When evaluating the security of your website or SaaS setup, it’s natural to look for certifications like SOC 2. This is especially relevant for users building sites with Super, where content is powered by Notion behind the scenes. Here’s how it all fits together.
Super and SOC 2 Compliance
At this time, Super is not independently SOC 2 certified.
Our legal and privacy documentation reflects this clearly:
We reference the certifications of the underlying platform, rather than listing standalone certifications for Super itself
Currently, there is no downloadable attestation or certification report publicly available for Super
This means that if your review process strictly requires a vendor-issued SOC 2 report, Super does not currently provide one.
Where Your Data Actually Lives
To understand the security model, it’s important to look at how Super works.
Super acts as a layer on top of Notion, which serves as:
The content management system (CMS)
The data host for your pages
In other words, your content, data, and infrastructure are fundamentally handled by Notion.
Notion’s Security Certifications
Notion maintains strong security and compliance standards, including:
SOC 2 Type II certification
ISO 27001 certification
Additional security controls and internal practices
These certifications confirm that Notion’s systems and processes have been independently audited and meet widely recognized standards for data protection and operational security.
What This Means for Security Reviews
If your assessment is focused on data security, you can rely on:
Notion’s publicly available trust and compliance documentation
Their independently audited controls and certifications
Since Notion is the system that stores and processes your data, its certifications are typically the most relevant in evaluating risk.
Privacy and Legal Documentation
For more details on how data is handled within Super, you can review our official documentation:
Article: Privacy Policy
This provides a deeper look into how Super operates in relation to user data, privacy, and platform responsibilities.
