Notion AI
notion.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Processing location not disclosed
See Before you sign, with what to ask for ↓
Scanned Sep 1, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.
What to ask for: Pin processing regions per data classification in the contract.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Notion states that neither it nor its AI subprocessors use customer data to train models by default, and that it holds contractual agreements with those subprocessors prohibiting it — so the commitment is passed down the supply chain rather than stopping at Notion.
“By default, Notion and its AI Subprocessors do not use Customer Data to train any models. We specifically have contractual agreements in place with our AI Subprocessors that prohibit the use of Customer Data to train their models.”
“Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our machine learning models.”
✓How long do they keep your data?Clear
Notion generates an embedding per workspace page using an OpenAI zero-retention embeddings API, and stores those embeddings in a vector database for fast lookup against a user request.
“For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.”
!Who else can access your data?Ask the vendor
Notion states it uses large language models hosted by Notion itself and by organisations such as Anthropic and OpenAI, and commits to publishing any third party that processes customer data on its subprocessor page.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
“Customers may sign up to receive notification of new Subprocessors by emailing [email protected] with the subject “Subscribe to New Subprocessors.””
!Where is your data processed?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!What happens in a security incident?Ask the vendor
Notion runs a bug bounty programme through HackerOne alongside annual third-party penetration testing.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Annual third-party penetration testing. * Bug bounty program through”
Key findingsclick a row for the evidence
✓The no-training commitment is passed down to the AI subprocessorsStrong
Notion states it holds contractual agreements with its AI subprocessors prohibiting them from using customer data to train their models, and that using Notion AI grants Notion no licence to train its own models on customer data.
Most vendors commit only for themselves and leave the model provider's terms to the buyer to chase. Binding the subprocessors contractually is the stronger position, because it closes the gap where a commitment stops at the vendor boundary and the actual model provider is governed by something else.
“By default, Notion and its AI Subprocessors do not use Customer Data to train any models. We specifically have contractual agreements in place with our AI Subprocessors that prohibit the use of Customer Data to train their models.”
“Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our machine learning models.”
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
✓Retrieval is built on a zero-retention embeddings APIStrong
Page embeddings are generated through an OpenAI zero-retention embeddings API and stored in Notion's own vector database, and Notion states embeddings carry the same protections as customer data.
Embeddings are where AI assurance quietly leaks: they are derived from customer content but often fall outside a vendor's data commitments. Naming the zero-retention API and explicitly pulling embeddings inside the customer-data commitments closes that gap, and is a level of architectural detail few vendors publish.
“For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.”
“Notion treats embeddings with the same level of security and privacy considerations as Customer Data.”
✓Subprocessor changes can be subscribed toStrong
Customers can register by email to be notified when new subprocessors are added, and Notion commits to publishing any third party processing customer data on its subprocessor page.
AI supply chains change faster than contracts get reviewed. A notification mechanism converts supply-chain monitoring from a recurring manual check into something that reaches the buyer, which is what makes an ongoing obligation practical.
“Customers may sign up to receive notification of new Subprocessors by emailing [email protected] with the subject “Subscribe to New Subprocessors.””
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
!A broad certification set is claimed, but no certificate was publicGap
Notion states annual third-party audits covering SOC 2 Type II, ISO 27001/17/18/701, HIPAA and BSI C5. The trust centre lists an ISO/IEC 27001 certificate behind a request-access gate, so no certificate or scope statement was readable in this collection.
The breadth claimed is unusually wide for a company of this size and would be a strong signal if evidenced. As collected it rests on Notion's own assertion, and the scope statements — in particular whether Notion AI sits inside them — cannot be checked from outside the gate.
Question for vendor: Please provide the ISO/IEC 27001 certificate and SOC 2 Type II report, and confirm whether Notion AI is named within their scope.
“Annual third-party audits: SOC 2 Type II, ISO 27001/17/18/701, HIPAA, BSI C5. * Annual third-party penetration testing. * Bug bounty program through [HackerOne](https://hackerone.com/notion). * 99.9% uptime SLA”
!Notion hosts some models itself and buys othersGap
Notion states it uses LLMs hosted by Notion as well as by Anthropic and OpenAI, and that it continuously evaluates providers. Which model serves which feature is not stated.
A mixed self-hosted and third-party estate means the assurance position differs by feature, and a provider change is a routine product decision rather than a contractual event. The notification mechanism mitigates this, but a buyer cannot currently tell which of their workflows leave Notion's own infrastructure.
Question for vendor: Which Notion AI features route to Anthropic or OpenAI rather than Notion-hosted models, and how are we told when that changes?
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
“For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.”
✓Tenant separation is stated explicitly for AI processingStrong
Notion states customer accounts are kept separate in production and that data from different customers is not mixed or processed together during AI processing.
Cross-tenant leakage through a shared AI pipeline is a distinct risk from ordinary multi-tenancy, and most vendors address only the latter. Saying it explicitly for the AI path is the useful part.
“Individual customer accounts are kept separate in our production environment. We do not mix or process data from different customers together during AI processing. This means we do not expose your data to other Notion customers.”
!Declared OpenAI, technically observed GoogleGap
The vendor's own materials name OpenAI as the model provider, but DNS, certificate, or HTTP evidence points to Google in that role instead.
A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.
Question for vendor: Can you confirm whether OpenAI or Google is the actual model provider?
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
“For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
Governance & accountability: not publicly evidenced.
AI system15% of the score25
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.”
“Chat about anything, using AI knowledge from the latest models Autofill summaries and insights across entire databases Automatically summarize and transcribe meeting notes Notion AI appears seamlessly in your workspace but leverages technology from several AI Subprocessors to provide you with the service. Check out our Subprocessor Page”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
Testing & evaluation: not publicly evidenced.
Change management: not publicly evidenced.
Model10% of the score75
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
Customer data15% of the score65
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“By default, Notion and its AI Subprocessors do not use Customer Data to train any models. We specifically have contractual agreements in place with our AI Subprocessors that prohibit the use of Customer Data to train their models.”
“Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our machine learning models.”
“Notion treats embeddings with the same level of security and privacy considerations as Customer Data.”
“Individual customer accounts are kept separate in our production environment. We do not mix or process data from different customers together during AI processing. This means we do not expose your data to other Notion customers.”
“it is encrypted in-transit using TLS 1.2 or greater. For more information about how Notion processes your data, please refer to our Data Processing Addendum”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the score75
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .”
“Customers may sign up to receive notification of new Subprocessors by emailing [email protected] with the subject “Subscribe to New Subprocessors.””
Security foundation15% of the scoreorganisation-level evidence50
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Annual third-party penetration testing. * Bug bounty program through”
Independent assurance evidence10% of the scoreorganisation-level evidence47
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Annual third-party audits: SOC 2 Type II, ISO 27001/17/18/701, HIPAA, BSI C5. * Annual third-party penetration testing. * Bug bounty program through [HackerOne](https://hackerone.com/notion). * 99.9% uptime SLA”
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score40
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“it is encrypted in-transit using TLS 1.2 or greater. For more information about how Notion processes your data, please refer to our Data Processing Addendum”
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 53 → up to 75 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 6 — registry checks and verification ladders, click to view
Stated as an annual third-party audit. No report or scope statement was readable — the trust centre gates documents behind request-access.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
A certificate is listed in the trust centre behind a request-access gate, so neither the certificate nor its scope could be read.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Sources 12 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
