Canva AI
canva.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
- Data retention window not stated
- Underlying model providers not named
+1 more
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“you retain your ownership rights to your Input, and you own your Output,”
Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.
What to ask for: Require named providers and model versions, plus notice before any model change.
Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.
What to ask for: Pin processing regions per data classification in the contract.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
The privacy policy discloses that user data may be used to train Canva’s algorithms, models and AI products, manageable through privacy-control settings.
Requires written confirmation — see Before you sign ↓
“to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings”
!How long do they keep your data?Ask the vendor
The AI Product Terms state users retain ownership of Inputs and own Outputs, subject to a Licensed Content exception.
Requires written confirmation — see Before you sign ↓
“you retain your ownership rights to your Input, and you own your Output,”
✓Who else can access your data?Clear
Canva maintains a sub-processor list tied to its DPA, with a notification sign-up; the register itself sits behind a versioned link.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
“Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.”
“***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.”
!Where is your data processed?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
✓What happens in a security incident?Clear
Threat detection, logging and alerting systems notify on-call teams about potential incidents.
“Our threat detection, logging and alerting systems notify our oncall teams about potential incidents.”
Key findingsclick a row for the evidence
!Training on user content is disclosed with a control, and the default mattersGap
The privacy policy discloses training of Canva’s models on user data, manageable via privacy settings; Canva Shield frames this as user control over private content.
Whether the training setting is on or off by default determines the real posture for most users and teams.
Question for vendor: What is the default state of the AI training privacy control for individual, team and enterprise accounts?
“to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings”
✓Security fundamentals are well evidencedStrong
SOC 2 Type II and ISO 27001 with external audits, bug bounty, VDP and CVE bulletins on the trust portal, encryption detail, and staged secure development.
The platform security baseline underneath the AI features is demonstrably mature.
“Is your platform security externally audited? Yes. Canva is SOC2 Type II compliant and is ISO 27001 certified, which requires us to have periodic external audits of our information security management system and security controls.”
“We run a bug bounty program and provide ways for security researchers to notify us of vulnerabilities in our products and environments.”
“# Bug bounty Contact: https://canva.com/security/bug-bounty # Vulnerability disclosure policy Policy: https://canva.com/security/vulnerability-disclosure # Trust documentation and security bulletins (including CVEs) Policy: https://trust.canva.com”
“In transit, designs are only accessible via TLS/SSL, and at rest, designs are encrypted with AES256.”
!No model providers are namedGap
None of the collected pages names the foundation models or providers behind the AI features; the sub-processor register sits behind a versioned link that did not resolve to content.
The data-flow question cannot be closed without knowing whose models process user content.
Question for vendor: Which model providers or self-hosted models power the AI features, and where are they listed?
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
“Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.”
“***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
“Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.”
“***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
“Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.”
“***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
AI system15% of the score33
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“you retain your ownership rights to your Input, and you own your Output,”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“We peer review and test our code prior to release, including manual and automated checks for security issues.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
AI system description: vendor-evidenced, not yet independently corroborated.
Change management: not publicly evidenced.
Model10% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
Model provider transparency: not publicly evidenced.
Customer data15% of the scoreorganisation-level evidence72
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“to train our algorithms, models and AI products and services using machine learning to develop, improve and provide our Service. You can manage the use of your data for training AI to improve our Service in the privacy controls page under your privacy settings”
“In transit, designs are only accessible via TLS/SSL, and at rest, designs are encrypted with AES256.”
“you retain your ownership rights to your Input, and you own your Output,”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the scoreorganisation-level evidence75
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Signup for Notifications (opens in a new tab or window) Go back to the Canva Data Processing Addendum (opens in a new tab or window) View the most recent version of Canva's Sub-Processors list.”
“Third-Party Subprocessors (Canva Services) Name Description of Processing Location Amazon Web Services, Inc. Platform Hosting, Infrastructure and Canva AI Services United States & EU Anthropic PBC Canva AI Services United States ElevenLabs Inc. Canva AI Services United States Features & Labels, Inc. Canva AI Services United States Google LLC Platform Hosting, Infrastructure, Security and Canva AI Services United States MongoDB, Inc. Platform Hosting and Infrastructure United States Nanonoble Pte. Ltd.*** Canva AI Services United States OpenAI, LLC Canva AI Services United States Snowflake Inc.”
“***These Subprocessors do not process Customer Personal Data for Canva Education, Canva Enterprise or Customers with a signed Order Form with Canva.”
Security foundation15% of the scoreorganisation-level evidence85
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“We run a bug bounty program and provide ways for security researchers to notify us of vulnerabilities in our products and environments.”
“# Bug bounty Contact: https://canva.com/security/bug-bounty # Vulnerability disclosure policy Policy: https://canva.com/security/vulnerability-disclosure # Trust documentation and security bulletins (including CVEs) Policy: https://trust.canva.com”
“Our threat detection, logging and alerting systems notify our oncall teams about potential incidents.”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the scoreorganisation-level evidence85
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Is your platform security externally audited? Yes. Canva is SOC2 Type II compliant and is ISO 27001 certified, which requires us to have periodic external audits of our information security management system and security controls.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.
Independent assurance: vendor-evidenced, not yet independently corroborated.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“you retain your ownership rights to your Input, and you own your Output,”
“it is prohibited to use AI Products to: Mislead anyone that the content generated by AI Products is human-generated;”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 57 → up to 81 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 6 — registry checks and verification ladders, click to view
SOC 2 Type II stated with periodic external audits.
Checked against SOC 2 Type 2 report held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry
ISO/IEC 27001:2022, certificate IS 826967 issued by BSI, valid to 2029-05-27. Scope covers the Canva suite (including the Canva AI features' supporting infrastructure) and Flourish.
Checked against BSI certificate IS 826967 held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
SOC 3 report by Sekuro (an Insight company), signed by Peter Sheville of C&N Audit Services, 5 June 2026: Canva Free, Pro, Business and Enterprise; trust services criteria security, availability, confidentiality and privacy; period 14 Apr 2025 - 13 Apr 2026; unqualified conclusion. Same period, scope and criteria as the corroborated SOC 2 Type 2 - the SOC 3 is its general-use counterpart, not additional assurance. NOTE: the document also quotes the TSP Section 100 title, which lists five criteria including processing integrity; processing integrity is NOT in this engagement's scope. Vault: Gated/Canva/2026-06_canva-soc3-sekuro.pdf. The scanned product (Canva AI features) operates within these Canva products.
Checked against SOC 3 report held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry
MERCHANT Attestation of Compliance (PCI DSS v4.0.1): attests Canva's own card-payment acceptance environment, NOT services provided to customers as a PCI service provider. Overall COMPLIANT; RoC dated 23 Sep 2025, assessment ended 15 Aug 2025; QSA Sekuro Pty Ltd. Annual cycle. Vault: Gated/Canva/2025-09_canva-pci-dss-v401-aoc-merchant.pdf.
Checked against PCI DSS v4.0.1 Attestation of Compliance held in the TrustyCyber vault (supplied by Canva), Aug 24, 2026: Verified on the registry
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry
Sources 18 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
