inbox and we will get back to you.
- Security
- [email protected]
- Privacy and data protection
- [email protected]
- Trust documentation and questionnaires
- [email protected]
To report a security issue, see our vulnerability disclosure policy.