<aside>

Character_security_badge.png

Why customers trust Notion

Security, privacy, and admin controls are built into Notion’s architecture, operations, and product, so teams can collaborate with confidence.

This document summarizes Notion's security, privacy, and compliance posture for procurement and security review.

</aside>

<aside>

🔗 Additional Resources

For more information on our security policies, penetration test and audit reports, please refer to the following:


1. Independent assurance and compliance

Notion maintains globally and regionally recognized certifications and audit reports, including SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA, K-FSI, ISMAP and BSI C5.

Notion supports security assurance with annual third-party penetration testing, a HackerOne bug bounty program, risk-based red teaming, detailed audit reports and security documentation, and cybersecurity insurance.

2. Data protection and architecture

Notion protects Customer Data through industry-standard encryption, resilient infrastructure, continuous monitoring, and enterprise controls designed to support security and operational continuity.


3. Product security controls

🔑 Authentication and access

📊 Monitoring and logging

🤝 External sharing and third-party access

🗄️ Data lifecycle and continuity


4. AI data handling and governance

Notion AI is designed to help customers work with their existing content while maintaining the security, privacy, and access controls of their workspace. The safeguards below explain how Customer Data is handled, how access is governed, and what controls are available to administrators.