Notion data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Notion, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Notion connector needs.
Checks (7)
severity: high Publicly Shared Page fix difficulty: easy #
Disable public web sharing for the flagged Notion page
- Open the flagged Notion page
- Click the Share button in the top-right corner
- Toggle off Share to web
- Confirm the change in the dialog if prompted
- Review other pages in the same workspace for similar public sharing settings
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Stale Public Page fix difficulty: easy #
Update or disable public sharing for stale publicly accessible pages
- Open the flagged Notion page
- Review the content to determine if it is still relevant and should remain public
- If the content is outdated or should not be public, click the Share button
- Toggle off Share to web
- If the page is still needed publicly, update its content and last-edited date
- Consider setting a reminder to review public pages periodically
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Publicly Shared Database fix difficulty: easy #
Disable public web sharing for the flagged Notion database
- Open the flagged Notion database
- Click the Share button in the top-right corner
- Toggle off Share to web
- Confirm the change if prompted
- Review all linked views and inline databases on the same page to ensure they are also not publicly shared
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Root Level Public Page fix difficulty: easy #
Move publicly shared pages out of the workspace root or disable public sharing
- Open the flagged Notion page at the workspace root
- Evaluate whether the page should remain publicly shared
- If not needed publicly, click Share and toggle off Share to web
- If it must remain public, move it into a dedicated Public section for better organization
- Ensure no sensitive internal content is exposed through the public page
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Stale Publicly Shared Database fix difficulty: easy #
Update or disable public sharing for databases not edited in over 90 days
- Open the flagged Notion database
- Review the content to determine if it should remain publicly shared
- If outdated, click Share and toggle off Share to web
- If still needed publicly, update the database content to keep it current
- Consider setting a reminder to review publicly shared databases periodically
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Root Level Public Database fix difficulty: easy #
Move publicly shared databases out of the workspace root or disable public sharing
- Open the flagged Notion database at the workspace root
- Evaluate whether the database should remain publicly shared
- If not needed publicly, click Share and toggle off Share to web
- If it must remain public, move it into a dedicated Public section for better organization
- Ensure no sensitive structured data is exposed through the public database
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Inline Public Database fix difficulty: easy #
Disable public sharing for inline databases that may expose structured data
- Open the parent page containing the flagged inline database
- Click the Share button on the parent page
- Toggle off Share to web if the inline database should not be publicly accessible
- If only the parent page should be public, consider moving sensitive data to a separate private database
- Review all inline databases on the page for similar exposure
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12