Notion AI

notion.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
53 / 100D
Procurement decision
Approve with conditions
1 condition outstanding
  • Processing location not disclosed

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Sep 1, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Processing location not disclosedCondition

Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.

What to ask for: Pin processing regions per data classification in the contract.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

Notion states that neither it nor its AI subprocessors use customer data to train models by default, and that it holds contractual agreements with those subprocessors prohibiting it — so the commitment is passed down the supply chain rather than stopping at Notion.

Evidence
By default, Notion and its AI Subprocessors do not use Customer Data to train any models. We specifically have contractual agreements in place with our AI Subprocessors that prohibit the use of Customer Data to train their models.
Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our machine learning models.
How long do they keep your data?Clear

Notion generates an embedding per workspace page using an OpenAI zero-retention embeddings API, and stores those embeddings in a vector database for fast lookup against a user request.

Evidence
For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.
!Who else can access your data?Ask the vendor

Notion states it uses large language models hosted by Notion itself and by organisations such as Anthropic and OpenAI, and commits to publishing any third party that processes customer data on its subprocessor page.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
Customers may sign up to receive notification of new Subprocessors by emailing [email protected] with the subject “Subscribe to New Subprocessors.”
!Where is your data processed?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!What happens in a security incident?Ask the vendor

Notion runs a bug bounty programme through HackerOne alongside annual third-party penetration testing.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Annual third-party penetration testing. * Bug bounty program through

Key findingsclick a row for the evidence

The no-training commitment is passed down to the AI subprocessorsStrong

Notion states it holds contractual agreements with its AI subprocessors prohibiting them from using customer data to train their models, and that using Notion AI grants Notion no licence to train its own models on customer data.

Most vendors commit only for themselves and leave the model provider's terms to the buyer to chase. Binding the subprocessors contractually is the stronger position, because it closes the gap where a commitment stops at the vendor boundary and the actual model provider is governed by something else.

Evidence
By default, Notion and its AI Subprocessors do not use Customer Data to train any models. We specifically have contractual agreements in place with our AI Subprocessors that prohibit the use of Customer Data to train their models.
Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our machine learning models.
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
Retrieval is built on a zero-retention embeddings APIStrong

Page embeddings are generated through an OpenAI zero-retention embeddings API and stored in Notion's own vector database, and Notion states embeddings carry the same protections as customer data.

Embeddings are where AI assurance quietly leaks: they are derived from customer content but often fall outside a vendor's data commitments. Naming the zero-retention API and explicitly pulling embeddings inside the customer-data commitments closes that gap, and is a level of architectural detail few vendors publish.

Evidence
For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.
Notion treats embeddings with the same level of security and privacy considerations as Customer Data.
Subprocessor changes can be subscribed toStrong

Customers can register by email to be notified when new subprocessors are added, and Notion commits to publishing any third party processing customer data on its subprocessor page.

AI supply chains change faster than contracts get reviewed. A notification mechanism converts supply-chain monitoring from a recurring manual check into something that reaches the buyer, which is what makes an ongoing obligation practical.

Evidence
Customers may sign up to receive notification of new Subprocessors by emailing [email protected] with the subject “Subscribe to New Subprocessors.”
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
!A broad certification set is claimed, but no certificate was publicGap

Notion states annual third-party audits covering SOC 2 Type II, ISO 27001/17/18/701, HIPAA and BSI C5. The trust centre lists an ISO/IEC 27001 certificate behind a request-access gate, so no certificate or scope statement was readable in this collection.

The breadth claimed is unusually wide for a company of this size and would be a strong signal if evidenced. As collected it rests on Notion's own assertion, and the scope statements — in particular whether Notion AI sits inside them — cannot be checked from outside the gate.

Question for vendor: Please provide the ISO/IEC 27001 certificate and SOC 2 Type II report, and confirm whether Notion AI is named within their scope.

Evidence
Annual third-party audits: SOC 2 Type II, ISO 27001/17/18/701, HIPAA, BSI C5. * Annual third-party penetration testing. * Bug bounty program through [HackerOne](https://hackerone.com/notion). * 99.9% uptime SLA
!Notion hosts some models itself and buys othersGap

Notion states it uses LLMs hosted by Notion as well as by Anthropic and OpenAI, and that it continuously evaluates providers. Which model serves which feature is not stated.

A mixed self-hosted and third-party estate means the assurance position differs by feature, and a provider change is a routine product decision rather than a contractual event. The notification mechanism mitigates this, but a buyer cannot currently tell which of their workflows leave Notion's own infrastructure.

Question for vendor: Which Notion AI features route to Anthropic or OpenAI rather than Notion-hosted models, and how are we told when that changes?

Evidence
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.
Tenant separation is stated explicitly for AI processingStrong

Notion states customer accounts are kept separate in production and that data from different customers is not mixed or processed together during AI processing.

Cross-tenant leakage through a shared AI pipeline is a distinct risk from ordinary multi-tenancy, and most vendors address only the latter. Saying it explicitly for the AI path is the useful part.

Evidence
Individual customer accounts are kept separate in our production environment. We do not mix or process data from different customers together during AI processing. This means we do not expose your data to other Notion customers.
!Declared OpenAI, technically observed GoogleGap

The vendor's own materials name OpenAI as the model provider, but DNS, certificate, or HTTP evidence points to Google in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether OpenAI or Google is the actual model provider?

Evidence
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Not Evidenced

Governance & accountability: not publicly evidenced.

AI system15% of the score25
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Covered
Evidence — AI system description
For each page in your workspace, we generate an embedding by using an OpenAI zero-retention embeddings API. Notion receives an embedding for each Notion page and stores it in a vector database (e.g., Turbopuffer). The vector database is a data store optimized for embeddings that enables fast lookup of the most relevant pages given a user request.
Chat about anything, using AI knowledge from the latest models Autofill summaries and insights across entire databases Automatically summarize and transcribe meeting notes Notion AI appears seamlessly in your workspace but leverages technology from several AI Subprocessors to provide you with the service. Check out our Subprocessor Page
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Testing & evaluation: not publicly evidenced.

Change management: not publicly evidenced.

Model10% of the score75
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Covered
Evidence — Model & provider transparency
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
Customer data15% of the score65
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
By default, Notion and its AI Subprocessors do not use Customer Data to train any models. We specifically have contractual agreements in place with our AI Subprocessors that prohibit the use of Customer Data to train their models.
Your use of Notion AI does not grant Notion any right or license to your Customer Data to train our machine learning models.
Notion treats embeddings with the same level of security and privacy considerations as Customer Data.
Individual customer accounts are kept separate in our production environment. We do not mix or process data from different customers together during AI processing. This means we do not expose your data to other Notion customers.
it is encrypted in-transit using TLS 1.2 or greater. For more information about how Notion processes your data, please refer to our Data Processing Addendum

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Notion currently utilizes various large language models (LLMs) hosted by Notion as well as by organizations such as Anthropic and OpenAI. We continuously evaluate LLM providers and their models to provide the highest quality experience to our Notion AI users. Any third parties that process Customer Data will be published in our Subprocessor Page .
Customers may sign up to receive notification of new Subprocessors by emailing [email protected] with the subject “Subscribe to New Subprocessors.”
Security foundation15% of the scoreorganisation-level evidence50

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Annual third-party penetration testing. * Bug bounty program through
Independent assurance evidence10% of the scoreorganisation-level evidence47

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Annual third-party audits: SOC 2 Type II, ISO 27001/17/18/701, HIPAA, BSI C5. * Annual third-party penetration testing. * Bug bounty program through [HackerOne](https://hackerone.com/notion). * 99.9% uptime SLA

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score40
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
it is encrypted in-transit using TLS 1.2 or greater. For more information about how Notion processes your data, please refer to our Data Processing Addendum

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Publish Change management evidenceAI System 2545
+3Publish Testing & evaluation evidenceAI System 2545
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 5070
+2Have Customer data treatment disclosures independently corroboratedData 6580
+2Complete the Legal & contractual transparency disclosureLegal Contractual 4060

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 53 → up to 75 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURENotionNotionNotion AINotion AIOpenAIOpenAIAnthropicAnthropicAWSAWS
View as list
Notion Uses AI Service Notion AI
Notion AI Contracted Subprocessor OpenAI
Notion AI Contracted Subprocessor Anthropic
Notion AI Uses Infrastructure AWS

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 6 — registry checks and verification ladders, click to view
SOC 2 Type IIVendor claimed only

Stated as an annual third-party audit. No report or scope statement was readable — the trust centre gates documents behind request-access.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001Vendor claimed only

A certificate is listed in the trust centre behind a request-access gate, so neither the certificate nor its scope could be read.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27701Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

BSI C5Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

HIPAAVendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

Sources 12 — click to view
Notion AI security & privacy practices | Notion Help – Notion Help Center
AI Documentation · Vendor · retrieved Sep 1, 2026
Notion Security & Compliance | SOC 2 Certified, trusted by Enterprises
Trust Or Security Page · Vendor · retrieved Sep 1, 2026
Security practices at Notion | Notion Help – Notion Help Center
Privacy Notice · Vendor · retrieved Sep 1, 2026
Overview - Notion Docs
Certification Or Compliance Page · Vendor · retrieved Sep 1, 2026
Docs | Notion
Product Documentation · Vendor · retrieved Sep 1, 2026
Build with Notion’s Developer Platform – Notion
Changelog Or Release Notes · Vendor · retrieved Sep 1, 2026
Rebuilding Notion’s lexical search reindexer
Technical Article · Vendor · retrieved Sep 1, 2026
Notion
AI Documentation · Vendor · retrieved Sep 1, 2026
Security update (July ’26)
Trust Or Security Page · Vendor · retrieved Sep 1, 2026
Notion
Privacy Notice · Vendor · retrieved Sep 1, 2026
Overview - Notion Docs
Product Documentation · Vendor · retrieved Sep 1, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).
Requirements for bodies auditing/certifying AIMS · Published (Jul 2025) — turns AI management systems into a certification and assessor-competence conversation. Builds on ISO/IEC 17021-1.

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.