Trust Center

Documents & Resources

Every security, privacy, and compliance document we publish, in one place. Public policies are linked directly below. Restricted artifacts are listed so you can see exactly what exists; enterprise customers download them from the NotAI dashboard, and everyone else can request access.

Restricted documents are downloaded from the Documents section of the NotAI dashboard by enterprise customers. If your organization needs one of the documents below and does not have an enterprise account, request access and we will follow up by email.

Request access

Public documents

These documents are published for everyone. Legal policies live on the main NotAI site; the subprocessor list and vulnerability disclosure policy live here in the Trust Center.

Privacy Policy

How NotAI collects, uses, and protects personal data across the platform.

Web page - public

Terms of Service

The agreement that governs use of the NotAI platform and services.

Web page - public

Data Processing Agreement

Our DPA with EU Standard Contractual Clauses and the UK IDTA, applicable to all customers.

Web page - public

AI Transparency Notice

Our EU AI Act Article 50 transparency disclosure describing how NotAI detection works.

Web page - public

NY Parents' Bill of Rights

Our Parents' Bill of Rights notice under New York Education Law Section 2-d.

Web page - public

Subprocessor List

Every third-party subprocessor we use, with purpose, location, and safeguards.

Web page - public

Vulnerability Disclosure Policy

How to report a security issue to NotAI, and the safe harbor we extend to researchers.

Web page - public

Restricted documents

These artifacts are listed publicly so you can see what exists, but downloads are limited to enterprise customers and approved reviewers. Enterprise customers can download them from the Documents section of the NotAI dashboard. Everyone else can request access by email.

SOC 2 Type II report

Independent service auditor's report covering our security, availability, and confidentiality controls. The attestation is refreshed annually.

PDF - NDA required

Penetration test executive summary

Executive summary of independent penetration testing of the platform, covering scope, methodology, and remediation status. Shared under NDA.

PDF - NDA required

HECVAT Full

HECVAT Full questionnaire response for higher-education vendor security reviews.

Spreadsheet - NDA required

HECVAT Lite

HECVAT Lite questionnaire response for streamlined vendor reviews.

Spreadsheet - NDA required

Accessibility report (VPAT)

Accessibility conformance report covering WCAG 2.1 and Section 508 for the dashboard and student-facing surfaces.

PDF - Available on request

CAIQ Lite

CAIQ Lite questionnaire response mapped to CSA Cloud Controls Matrix domains.

Spreadsheet - NDA required

Architecture & data-flow diagrams

Architecture and data-flow diagrams showing how detection data moves through the platform.

PDF - NDA required

BC/DR summary

Summary of business continuity and disaster recovery planning, including recovery time and recovery point objectives.

PDF - Available on completion

Cyber liability insurance certificate

Certificate of insurance for cyber liability coverage.

PDF - Available on request

Incident response plan summary

Summary of our incident response plan, covering roles, severity classification, and customer notification.

PDF - NDA required

DPIA support pack

Supporting materials for institutional data protection impact assessments and privacy reviews.

PDF - NDA required

W-9

Completed IRS Form W-9 for procurement and vendor onboarding.

PDF - Available on request

Need a restricted document?

Email us your name, work email, and organization, and we review the request within two business days. Approved reviewers accept a click-through NDA, and documents are delivered in the dashboard through watermarked, expiring links - never permanent URLs.

Request access