Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Notion

Notion Vendor Cyber Rating & Cyber Score

notion.com

Notion blends your everyday work tools into one. Product roadmap? Company wiki? Meeting notes? With Notion, they're all in one place, and totally customizable to meet the needs of any workflow. It's the all-in-one workspace for you, your team, and your whole company. We humans are toolmakers by nature, but most of us can't build or modify the software we use every day — arguably our most powerful tool. Our team at Notion is on a mission to make it possible for everyone to shape the tools that shape their lives.


Notion A.I CyberSecurity Scoring

Notion
Company Information
Website:https://notion.com
Employees number:5,221
Number of followers:934,589
NAICS:5112
Industry Type:Software Development
Homepage:notion.com
Notion Risk Score (AI oriented)
Between 650 and 699
logo
NotionSoftware Development
Updated:
04/05/2026
693/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Notion Global Score (TPRM)
xxxx
logo
NotionSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Notion
NotionWeak
Current Score
693B (WEAK)
01000
2 incidents
-47 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
697Before Incident
MAY 2026
693Before Incident
APRIL 2026
697Before Incident
Vulnerability
22 Apr 2026Notion
Notion: Notion public pages found leaking user emails and profile pictures

Notion Privacy Leak Exposes User Metadata in Public Pages

693After Incident
CRITICAL-4
NOT1776839801
Notion Privacy Leak Exposes User Metadata in Public Pages A recent investigation has revealed a privacy risk in Notion, the widely used productivity platform with tens of millions of users. Cybersecurity researchers found that publicly shared pages may inadvertently expose personal metadata of collaborators, including usernames, profile images, and email addresses. The issue stems from Notion’s design when users publish pages without restrictions, the platform includes internal metadata alongside visible content. While this behavior is intentional, researchers argue that its privacy implications are often overlooked by users, who may not realize they are exposing sensitive details. The vulnerability affects both individual users and organizations that rely on Notion for public documentation, knowledge bases, or shared repositories. Any unrestricted page could potentially leak contributor data, raising concerns about unintended exposure. Notion initially defended its practices, stating that users were warned about metadata exposure during publishing. However, researchers demonstrated that these warnings were not consistently displayed in the interface. Following public backlash, the company acknowledged the issue, with spokesperson Max Schoening calling the current behavior "unacceptable." Notion is now exploring solutions, such as removing personal identifiers from public API responses or implementing email masking, similar to GitHub’s approach. While the company works on a fix, the incident highlights the broader risks of metadata exposure in collaborative platforms.
INCIDENT DETAILS -
TYPE
Privacy Leak
IMPACT
Data Compromised: Usernames, profile images, email addressesSystems Affected: Notion public pages and API responsesBrand Reputation Impact: Public backlash and reputational damageIdentity Theft Risk: Potential risk due to exposed email addresses and personal identifiers
DATA BREACH
Type Of Data Compromised: Metadata (usernames, profile images, email addresses)Sensitivity Of Data: Personally identifiable informationPersonally Identifiable Information: Yes
MARCH 2026
785Before Incident
Breach
20 Mar 2026Notion
Notion, Slack, Google, Zoom, Nikkei and Workday: Your work apps are quietly handing 19 data points to someone

Workplace Apps Collect Extensive User Data, Raising Privacy and Security Concerns

695After Incident
CRITICAL-90
WORNOTGOOZOONIKTIN1777868873
Workplace Apps Collect Extensive User Data, Raising Privacy and Security Concerns A recent study by Incogni, analyzing data from the Google Play Store as of March 20, 2026, reveals that ten widely used workplace apps including Gmail, Microsoft Teams, Zoom Workplace, Slack, and Notion collect an average of 19 data points per app, with some sharing sensitive information with third parties. These apps, cumulatively downloaded over 12.5 billion times, are integral to U.S. corporate operations but pose significant privacy and security risks. Data Collection and Sharing Practices Gmail leads in data harvesting, collecting 26 distinct data types, including approximate location, app interactions, and user IDs for advertising. Microsoft Teams and Zoom Workplace follow closely, with 25 and 23 data types, respectively both uniquely gathering precise location data. Six of the ten apps, including Slack, Notion, and Zoom Workplace, use collected data for marketing, with Slack, Todoist, and Notion specifically harvesting employee email addresses for this purpose. Notion stands out for its outbound data flow, sharing eight data types such as email addresses, names, and device IDs with third parties, including advertising partners. The app’s privacy policy permits tracking tools on user browsers, raising concerns over the exposure of sensitive workspace content like HR records and client data. Regulatory scrutiny has intensified, particularly after the EU’s Data Protection Board tightened GDPR requirements in December 2024 regarding personal data use in AI training, directly impacting Notion’s third-party model integrations. Security Vulnerabilities and Breach History Most apps in the study have a history of breaches. In January 2026, a 96-gigabyte database containing 149 million login credentials 48 million tied to Gmail was exposed, attributed to infostealer malware on user devices. Slack suffered a November 2025 breach where attackers used stolen credentials to access accounts of over 17,000 Nikkei employees, exposing names, emails, and chat histories. Trello, Zoom, and Microsoft products have also faced incidents, with Trello data appearing for sale in January 2024. Workday is the only app in the analysis without a user data deletion option, despite holding employment records and payroll details. In August 2025, the platform confirmed two breaches linked to its Salesforce CRM, where attackers obtained business contact information as part of a ShinyHunters social engineering campaign. BYOD Risks and Platform Disparities Many employees install these apps on personal devices, exposing contact details, financial data, and location information to advertising networks or corporate administrators. Slack, for example, lacks end-to-end encryption, allowing workspace owners to access direct messages and private channels. While the study focuses on Google Play data, Incogni notes that iOS disclosures may differ, though past comparisons suggest similar privacy practices across platforms. The findings highlight the trade-offs between workplace productivity and data exposure, with recurring breaches and extensive tracking underscoring the risks of integrating these tools into daily operations.
INCIDENT DETAILS -
TYPE
Data CollectionPrivacy ViolationData Breach
MOTIVATION
Data Harvesting for AdvertisingFinancial GainEspionage
IMPACT
Login CredentialsEmail AddressesNamesChat HistoriesEmployment RecordsPayroll DetailsDevice IDsLocation DataGmailMicrosoft TeamsZoom WorkplaceSlackNotionTrelloWorkdayOperational Impact: Exposure of sensitive workspace content and corporate dataBrand Reputation Impact: Increased regulatory scrutiny and loss of user trustGDPR ViolationsPotential FinesIdentity Theft Risk: High
DATA BREACH
Login CredentialsEmail AddressesNamesChat HistoriesEmployment RecordsPayroll DetailsDevice IDsLocation Data149 million (Gmail-related)17,000 (Slack)Sensitivity Of Data: HighData Exfiltration: YesData Encryption: Lacking in some cases (e.g., Slack)Email AddressesNamesEmployment RecordsPayroll Details
FEBRUARY 2026
785Before Incident
JANUARY 2026
785Before Incident
DECEMBER 2025
785Before Incident
NOVEMBER 2025
785Before Incident
OCTOBER 2025
785Before Incident
SEPTEMBER 2025
785Before Incident
AUGUST 2025
785Before Incident
JULY 2025
785Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Notion ?
?
What was Notion's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Notion's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Notion's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Notion's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Notion's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Notion's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Notion's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Notion's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Notion's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Notion's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Notion's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Notion's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Notion ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Notion's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?