<aside>

Why customers trust Notion
Security, privacy, and admin controls are built into Notion’s architecture, operations, and product, so teams can collaborate with confidence.
This document summarizes Notion's security, privacy, and compliance posture for procurement and security review.
</aside>
<aside>
🔗 Additional Resources
For more information on our security policies, penetration test and audit reports, please refer to the following:
1. Independent assurance and compliance
Notion maintains globally and regionally recognized certifications and audit reports, including SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA, K-FSI, ISMAP and BSI C5.
Notion supports security assurance with annual third-party penetration testing, a HackerOne bug bounty program, risk-based red teaming, detailed audit reports and security documentation, and cybersecurity insurance.
2. Data protection and architecture
Notion protects Customer Data through industry-standard encryption, resilient infrastructure, continuous monitoring, and enterprise controls designed to support security and operational continuity.
- Encryption in transit and at rest. Notion encrypts data in transit using TLS 1.2 or higher and at rest using AES-256.
- Customer-managed encryption keys. Enterprise Key Management (EKM/BYOK) supports customer-managed AWS KMS keys for supported Notion data. EKM is currently available in beta and is separately priced for eligible Enterprise customers.
- Highly available infrastructure. Notion uses highly available infrastructure with multi-region failover and automated cross-region backups.
- Business continuity and disaster recovery. Notion tests its disaster recovery and business continuity plans annually. The estimated recovery point objective (RPO) is 24 hours, while the recovery time objective (RTO) is determined based on the nature and scope of the incident.
- Continuous security monitoring. Notion continuously monitors endpoints, cloud infrastructure, containers, database access, and elevated access to detect threats, investigate unusual activity, and protect Customer Data.
3. Product security controls
🔑 Authentication and access
- SAML SSO and SCIM provisioning. Centralize authentication and user lifecycle management, reducing manual admin work and access drift.
- Multi-factor authentication and passkeys. Multi-layered approach for protection against credential compromise.
- Inactivity-based session duration. Reducing exposure from unattended or shared services.
- IP address access controls. Restrict access to approved networks, adding another layer of protection for sensitive workspaces.
- New device login alerts. Identification of unusual access activity.
📊 Monitoring and logging
- SIEM partner integrations. Enables routing of audit logs for centralized logging and monitoring.
- DLP partner integrations. Identify and manage sensitive information in line with internal data protection policies.
- Content search. Locate information quickly for governance, eDiscovery, audits, or operational continuity.
🤝 External sharing and third-party access
- Guest invite requests. Review external collaboration before guests are added, reducing accidental over-sharing.
- Integration allowlisting. Control which third-party tools can connect to their workspace and limit unmanaged data flows.
- Granular admin controls. Tailor permissions to match internal policies, including controls for public sharing, guest access, export, duplication, and content movement where available.
🗄️ Data lifecycle and continuity
- Custom data retention settings. Align content retention schedules with legal, regulatory, and internal policy requirements.
- Unlimited page history. Support recovery, review, and accountability by preserving prior versions of workspace content.
- Transfer of content from de-provisioned users. Preserve business records and continuity when employees leave the organization.
- Managed user visibility and controls. Provide oversight of managed users so administrators can govern access and account ownership more effectively.
4. AI data handling and governance
Notion AI is designed to help customers work with their existing content while maintaining the security, privacy, and access controls of their workspace. The safeguards below explain how Customer Data is handled, how access is governed, and what controls are available to administrators.
- Customer Data is not used for model training. By default, neither Notion nor its subprocessors use Customer Data to train models. Customer content submitted to Notion AI is processed to provide the requested feature, subject to Notion’s contractual, privacy, and security commitments.
- Enterprise zero data retention. For Enterprise workspaces, Notion’s default LLM providers use zero data retention. Prompts and outputs are processed to provide the service but are not retained by those providers after processing.