Canva

canva.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
63 / 100C
Procurement decision
Approve with conditions
2 conditions outstanding
  • No clear commitment that your data will not train their models
  • Underlying model providers not named

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedPrivacy Policyretrieved Aug 28, 2026
to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings
Vendor publishedCanva Shield - Ensuring safe AI use at Canvaretrieved Aug 28, 2026
You are in control of whether we train on your private content. We will always handle your data in line with our commitments in our Privacy Policy and, if applicable our Data Processing Addendum.
Underlying model providers not namedCondition

Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.

What to ask for: Require named providers and model versions, plus notice before any model change.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

The privacy policy discloses that user data may be used to train Canva’s algorithms, models and AI products, manageable through privacy-control settings.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPrivacy Policyretrieved Aug 28, 2026
to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings
Vendor publishedCanva Shield - Ensuring safe AI use at Canvaretrieved Aug 28, 2026
You are in control of whether we train on your private content. We will always handle your data in line with our commitments in our Privacy Policy and, if applicable our Data Processing Addendum.
How long do they keep your data?Clear

Users can delete or download their data in account settings and make privacy requests, with consent and opt-out for marketing and tracking.

Evidence
Vendor publishedCanva - Trust Center - Privacyretrieved Aug 28, 2026
Users can delete or download their data in their Account Settings and make other privacy requests (such as to access their data) at [email protected].
Who else can access your data?Clear

Canva maintains a sub-processor list tied to its DPA, with a notification sign-up; the register itself sits behind a versioned link.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
Externally corroboratedcontent-management-files.canva.comretrieved Aug 28, 2026
Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.
Vendor publishedcontent-management-files.canva.comretrieved Aug 28, 2026
***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.
!Where is your data processed?Ask the vendor

Canva discloses cross-border transfers with technical, organisational and contractual safeguards where destination laws are less strict.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedCanva - Trust Center - Privacyretrieved Aug 28, 2026
Whenever Canva transfers your data to a place other than where you live (especially if it has less strict privacy laws), we ensure adequate technical, organizational and contractual safeguards are in place.
What happens in a security incident?Clear

Threat detection, logging and alerting systems notify on-call teams about potential incidents.

Evidence
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
Our threat detection, logging and alerting systems notify our oncall teams about potential incidents.

Key findingsclick a row for the evidence

!Training on user content is disclosed with a control, and the default mattersGap

The privacy policy discloses training of Canva’s models on user data, manageable via privacy settings; Canva Shield frames this as user control over private content.

Whether the training setting is on or off by default determines the real posture for most users and teams.

Question for vendor: What is the default state of the AI training privacy control for individual, team and enterprise accounts?

Evidence
Vendor publishedPrivacy Policyretrieved Aug 28, 2026
to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings
Vendor publishedCanva Shield - Ensuring safe AI use at Canvaretrieved Aug 28, 2026
You are in control of whether we train on your private content. We will always handle your data in line with our commitments in our Privacy Policy and, if applicable our Data Processing Addendum.
Security fundamentals are well evidencedStrong

SOC 2 Type II and ISO 27001 with external audits, bug bounty, VDP and CVE bulletins on the trust portal, encryption detail, and staged secure development.

The platform security baseline underneath the AI features is demonstrably mature.

Evidence
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
Is your platform security externally audited? Yes. Canva is SOC2 Type II compliant and is ISO 27001 certified, which requires us to have periodic external audits of our information security management system and security controls.
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
We run a bug bounty program and provide ways for security researchers to notify us of vulnerabilities in our products and environments.
Vendor publishedcanva.comretrieved Aug 28, 2026
# Bug bounty Contact: https://canva.com/security/bug-bounty # Vulnerability disclosure policy Policy: https://canva.com/security/vulnerability-disclosure # Trust documentation and security bulletins (including CVEs) Policy: https://trust.canva.com
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
In transit, designs are only accessible via TLS/SSL, and at rest, designs are encrypted with AES256.
!No model providers are namedGap

None of the collected pages names the foundation models or providers behind the AI features; the sub-processor register sits behind a versioned link that did not resolve to content.

The data-flow question cannot be closed without knowing whose models process user content.

Question for vendor: Which model providers or self-hosted models power the AI features, and where are they listed?

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
Externally corroboratedcontent-management-files.canva.comretrieved Aug 28, 2026
Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.
Vendor publishedcontent-management-files.canva.comretrieved Aug 28, 2026
***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
Externally corroboratedcontent-management-files.canva.comretrieved Aug 28, 2026
Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.
Vendor publishedcontent-management-files.canva.comretrieved Aug 28, 2026
***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
Externally corroboratedcontent-management-files.canva.comretrieved Aug 28, 2026
Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.
Vendor publishedcontent-management-files.canva.comretrieved Aug 28, 2026
***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedCanva - Trust Center - Privacyretrieved Aug 28, 2026
Strict Internal policies - On how we handle, secure and retain user data and respond to incidents. We also maintain up-to-date records of our data processing activities and data flows.
AI system15% of the score33
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedCanva Shield - Ensuring safe AI use at Canvaretrieved Aug 28, 2026
Canva Shield is our industry-leading collection of robust trust,
Vendor publishedAI Product Termsretrieved Aug 28, 2026
you retain your ownership rights to your Input, and you own your Output,
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
We peer review and test our code prior to release, including manual and automated checks for security issues.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

AI system description: vendor-evidenced, not yet independently corroborated.

Change management: not publicly evidenced.

Model10% of the score0
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Not Evidenced

Model provider transparency: not publicly evidenced.

Customer data15% of the score72
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedPrivacy Policyretrieved Aug 28, 2026
to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings
Vendor publishedCanva Shield - Ensuring safe AI use at Canvaretrieved Aug 28, 2026
You are in control of whether we train on your private content. We will always handle your data in line with our commitments in our Privacy Policy and, if applicable our Data Processing Addendum.
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
In transit, designs are only accessible via TLS/SSL, and at rest, designs are encrypted with AES256.
Vendor publishedCanva - Trust Center - Privacyretrieved Aug 28, 2026
Users can delete or download their data in their Account Settings and make other privacy requests (such as to access their data) at [email protected].
Vendor publishedCanva - Trust Center - Privacyretrieved Aug 28, 2026
Whenever Canva transfers your data to a place other than where you live (especially if it has less strict privacy laws), we ensure adequate technical, organizational and contractual safeguards are in place.
Vendor publishedAI Product Termsretrieved Aug 28, 2026
you retain your ownership rights to your Input, and you own your Output,

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Vendor publishedCanva's Sub-Processorsretrieved Aug 28, 2026
Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum ⁠ (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.
Externally corroboratedcontent-management-files.canva.comretrieved Aug 28, 2026
Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.
Vendor publishedcontent-management-files.canva.comretrieved Aug 28, 2026
***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.
Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
We run a bug bounty program and provide ways for security researchers to notify us of vulnerabilities in our products and environments.
Vendor publishedcanva.comretrieved Aug 28, 2026
# Bug bounty Contact: https://canva.com/security/bug-bounty # Vulnerability disclosure policy Policy: https://canva.com/security/vulnerability-disclosure # Trust documentation and security bulletins (including CVEs) Policy: https://trust.canva.com
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
Our threat detection, logging and alerting systems notify our oncall teams about potential incidents.

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score85
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedSecurity at Canvaretrieved Aug 28, 2026
Is your platform security externally audited? Yes. Canva is SOC2 Type II compliant and is ISO 27001 certified, which requires us to have periodic external audits of our information security management system and security controls.

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Registry verifiedBSI Client Directory record — ISO/IEC 27001retrieved Aug 21, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.

Independent assurance: vendor-evidenced, not yet independently corroborated.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedAI Product Termsretrieved Aug 28, 2026
you retain your ownership rights to your Input, and you own your Output,
Vendor publishedAI Product Termsretrieved Aug 28, 2026
it is prohibited to use AI Products to: Mislead anyone that the content generated by AI Products is human-generated;
Vendor publishedCanva - Trust Center - Privacyretrieved Aug 28, 2026
Canva offers a Data Processing Addendum ⁠ (opens in a new tab or window) (DPA) that is automatically incorporated into your agreement with us.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Publish Change management evidenceAI System 3353
+3Complete the Governance & accountability disclosureOrganisation 4060
+3Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 85100
+2Have Customer data treatment disclosures independently corroboratedData 7287
+2Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 85100

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 63 → up to 81 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURECanvaCanvaCanva AICanva AICanva ShieldCanva ShieldAnthropic PBCAnthropic PBCElevenLabs Inc.ElevenLabs Inc.Features & Labels, Inc.Features & Labels, Inc.Google LLCGoogle LLCNanonoble Pte. Ltd.Nanonoble Pte. Ltd.OpenAI, LLCOpenAI, LLCAmazon Web Services, Inc.Amazon Web Services, Inc.MongoDB, Inc.MongoDB, Inc.Snowflake Inc.Snowflake Inc.
View as list
Canva Uses Infrastructure Amazon Web Services, Inc.
Canva Uses AI Service Anthropic PBC
Canva Uses AI Service ElevenLabs Inc.
Canva Uses AI Service Features & Labels, Inc.
Canva Uses AI Service Google LLC
Canva Uses Infrastructure MongoDB, Inc.
Canva Uses AI Service Nanonoble Pte. Ltd.
Canva Uses AI Service OpenAI, LLC
Canva Uses Infrastructure Snowflake Inc.

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 7 — registry checks and verification ladders, click to view
SOC 2Vendor claimed only

SOC 2 Type II stated with periodic external audits.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001Claimed & corroborated

ISO/IEC 27001:2022, certificate IS 826967 issued by BSI. Scope covers the Canva suite and Flourish; certified sites in Sydney, Manila (Canva Solutions Inc), Austin (Canva US, Inc.) and London (Canva UK Operations Ltd).

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil May 27, 2029

Checked against BSI certificate IS 826967 held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

Checked against IAF CertSearch and the BSI Client Directory, operator-run searches, Sep 1, 2026: Not found on the registry (not every certification body publishes there — ask the vendor for the certificate)

SOC 2 Type IIClaimed & corroborated

SOC 2 Type 2 by Sekuro (an Insight company): Canva Free, Pro, Business and Enterprise; trust services criteria security, availability, confidentiality and privacy; period 14 Apr 2025 - 13 Apr 2026; unqualified opinion. Vault: Gated/Canva/2026-06_canva-soc2-type2-sekuro.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry

SOC 3Claimed & corroborated

SOC 3 report by Sekuro (an Insight company), signed by Peter Sheville of C&N Audit Services, 5 June 2026: Canva Free, Pro, Business and Enterprise; trust services criteria security, availability, confidentiality and privacy; period 14 Apr 2025 - 13 Apr 2026; unqualified conclusion. Same period, scope and criteria as the corroborated SOC 2 Type 2 - the SOC 3 is its general-use counterpart, not additional assurance. NOTE: the document also quotes the TSP Section 100 title, which lists five criteria including processing integrity; processing integrity is NOT in this engagement's scope. Vault: Gated/Canva/2026-06_canva-soc3-sekuro.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 3 report held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry

PCI DSSClaimed & corroborated

MERCHANT Attestation of Compliance (PCI DSS v4.0.1): attests Canva's own card-payment acceptance environment, NOT services provided to customers as a PCI service provider. Overall COMPLIANT; RoC dated 23 Sep 2025, assessment ended 15 Aug 2025; QSA Sekuro Pty Ltd. Annual cycle. Vault: Gated/Canva/2025-09_canva-pci-dss-v401-aoc-merchant.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against PCI DSS v4.0.1 Attestation of Compliance held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry

EU-U.S. Data Privacy FrameworkClaimed & corroborated

EU-U.S., Swiss-U.S. and UK Extension all Active; Non-HR Data. Verified on the official participant list, 20 Aug 2026.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

Sources 31 — click to view
AI Product Terms
AI Documentation · Vendor · retrieved Aug 28, 2026
Canva - Trust Center
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Canva's Sub-Processors
Subprocessor List · Vendor · retrieved Aug 28, 2026
Privacy Policy
Privacy Notice · Vendor · retrieved Aug 28, 2026
Legal Trust Center
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Canva Docs - Free & Easy Online Document Editor
Product Documentation · Vendor · retrieved Aug 28, 2026
Login to your Canva account
AI Documentation · Vendor · retrieved Aug 28, 2026
Security at Canva
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Canva - Trust Center - Privacy
Privacy Notice · Vendor · retrieved Aug 28, 2026
Free AI Image Generator: Text to Image | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
https://www.canva.com/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
AI Photo Editor - Instant Photo Editing with AI | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
Free AI Art Generator - Online Text to Artwork App | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
AI Video Generator: Text to Video AI Tool | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
AI Music Generator: Create songs using AI | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
AI Voice Generator: Text to Speech Online | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
Canva AI: Your all-in-one AI assistant
AI Documentation · Vendor · retrieved Aug 28, 2026
AI Code Generator: Transform your designs with coding-free creations | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
AI data analysis: get quick insights from your data | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
Free Formula Generator: Get the right spreadsheet formula | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
Canva AI 2.0 – AI design, writing, and creative tools | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
The State of Marketing and AI Report 2026 | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
Canva Shield - Ensuring safe AI use at Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
Free Online AI Logo Generator: | Canva
AI Documentation · Vendor · retrieved Aug 28, 2026
U.S. Department of Commerce Data Privacy Framework list record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 20, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
BSI Client Directory record — ISO/IEC 27001
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (supplied by Canva) record — SOC 2 Type II
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
PCI DSS v4.0.1 Attestation of Compliance held in the TrustyCyber vault (supplied by Canva) record — PCI DSS
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
SOC 3 report held in the TrustyCyber vault (supplied by Canva) record — SOC 3
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Canva at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.