Privacy Policy
How NotAI collects, uses, and protects personal data across the platform.
Trust Center
Every security, privacy, and compliance document we publish, in one place. Public policies are linked directly below. Restricted artifacts are listed so you can see exactly what exists; enterprise customers download them from the NotAI dashboard, and everyone else can request access.
Restricted documents are downloaded from the Documents section of the NotAI dashboard by enterprise customers. If your organization needs one of the documents below and does not have an enterprise account, request access and we will follow up by email.
Request accessThese documents are published for everyone. Legal policies live on the main NotAI site; the subprocessor list and vulnerability disclosure policy live here in the Trust Center.
How NotAI collects, uses, and protects personal data across the platform.
The agreement that governs use of the NotAI platform and services.
Our DPA with EU Standard Contractual Clauses and the UK IDTA, applicable to all customers.
Our EU AI Act Article 50 transparency disclosure describing how NotAI detection works.
Our Parents' Bill of Rights notice under New York Education Law Section 2-d.
Every third-party subprocessor we use, with purpose, location, and safeguards.
How to report a security issue to NotAI, and the safe harbor we extend to researchers.
These artifacts are listed publicly so you can see what exists, but downloads are limited to enterprise customers and approved reviewers. Enterprise customers can download them from the Documents section of the NotAI dashboard. Everyone else can request access by email.
Independent service auditor's report covering our security, availability, and confidentiality controls. The attestation is refreshed annually.
Executive summary of independent penetration testing of the platform, covering scope, methodology, and remediation status. Shared under NDA.
HECVAT Full questionnaire response for higher-education vendor security reviews.
HECVAT Lite questionnaire response for streamlined vendor reviews.
Accessibility conformance report covering WCAG 2.1 and Section 508 for the dashboard and student-facing surfaces.
CAIQ Lite questionnaire response mapped to CSA Cloud Controls Matrix domains.
Architecture and data-flow diagrams showing how detection data moves through the platform.
Summary of business continuity and disaster recovery planning, including recovery time and recovery point objectives.
Certificate of insurance for cyber liability coverage.
Summary of our incident response plan, covering roles, severity classification, and customer notification.
Supporting materials for institutional data protection impact assessments and privacy reviews.
Completed IRS Form W-9 for procurement and vendor onboarding.
Email us your name, work email, and organization, and we review the request within two business days. Approved reviewers accept a click-through NDA, and documents are delivered in the dashboard through watermarked, expiring links - never permanent URLs.
Request access