← Trust Directory

Notion

notion.com · 1 assessment

Notion
Approve with conditions
1 item to confirm in writing
Assessed Sep 1, 2026 · public evidence coverage 57% · evidence confidence medium high · methodology 0.7.0

Assessed before company and product grades were shown separately; see the product assessments below.

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

Notion AI
Approve with conditions
1 item to confirm in writing
Assessed Sep 1, 2026 · public evidence coverage 57% · evidence confidence medium high · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2 Type II
Vendor claimed only

Stated as an annual third-party audit. No report or scope statement was readable — the trust centre gates documents behind request-access.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27001
Vendor claimed only

A certificate is listed in the trust centre behind a request-access gate, so neither the certificate nor its scope could be read.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27701
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
BSI C5
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
HIPAA
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 42001
Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: OpenAI, Anthropic
Infrastructure: AWS

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Sep 1, 2026.