Trust Center

Documents & Resources

Every security, privacy, and compliance document we publish, in one place. Public policies are linked directly below. Restricted artifacts are listed so you can see exactly what exists; NotAI customers download them from the dashboard, and anyone else can request access.

Restricted documents are available to NotAI customers in the Documents section of the dashboard, and the most sensitive documents require an enterprise plan. If your organization does not have a NotAI account, you can request access. Requests from non-customers are handled at our discretion.

Request access

Public Documents

These documents are published for everyone. Legal policies live on the main NotAI site; the subprocessor list, the vulnerability disclosure policy, and the continuously generated compliance documents (the Accessibility Conformance Report and HECVAT Lite) are published here in the Trust Center as direct downloads.

Privacy Policy

How NotAI collects, uses, and protects personal data across the platform.

Web page, public

Terms of Service

The agreement that governs use of the NotAI platform and services.

Web page, public

Data Processing Agreement

Our DPA with EU Standard Contractual Clauses and the UK IDTA, applicable to all customers.

Web page, public

AI Transparency Notice

Our EU AI Act Article 50 transparency disclosure describing how NotAI detection works.

Web page, public

NY Parents' Bill of Rights

Our Parents' Bill of Rights notice under New York Education Law Section 2-d.

Web page, public

Subprocessor List

Every third-party subprocessor we use, with purpose, location, and safeguards.

Web page, public

Vulnerability Disclosure Policy

How to report a security issue to NotAI, and the safe harbor we extend to researchers.

Web page, public

Accessibility Conformance Report

Our accessibility conformance report (a VPAT-convention ACR) covering WCAG 2.1 Levels A and AA, regenerated continuously from live evidence by an automated compliance pipeline.

PDF and web page, public download

HECVAT Lite

HECVAT Lite questionnaire response for streamlined vendor reviews, regenerated continuously from live evidence by an automated compliance pipeline.

Spreadsheet, public download

Restricted Documents

These artifacts are listed publicly so you can see what exists, but downloads are limited to NotAI customers and approved reviewers. Customers can download them from the Documents section of the NotAI dashboard according to their plan; the most sensitive documents require an enterprise plan. Anyone else can request access by email.

SOC 2 Type II Report

Independent service auditor's report covering our security, availability, and confidentiality controls. The attestation is refreshed annually.

PDF, NDA required

Penetration Test Executive Summary

Executive summary of independent penetration testing of the platform, covering scope, methodology, and remediation status. Shared under NDA.

PDF, NDA required

HECVAT Full

HECVAT Full questionnaire response for higher-education vendor security reviews.

Spreadsheet, NDA required

CAIQ Lite

CAIQ Lite questionnaire response mapped to CSA Cloud Controls Matrix domains.

Spreadsheet, NDA required

Architecture & Data-Flow Diagrams

Architecture and data-flow diagrams showing how detection data moves through the platform.

PDF, NDA required

BC/DR Summary

Summary of business continuity and disaster recovery planning, including recovery time and recovery point objectives.

PDF, available on completion

Cyber Liability Insurance Certificate

Certificate of insurance for cyber liability coverage.

PDF, available on request

Incident Response Plan Summary

Summary of our incident response plan, covering roles, severity classification, and customer notification.

PDF, NDA required

DPIA Support Pack

Supporting materials for institutional data protection impact assessments and privacy reviews.

PDF, NDA required

W-9

Completed IRS Form W-9 for procurement and vendor onboarding.

PDF, available on request

Need a Restricted Document?

NotAI customers download restricted documents from the Documents section of the dashboard, and the most sensitive documents require an enterprise plan. Not a customer? Email us your name, work email, and organization; requests are handled at our discretion and may not receive a response. Approved reviewers accept a click-through NDA, and documents are delivered in the dashboard through watermarked, expiring links - never permanent URLs.

Request access