Skip to main content

Understanding SOC 2 for Super and Notion

Written by Charlene
Updated yesterday

When evaluating the security of your website or SaaS setup, it’s natural to look for certifications like SOC 2. This is especially relevant for users building sites with Super, where content is powered by Notion behind the scenes. Here’s how it all fits together.

Super and SOC 2 Compliance

At this time, Super is not independently SOC 2 certified.

Our legal and privacy documentation reflects this clearly:

  • We reference the certifications of the underlying platform, rather than listing standalone certifications for Super itself

  • Currently, there is no downloadable attestation or certification report publicly available for Super

This means that if your review process strictly requires a vendor-issued SOC 2 report, Super does not currently provide one.

Where Your Data Actually Lives

To understand the security model, it’s important to look at how Super works.

Super acts as a layer on top of Notion, which serves as:

  • The content management system (CMS)

  • The data host for your pages

In other words, your content, data, and infrastructure are fundamentally handled by Notion.

Notion’s Security Certifications

Notion maintains strong security and compliance standards, including:

  • SOC 2 Type II certification

  • ISO 27001 certification

  • Additional security controls and internal practices

These certifications confirm that Notion’s systems and processes have been independently audited and meet widely recognized standards for data protection and operational security.

What This Means for Security Reviews

If your assessment is focused on data security, you can rely on:

  • Notion’s publicly available trust and compliance documentation

  • Their independently audited controls and certifications

Since Notion is the system that stores and processes your data, its certifications are typically the most relevant in evaluating risk.

Privacy and Legal Documentation

For more details on how data is handled within Super, you can review our official documentation:

  • Article: Privacy Policy

This provides a deeper look into how Super operates in relation to user data, privacy, and platform responsibilities.

Did this answer your question?