Privacy Policy
How NotAI collects, uses, and protects personal data across the platform.
Trust Center
Every security, privacy, and compliance document we publish, in one place. Public policies are linked directly below. Restricted artifacts are listed so you can see exactly what exists; NotAI customers download them from the dashboard, and anyone else can request access.
Restricted documents are available to NotAI customers in the Documents section of the dashboard, and the most sensitive documents require an enterprise plan. If your organization does not have a NotAI account, you can request access. Requests from non-customers are handled at our discretion.
Request accessThese documents are published for everyone. Legal policies live on the main NotAI site; the subprocessor list, the vulnerability disclosure policy, and the continuously generated compliance documents (the Accessibility Conformance Report and HECVAT Lite) are published here in the Trust Center as direct downloads.
How NotAI collects, uses, and protects personal data across the platform.
The agreement that governs use of the NotAI platform and services.
Our DPA with EU Standard Contractual Clauses and the UK IDTA, applicable to all customers.
Our EU AI Act Article 50 transparency disclosure describing how NotAI detection works.
Our Parents' Bill of Rights notice under New York Education Law Section 2-d.
Every third-party subprocessor we use, with purpose, location, and safeguards.
How to report a security issue to NotAI, and the safe harbor we extend to researchers.
Our accessibility conformance report (a VPAT-convention ACR) covering WCAG 2.1 Levels A and AA, regenerated continuously from live evidence by an automated compliance pipeline.
HECVAT Lite questionnaire response for streamlined vendor reviews, regenerated continuously from live evidence by an automated compliance pipeline.
These artifacts are listed publicly so you can see what exists, but downloads are limited to NotAI customers and approved reviewers. Customers can download them from the Documents section of the NotAI dashboard according to their plan; the most sensitive documents require an enterprise plan. Anyone else can request access by email.
Independent service auditor's report covering our security, availability, and confidentiality controls. The attestation is refreshed annually.
Executive summary of independent penetration testing of the platform, covering scope, methodology, and remediation status. Shared under NDA.
HECVAT Full questionnaire response for higher-education vendor security reviews.
CAIQ Lite questionnaire response mapped to CSA Cloud Controls Matrix domains.
Architecture and data-flow diagrams showing how detection data moves through the platform.
Summary of business continuity and disaster recovery planning, including recovery time and recovery point objectives.
Certificate of insurance for cyber liability coverage.
Summary of our incident response plan, covering roles, severity classification, and customer notification.
Supporting materials for institutional data protection impact assessments and privacy reviews.
Completed IRS Form W-9 for procurement and vendor onboarding.
NotAI customers download restricted documents from the Documents section of the dashboard, and the most sensitive documents require an enterprise plan. Not a customer? Email us your name, work email, and organization; requests are handled at our discretion and may not receive a response. Approved reviewers accept a click-through NDA, and documents are delivered in the dashboard through watermarked, expiring links - never permanent URLs.
Request access