(no title)
cinbun8 | 10 months ago
"Is Notion Mail SOC 2 compliant?"
"While Notion Mail is not currently SOC 2 compliant, we expect Notion Mail to be SOC 2 Type I compliant by GA launch."
Either the FAQ or the landing page needs an update.
cinbun8 | 10 months ago
"Is Notion Mail SOC 2 compliant?"
"While Notion Mail is not currently SOC 2 compliant, we expect Notion Mail to be SOC 2 Type I compliant by GA launch."
Either the FAQ or the landing page needs an update.
peterldowns|10 months ago
jedberg|10 months ago
No it's not. It's a new product. As you aptly pointed out, Type 2 is "over time". It's a fixed time period (at a minimum three months) that you have to be observed. That means you can't get a type 2 until you've been live for 3 months, and that's assuming you've already engaged the auditor on day one.
Given that this is a new space for them, they probably had to add new infra or policies that weren't under consideration before.
atonse|10 months ago
It might be that this particular app was not ready to be in scope for their audit or observation period, so was left out, even if it's in the same infrastructure.
It still means the app is less mature, but I wouldn't go so far as to say it's a red flag.
Either way, I'd wait for something this critical (like giving it access to my email) for a few months to have any low hanging fruit bugs worked out before jumping in.
sudonim|10 months ago
I was surprised that our auditors wanted to re-do Soc 2 for our second product rather than just apply it to the company.
1123581321|10 months ago
jy14898|10 months ago