資訊安全措施
我們深知您將寶貴的資料託付給我們,因此我們非常重視其安全性。我們已針對自身的安全實務提供了深入的說明 🔒
跳至常見問題存取監控: Notion 已在所有關鍵系統上啟用記錄檔功能。記錄檔內容包含失敗/成功的登入、應用程式存取、管理員變更與系統變更。記錄檔會由我們的可觀測性與安全事件管理 (SIEM) 解決方案進行擷取,以提供記錄檔擷取與自動化記錄檔/警示功能。
已啟用備份:Notion 由 AWS 託管,並結合多種資料庫來儲存客戶資料。AWS 預設提供耐用的基礎架構來儲存重要資料,其設計目標為 99.9% 的物件耐用性。系統已啟用所有客戶與系統資料的自動備份,且資料至少每日備份一次。備份資料的加密方式與即時生產資料相同,並受到監控與警示。
靜態資料加密: 客戶資料在靜態時使用 AES-256 進行加密。客戶資料在 Notion 內部網路傳輸時、在雲端儲存空間、資料庫表格與備份中處於靜態時,皆會進行加密。
傳輸中資料加密: 傳輸中的資料使用 TLS 1.2 或更高版本進行加密。
實體安全: Notion 利用 Amazon Web Services (AWS) 來託管我們的應用程式,並將所有資料中心的實體安全控制委託給他們。請參閱 AWS 的實體安全控制此處。
負責任的揭露: Notion 維護著一個漏洞獎勵計畫。請參閱我們的 負責任揭露政策。
程式碼分析: Notion 的安全與開發團隊會針對新版本與更新進行威脅建模與安全設計審查。在完成重大功能發布的程式碼後,我們會執行程式碼稽核、程式碼審查,並針對我們的程式碼庫進行安全掃描。
軟體開發生命週期 (SDLC): Notion 使用定義明確的 SDLC 來確保程式碼編寫的安全性。在設計階段,我們會針對新版本與更新執行安全威脅建模與安全設計審查。在完成重大功能發布的程式碼後,我們會執行程式碼稽核、與供應商公司合作或推動內部滲透測試,並針對我們的程式碼庫進行安全掃描。發布後,我們會舉辦漏洞獎勵計畫,並設有漏洞管理計畫來處理嚴重的安全問題。
憑證管理: Notion 使用第三方金鑰管理服務 (KMS),該服務會自動管理金鑰產生、存取控制、安全儲存、備份與金鑰輪替。加密金鑰會根據最小權限存取原則分配給特定角色,且金鑰會每年自動輪替。金鑰的使用受到監控與記錄。
漏洞與修補程式管理: Notion 會對所有基礎架構相關的主機以及公司產品持續執行漏洞掃描與套件監控。對外與對內的服務皆會定期進行修補。任何發現的問題都會根據 Notion 環境內的嚴重程度進行分類與解決。
網頁應用程式防火牆 (WAF): 所有公開端點皆利用託管式網頁應用程式防火牆來防禦利用常見漏洞的攻擊嘗試。
資料存取層級: 內部(即 Notion 員工僅會在為您排解問題或復原內容時存取您的資料。)
第三方依賴: 是 - 請參閱我們的轉包處理器列表 此處。
託管: Notion 託管於 Amazon Web Services (AWS) 上,這是主要的雲端服務供應商之一。
員工培訓: 員工在入職流程中必須接受安全培訓,之後每年也需接受一次。員工還必須閱讀並確認 Notion 的行為準則與安全政策。開發人員培訓亦至少每年進行一次。
人力資源安全: Notion 在聘僱員工時,會依據當地法律法規進行背景調查。
事件回應: Notion 設有事件管理計畫,其中包含準備、識別、圍堵、調查、根除、復原與後續追蹤/事後檢討的步驟,並至少每年進行一次審查與測試。
內部評估: Notion 至少每年執行一次內部安全稽核。
內部單一登入 (SSO): 所有 Notion 員工登入 Notion 的身分識別提供者時,皆須進行多因素驗證 (MFA)。
資料存取: Notion 在內部運用「最小權限原則」進行存取。存取權限是根據職務功能、業務需求與「知情必要」原則授予。我們會定期進行存取審查,以確保對關鍵系統的持續存取權限仍有其必要性。
記錄檔管理: Notion 利用 SIEM 解決方案進行記錄檔擷取與自動化記錄檔及警示。記錄檔會從關鍵系統中擷取,並利用警示規則確保在必要時產生安全事件警示。
密碼安全: Notion 要求所有提供多重驗證 (MFA) 選項的系統皆須啟用多重驗證 (MFA)。若無法進行此類委派,Notion 會維持嚴格的內部密碼管理政策,包含複雜度與長度要求。
防禦 DDoS: Notion 利用第三方應用程式進行 DDoS 防護。
資料中心: Notion 託管於 AWS,由其處理資料中心的實體安全。請參閱 AWS 的安全文件 此處。
獨立的生產環境: 客戶資料絕不會儲存在非生產環境中。客戶帳戶在我們的生產環境中進行邏輯隔離。我們擁有獨立的開發、測試和生產環境。
磁碟加密: 員工筆記型電腦已啟用磁碟加密以提供保護。
端點偵測與回應: 所有端點皆已安裝偵測軟體。此外,Notion 已實施多項安全控制措施,以確保客戶資料與解決方案的安全。這些控制措施確保我們能持續掌握端點的運作狀況,並能針對任何竄改或威脅快速偵測與反應,同時具備記錄檔與強制執行控制功能。
行動裝置管理: 員工裝置及其軟體配置由 IT 與安全團隊透過 MDM 軟體進行遠端管理。
威脅偵測: Notion 使用第三方端點防護軟體進行專門的威脅偵測。該端點軟體可偵測端點上的入侵、惡意軟體與惡意活動,並協助快速反應以消除與減輕威脅。
防火牆: Notion 辦公室網路配置有網路防火牆。WAN 可存取的網路服務不得託管於辦公室環境內。
IDS/IPS:Notion 採用網路與主機型 IDS/IPS 混合系統,作為組織防禦深度安全策略的一部分。這包括透過特徵碼與異常偵測的組合來監控可疑活動。
安全資訊與事件管理 (SIEM):Notion 採用 SIEM 解決方案進行事件管理。事件通知會即時傳達給我們的安全人員。
無線網路安全:Notion 辦公室對辦公室無線網路使用強加密技術。Notion 不維護任何會影響客戶資料或生產系統的無線網路。
網域管理:網域指的是與 Notion 帳號關聯的電子郵件地址網域。網域驗證允許工作空間擁有者主張網域的擁有權,進而解鎖網域管理設定。
SAML 單一登入 (SSO):Notion 為商業版與企業版客戶提供單一登入 (SSO) 功能,以便透過單一驗證來源存取應用程式。
SCIM 佈建與撤銷:Notion 工作空間支援跨網域身分管理系統 (SCIM) API 標準。
稽核記錄檔:Notion 讓工作空間擁有者能夠存取權限有關安全與安全相關活動的詳細資訊。這包括識別潛在的安全問題、調查可疑行為以及排解存取權限問題。
2FA (MFA):Notion 提供雙重驗證,為您的 Notion 帳號增加額外的保護層。此功能適用於所有方案類型,並可在您的帳號設定中輕鬆設定。
管理權限:Notion 允許擁有者控制其權限層級,確保使用者能完全依照您期望的方式檢視並與您的內容互動。
管理團隊協作區:工作空間擁有者可以概覽工作空間中的所有團隊協作區、修改其設定,並存取額外的管理工具。
SIEM 與 DLP 整合:Notion 可與您選擇的 DLP 或 SIEM 整合以偵測事件。
Notion 維護一套全面的安全與隱私權計畫,提供先進的安全功能,旨在根據各種法規與產業標準保護您的資料。若要取得 Notion 的獨立稽核報告(例如 SOC 2 Type II 稽核報告、ISO 27001 證書),請造訪我們的 信任中心。
SOC 2 Type 2:SOC 2 Type 2 是一份由美國會計師公會 (AICPA) 認證的獨立第三方所執行之稽核報告,旨在評估服務組織與信任服務準則 (TSC) 相關的控制措施。SOC 2 Type 2 報告會評估這些控制措施在一段時間內的有效性,旨在向客戶與利害關係人保證,該組織已實施適當的控制措施來保護其資料。
ISO:ISO 是一個國際標準制定組織,Notion 已取得四項 ISO 標準認證:ISO 27001、ISO 27701、ISO 27017 與 ISO 27018。這些標準概述了建立、實施並持續改進 Notion 資訊安全管理系統 (ISMS) 與隱私資訊管理系統 (PIMS) 的要求。
HIPAA:《健康保險流通與責任法案》(HIPAA) 是美國於 1996 年頒布的聯邦法律,要求醫療保健提供者、健康計畫與醫療保健交換中心等受規範實體及其業務夥伴,必須保護並保密處理受保護的醫療資訊 (PHI)。若受 HIPAA 規範的企業採用我們文章此處中所述的 Notion 企業級安全功能,並簽署 Notion 的業務夥伴協議,即可在其 Notion 工作空間內處理 PHI。
BSI C5(雲端運算合規控制目錄):BSI C5 是由德國聯邦資訊安全局開發的安全標準。它概述了雲端服務供應商的基準安全控制措施。C5 包含與資料位置、服務供應、管轄地、現有認證、資訊揭露義務及完整服務說明相關的額外控制要求。
PCI DSS:支付卡產業 (PCI) 資料安全標準 (DSS) 是一項全球資訊安全標準,旨在透過加強對信用卡資料的控制來防止詐欺。Notion 符合 PCI-DSS 商戶等級 2 的要求,確保在我們的付款處理作業中安全地處理支付卡資料。然而,我們的 PCI-DSS 合規性不適用於客戶資料,且如我們的資料處理附錄中明確指出,客戶禁止在 Notion 工作空間內輸入或儲存支付卡資訊 (PCI 資料)。
K-FSI:Notion 已成功完成韓國金融安全院 (K-FSI) 的雲端服務供應商 (CSP) 安全與防護評估,展現我們致力於滿足韓國金融業雲端服務關鍵法規要求的承諾。金融機構可審閱我們針對 SaaS 服務控制範圍的 K-FSI CSP 稽核結果,以支援其供應商風險評估與內部合規需求。
常見問題
What data does Notion process?
What data does Notion process?
Notion is committed to your safety and privacy. For detailed information on the data we process, please refer to our Data Processing Addendum.
If I decide to leave Notion, what happens to my data?
If I decide to leave Notion, what happens to my data?
For information around how long Notion will maintain data, please refer to the Data Processing Addendum.
Follow the instructions here to delete your data.
If there was a disaster with Notions Systems and my Notion Instance was impacted, how does Notion restore itself?
If there was a disaster with Notions Systems and my Notion Instance was impacted, how does Notion restore itself?
Notion performs daily automated backups of all customer and system data to protect against loss due to unforeseen events across separate availability zones in AWS US West-2 and AWS US East-2.
We have a dedicated Business Continuity Plan and Disaster Recovery Plan for these circumstances, and our Disaster Recovery Plan is tested at least annually to ensure Notion will recover from a disruption resulting from a disaster.
Can Notion employees access our information?
Can Notion employees access our information?
Notion employees will only ever access your data for the purposes of troubleshooting problems or recovering content on your behalf. Please refer to our Data Access Consent for further information.
Will other people be able to see my pages?
Will other people be able to see my pages?
Your data is safe in Notion! If someone tries to navigate to your workspace without having access, they’ll see a page that lets them know that they do not have the correct permission state to access that content.
If you enable Share to web in the Share menu at the top right of a page, it will publish that page to the web so that anyone with the link can access it. This is always turned off by default.
If you’re sharing a workspace with others, some pages will be visible to everyone in the workspace, or specific groups of people — this is based on the permissions you see in the Share menu at the top right of the page.
Please note, if you are using an account in an enterprise workspace, your content may be accessed by the workspace’s workspace owner. Learn more in our Personal Use Terms of Service.
Can I opt out of Notion's tracking/analytics?
Can I opt out of Notion's tracking/analytics?
Yes you can! This will also disable in-app message support, but you can still reach out to us for help at [email protected].
Just send a message to our support team at that address and we'll opt you out.
My browser alerted me that Notion is using trackers. What do these trackers do?
My browser alerted me that Notion is using trackers. What do these trackers do?
We use tracking code in order to effectively run ads (for example, tracking a visit to our marketing site). We isolate this to a sandboxed iframe on a subdomain (aif.app.notion.com) — it's never activated on user pages.
No user content is exposed to any third-party service.
Does Notion review findings from Third Party Risk Assessment Platforms (i.e. Security Scorecard, Bitsight, Upguard)?
Does Notion review findings from Third Party Risk Assessment Platforms (i.e. Security Scorecard, Bitsight, Upguard)?
We understand that many organizations use third-party risk assessment platforms for security due diligence. However, we’ve noticed that these platforms often produce unreliable and incorrect results, and addressing these incorrect findings is costly and distracts from important cybersecurity work. Therefore, our policy is to not always respond to inquiries or findings from these platforms. This approach allows us to focus our cybersecurity resources on what truly matters for Notion and our customers.
