Snapshot 81509
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Miro Trust Center Welcome to Miro's Trust Center, where our commitment to data privacy and security is central to our operations. [Miro](https://miro.com/index/) provides a AI powered innovation workspace that enables distributed teams of any size to dream, design, and build the future together. This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data. Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives. Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation. Skip to main content Miro Trust Center Welcome to Miro's Trust Center, where our commitment to data privacy and security is central to our operations. Miro provides a AI powered innovation workspace that enables distributed teams of any size to dream, design, and build the future together. This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data. Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives. security@miro.com ⌘K OverviewDocumentationControlsSubprocessors Loading content... Certifications Trusted by Accenture Deloitte Ulta Beauty CVS Health PepsiCo Danaher Corporation Ubisoft Slalom Comcast Chase DocuSign Microsoft PwC EY ServiceNow Zendesk Contact supportReport a vulnerability Trust center by Wolfia: AI trust center & security questionnaire automation Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers Documentation Featured ISO/IEC 42001:2023 Certificate ISO/IEC 27001 Certificate IRAP Attestation Letter SOC 2 Type II Report 2025-2026 SOC 3 System and Organization Controls Report 2025-2026 Subprocessors Amazon Web Services, Inc. · United States* (data residency available for AUS, EU, US, Japan) Infrastructure United States* (data residency available for AUS, EU, US, Japan) Anthropic · United States AI Functionality United States Braze, Inc. · United States Service Related Emails United States ElevenLabs · United States Live Captions, Transcripts United States Gainsight, Inc. · United States Customer Success/Support United States Controls AI governance AI and machine learning features are safeguarded by governance, privacy, and security controls to align with enterprise policies and compliance frameworks. ISO 42001 management system Administrator control over AI features AI activity audit logging Global AI scope coverage Ongoing surveillance audits AI data handling and training restrictions Built-in prompt redaction and moderation ISO/IEC 42001 certification for AI Internal security procedures Internal security practices and governance ensure consistency, accountability, and continuous improvement in protecting information and systems. Annual risk assessment Annual risk assessment and review Formal security policies Semi-annual risk reviews Incident response plan Incident response procedures Internal security audits and monitoring Post-incident root cause analysis Cybersecurity insurance Role-based responsibilities and accountability Access control Strict access management policies and technical controls ensure only authorized, validated individuals can access systems and sensitive data. Multi-factor authentication Multi-factor authentication for all systems Role-based access control Single sign-on integration Just-in-time privileged access Automated access reviews Biannual access reviews Account lockout and session timeout Frequently asked security questions Is Miro secure? Miro operates this public trust center. It publishes 10 independent compliance certifications, security documentation available on request, and a published list of its subprocessors. Is Miro SOC 2 compliant? Yes. Miro maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center. Does Miro have ISO 27001 certification? Yes. Miro is ISO 27001 certified. You can review this certification in the compliance section of this trust center. Is Miro GDPR compliant? Yes. Miro maintains GDPR compliance. See the compliance section of this trust center for details. Who are Miro's subprocessors? Miro discloses its subprocessors in this trust center, including Amazon, Anthropic, and Braze. See the subprocessors section for the complete list. How do I request Miro's security documentation? You can request access to Miro's security documentation directly through this trust center. Submit an access request and the Miro team reviews and grants access. Contact supportReport a vulnerability Trust center by Wolfia: AI trust center & security questionnaire automation Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers Controls AI governance AI and machine learning features are safeguarded by governance, privacy, and security controls to align with enterprise policies and compliance frameworks. ISO 42001 management system The organisation operates an audited framework dedicated to governing the lifecycle and risks of artificial intelligence systems Administrator control over AI features Enterprise administrators can enable or disable AI features at the organization or team level, enacting granular usage policies in line with internal governance needs. AI activity audit logging Comprehensive audit logs track all AI-related interactions and activities, providing an immutable record for monitoring, compliance, and policy enforcement. Global AI scope coverage Certification scope encompasses production and continuous improvement of AI-enabled SaaS across EMEA, USA and other key regions, ensuring consistent controls worldwide Ongoing surveillance audits Accredited auditors conduct periodic surveillance to confirm the AI management system continues to meet ISO requirements over time AI data handling and training restrictions Customer data is excluded from training AI models, and only opted-in, non-enterprise user data may be used for AI improvement, preserving privacy and regulatory compliance. Built-in prompt redaction and moderation Automated prompt redaction and customizable output moderation help protect against prompt injection, sensitive data leakage, and harmful content generation. ISO/IEC 42001 certification for AI AI systems development and operation are externally validated according to ISO/IEC 42001, demonstrating responsible design, risk management, and ethical safeguards. Internal security procedures Internal security practices and governance ensure consistency, accountability, and continuous improvement in protecting information and systems. Annual risk assessment Risks to confidentiality, integrity and availability are identified and scored using ISO and NIST methodologies, guiding mitigation plans Annual risk assessment and review A formal risk management process, reviewed at least annually, identifies, evaluates, and drives treatment of risks according to regulatory and customer requirements, ensuring the risk posture adapts to new threats. Formal security policies Comprehensive security policies aligned to ISO 27001:2022 and SOC 2 are maintained, reviewed, approved, and distributed at least annually to all employees and relevant third parties, ensuring ongoing relevance and employee awareness. Semi-annual risk reviews Risk registers are revisited twice a year to capture changes in the threat landscape and business operations Incident response plan Documented procedures outline roles, communication and evidence handling to ensure consistent response to security events Incident response procedures A documented incident response plan details structured procedures for detection, reporting, containment, communication, and post-incident analysis to minimize impact and drive continuous improvement. Internal security audits and monitoring Regular internal control assessments and audits validate that controls are effectively deployed, operational, and improved as necessary, providing assurance to management and clients. Post-incident root cause analysis Every significant incident triggers a lessons-learned review, driving continual control improvements Cybersecurity insurance An active policy transfers residual financial risk from severe cyber events, protecting both the company and its customers Role-based responsibilities and accountability Key information security roles and responsibilities are formally assigned, with management oversight, board-level involvement, and documented accountability for policy enforcement and control operation. Access control Strict access management policies and technical controls ensure only authorized, validated individuals can access systems and sensitive data. Multi-factor authentication All workforce and production accounts must use a second factor via the identity platform, significantly reducing the risk of credential compromise Multi-factor authentication for all systems Multi-factor authentication is enforced for all user and administrator accounts across production and corporate environments, reducing the risk of unauthorized access due to credential compromise. Role-based access control Permissions are assigned through an RBAC matrix that maps job roles to least-privilege groups, ensuring users receive only the access they need Single sign-on integration SAML-based SSO through the corporate identity provider streamlines account lifecycle management and enforces centralised security policies Just-in-time privileged access Teleport grants time-bound production access only after approval, limiting standing administrator privileges and improving accountability Automated access reviews User and administrator access privileges are reviewed at least biannually to validate appropriateness and minimize the risk of privilege creep. Biannual access reviews Access rights for all users are re-certified at least twice a year to verify continued business need and remove excess privileges Account lockout and session timeout Accounts lock after multiple failed login attempts, while idle sessions automatically expire after a defined period, limiting brute-force attacks and reducing exposure from unattended sessions. Data security Comprehensive data protection measures safeguard customer and confidential information throughout its entire lifecycle. Encryption at rest All data stores and backups are secured with cloud-native encryption keys managed by the provider, protecting information from unauthorised reading of physical media Data classification and handling Company-wide data classification schemes and policies establish protection requirements for each data category, enforcing handling rules and access restrictions based on sensitivity. Encryption in transit TLS 1.2 or higher is enforced at every network edge, ensuring data cannot be intercepted or tampered with while moving between clients and services Encryption at rest and in transit Sensitive data is encrypted both at rest and during transmission using industry-standard protocols and algorithms, ensuring confidentiality and integrity across all storage and transfer channels. Data classification programme A documented policy assigns sensitivity levels and required protections to each data type, enabling consistent handling across the organisation Customer-controlled encryption keys Enterprise customers can leverage encryption key management options, including bring-your-own-key capabilities, to maintain autonomy and visibility over their encrypted data. Backup encryption and replication Daily encrypted backups with four-hour snapshots are replicated to a secondary region, combining confidentiality with resilience Secure data retention and disposal Data retention periods and secure disposal procedures are defined and enforced, ensuring data is not retained longer than necessary and is irretrievably destroyed when no longer required. Data protection by design and default Data privacy and protection measures are embedded into product design, system development, and operational workflows to meet regulatory and compliance standards such as GDPR and CCPA. Secure data deletion Customer content is purged 30 days after contract termination, aligning with privacy commitments and minimising residual risk Infrastructure security Robust infrastructure design and layered controls enhance system resilience and reduce risks to core technology assets. Web application firewall A managed WAF inspects all inbound traffic and blocks malicious requests before they reach application workloads Cloud infrastructure with strong regional controls Primary systems and backups are hosted in leading public cloud environments with physical security validation, multiple regions for redundancy, and operational control over logical and network security. Network segmentation and DMZ Production, development and corporate networks are isolated with default-deny security groups, limiting lateral movement Network segmentation and firewalls Critical environments are segmented and protected by network firewalls, security groups, and allow-by-exception rules, minimizing the risk of lateral movement and unauthorized access. Web application firewall and DDoS protection A web application firewall inspects all inbound traffic to protect web applications from exploits and denial-of-service attacks, significantly strengthening perimeter defenses. Infrastructure as code with CIS benchmarks Systems are provisioned through scripted templates that apply industry-standard hardening baselines consistently and prevent drift Default-deny security groups Cloud firewalls start from a deny-all rule set and allow only approved ports and protocols, reducing the exposed attack surface Continuous vulnerability and patch management Automated vulnerability scanning, internal and third-party penetration testing, and patch deployment processes help identify and address security flaws before they can be exploited. Annual penetration testing Independent testers assess the environment each year, and identified issues are tracked to remediation, validating real-world security posture Intrusion detection and monitoring Comprehensive network and host-based intrusion detection systems continuously monitor for anomalies, triggering alerts, and enabling rapid incident response. Product security Security is embedded across the product lifecycle, from design to release, to ensure ongoing protection against emerging risks. Secure software development lifecycle A documented SDLC integrates security checkpoints, code review, static and dynamic analysis, and vulnerability testing into every phase of software development and deployment. Secure development lifecycle policy Documented standards guide design, coding, testing and deployment activities to embed security throughout the software lifecycle Separation of development and production environments Production systems are strictly segregated from development and test environments, reducing attack surface and preventing accidental introduction of code or data leakage. Static code and dependency scanning Automated SAST, secret scanning and dependency checks run in the CI pipeline to catch issues before code reaches production Peer code reviews All pull requests require approval from qualified reviewers, ensuring that security considerations are evaluated before merge Automated dependency and secret scanning Automated tools scan for vulnerable dependencies, hardcoded secrets, and misconfigurations, alerting teams prior to integration and production roll-out. Third-party penetration testing Annual assessments by independent specialists identify and validate application-layer weaknesses under real-world conditions Annual third-party penetration testing Accredited independent security firms conduct annual penetration testing for all production-facing systems, verifying resilience against real-world attack scenarios. Public bug bounty programme Continuous crowdsourced testing rewards researchers for responsibly disclosing vulnerabilities, amplifying security coverage Bug bounty program A public bug bounty program incentivizes external researchers to report security vulnerabilities, complementing internal testing and driving continuous improvement. Business continuity and disaster recovery Comprehensive procedures and resilient infrastructure ensure operational continuity, rapid recovery, and minimal data loss during major incidents or disruptions. Documented disaster recovery plan A formal, tested disaster recovery policy defines roles, responsibilities, and step-by-step procedures for restoring systems and data with minimal downtime and data loss. Disaster recovery policy with defined RTO / RPO The plan sets an eight-hour recovery time and four-hour recovery point for critical systems, giving customers clear availability guarantees Automated backups and snapshots Scripts create daily full backups and four-hour incremental snapshots for core datastores, preserving recent copies for rapid restoration Automated, encrypted backups with multi-region storage Critical data is backed up automatically, encrypted, and replicated to geographically separate data centers, with retention policies and quarterly restoration exercises. Annual disaster recovery testing Full failover exercises are conducted each year, with results documented and improvements tracked, proving the ability to meet recovery objectives Defined recovery time and point objectives Clear RTOs and RPOs for primary and secondary sites are documented and measured to meet contractual and operational requirements. Multi-region replication Data is continuously replicated to secondary cloud regions so that services can be restored even if a primary location becomes unavailable 99.5 % uptime service-level agreement Contractual SLA commits to high availability and includes financial remedies, demonstrating confidence in operational resilience Business continuity framework based on ISO 22301 The business continuity program encompasses planning, monitoring, regular testing, and continuous improvement to maintain service under adverse conditions. Employee security and awareness Employee-focused controls and continual security education reduce insider risk and create a strong culture of security and compliance. Pre-employment background checks All new hires undergo identity, employment, education and criminal screening before receiving system access, lowering insider risk Mandatory background checks Pre-employment background screening covers employment, education, identity, and, where permitted by law, criminal history to reduce hiring risk. Annual security awareness training All personnel complete mandatory security and privacy training at onboarding and annually, covering threats, data handling, phishing, malware, and corporate policies. Security awareness training Employees complete mandatory information-security courses during onboarding and annually thereafter to reinforce best practices Secure coding training Developers receive annual education aligned with OWASP guidelines to reduce the introduction of software vulnerabilities Acceptable use and confidentiality agreements Employees must sign and agree to acceptable use, confidentiality, and security policy acknowledgments as a condition of employment and system access. Terminations and offboarding controls Automated offboarding workflows ensure timely revocation of system and facility access, minimizing the risk of orphaned accounts or data leakage. Progressive disciplinary policy Documented sanctions for policy violations hold individuals accountable and deter risky behaviour Certification reimbursement programme Staff are encouraged to pursue recognised security credentials, supporting continuous improvement of organisational expertise Disciplinary procedures for policy violations Violations of security or acceptable use policies are investigated and subject to documented disciplinary actions up to and including termination or referral to authorities. Physical and environmental security Physical access to offices, assets, and sensitive areas is tightly controlled, monitored, and audited to prevent unauthorized entry or damage. Badge and biometric access controls Office entry points require card swipes or fingerprint scans, ensuring only authorised personnel enter sensitive areas Badge-based access control and visitor management Office facilities are secured with badge access, visitor badges, and registration logs, while entry to sensitive areas is reviewed quarterly and limited to authorized personnel. Video surveillance and retention Security cameras monitor entrances, exits, and sensitive areas, with footage retained for a minimum of 90 days to support investigations. CCTV surveillance Security cameras monitor entrances and critical rooms with footage retained for at least 90 days to support investigations Visitor management and logging Guests must pre-register, sign in, wear badges and remain escorted, creating an auditable trail of facility access Physical media and device protection Sensitive media and devices are securely stored and destructed according to policy, and all portable storage is required to use encryption and access controls. Fire detection and suppression systems Data-relevant office floors include automatic sprinklers and detectors, reducing the impact of fire on operations Fire suppression and environmental controls Critical offices are protected by fire detection, suppression systems, and controlled environments to mitigate physical threats and maintain operational uptime. Secure media disposal Locked shred bins and third-party destruction services ensure physical documents and retired devices are safely destroyed Compliance and auditing Certified compliance with leading standards, external and internal audits, and transparent practices demonstrate commitment to industry best practices. SOC 2 Type II certification An independent auditor confirms the design and operating effectiveness of security, availability and confidentiality controls over a year-long period, giving customers third-party assurance of the service’s control environment ISO/IEC 27001:2022 certification A certified and regularly audited information security management system (ISMS) covers all relevant operations, systems, and processes organization-wide. ISO / IEC 27001:2022 certification A formal information security management system is certified by an accredited body, demonstrating systematic risk management and continual improvement of security controls SOC 2 Type II and SOC 3 attestation Annual independent assurance reports attest to the design and operating effectiveness of controls against recognized trust criteria for security, availability, and confidentiality. ISO 42001:2023 certification The artificial intelligence management system is certified to the new ISO standard, evidencing structured governance and risk controls over AI-enabled services GDPR, CCPA, and privacy regulation alignment Security and privacy programs are designed and operated to meet regulatory obligations and client requirements in multiple jurisdictions. Vendor due diligence and compliance management A formal program evaluates, contracts, and reviews vendors for compliance with security, privacy, and regulatory requirements before and during the relationship. Cyber Essentials certification Certification to the UK government-backed scheme shows foundational cyber hygiene measures have been independently assessed and found effective Annual internal control reviews Management performs scheduled assessments of key controls between external audits to ensure they remain properly designed and functioning Privacy policy transparency and data subject rights A published privacy policy details personal data processing, third-party sharing, and user controls, enabling customers to comply with modern privacy regulations. Third-party and supply chain management Vendors and partners are systematically assessed, monitored, and contractually required to meet security, confidentiality, and privacy standards. Vendor due-diligence assessments Security, compliance and financial standing are reviewed before any new provider is approved, reducing supply-chain risk Due diligence and onboarding assessments Critical vendors are screened prior to engagement for security controls, regulatory adherence, financial stability, and service fit, mitigating third-party risk. Annual vendor re-evaluation Key suppliers are re-assessed each year, including review of their SOC 2 or ISO reports, to verify continued alignment with requirements Annual review and reassessment of vendors Vendors are reviewed annually for ongoing compliance, with up-to-date documentation (e.g., SOC reports, ISO certificates) and risk reassessment. Contractual data protection agreements Data processing addenda and non-disclosure agreements require vendors to meet stringent data protection and confidentiality commitments. Non-disclosure agreements All vendors sign legally binding NDAs before sensitive information is shared, protecting proprietary and customer data Centralised vendor inventory A maintained register records purpose, risk classification and contract status for every third-party relationship Published subprocessor list and notification process A list of authorized third-party data processors is maintained and updated, with customer notification and opt-out procedures for new subprocessors. Contractual security obligations Service agreements define roles, responsibilities, SLAs and data-protection clauses to enforce expected control levels Device and endpoint security Robust controls ensure all endpoint devices are protected against threats through technical enforcement and managed configurations. Mobile device management Jamf enforces configuration baselines, disk encryption and approved software on all corporate laptops and mobile devices Device inventory and management All company-owned and authorized endpoints are inventoried and managed, with policies enforced through mobile device management solutions. Disk encryption FileVault ensures that data on employee devices remains unreadable if hardware is lost or stolen Antivirus and endpoint protection Mandatory endpoint protection software with automatic updates, periodic scans, and prohibited removable media reduces malware risk and meets compliance standards. Full disk encryption for endpoints Laptop and mobile device disk encryption is enforced at the hardware or OS level to prevent data exposure in case of loss or theft. Next-generation antivirus and EDR SentinelOne provides real-time behaviour analysis, automatic quarantine and regular signature updates across servers and workstations Forced operating system updates Automated policies deploy OS and security patches within defined timelines, closing vulnerabilities promptly Automatic screen lock and clear desk policy Endpoints are configured for automatic screen lock, and staff are educated to clear workspaces of sensitive information when unattended. Removable media restrictions USB access is blocked or limited to read-only, mitigating the risks of malware introduction and data exfiltration Change management System changes are subject to rigorous processes for approval, testing, and review to minimize the risk of errors or vulnerabilities in production. Infrastructure as code change process All infrastructure modifications follow pull-request workflows with documented purpose, approvals and automated testing Formal change management policy All infrastructure and application changes must be formally requested, assessed for risk, tested in pre-production, and approved before implementation. Infrastructure as code for deployments Deployment pipelines leverage infrastructure as code for consistent, auditable, and rapid system provisioning and rollback, limiting human error. Automated rollback plans Deployment pipelines include predefined rollback steps, enabling rapid recovery if a change negatively impacts the service Automated testing and rollback plans Automated testing and defined rollback procedures are prerequisites for production changes, ensuring swift remediation in case of issues. Segregated environments Development, staging and production are isolated to prevent untested code from affecting live customer data Separation of duties for code changes Code reviews and separation of developer and approver roles prevent unauthorized or untested changes from reaching critical environments. Continuous configuration reviews Hardening standards and Terraform templates are revisited throughout the year to incorporate evolving best practices Comprehensive testing standards Unit, integration and regression tests are mandated for every change, decreasing the likelihood of defects reaching production Monitoring and logging Centralized monitoring and audit logging deliver visibility across environments, supporting threat detection, incident response, and compliance verification. Centralised log aggregation System and security logs are collected in searchable storage for at least one year, supporting investigations and compliance evidence Centralized log collection and retention Critical system and security event logs are collected centrally, retained according to policy, and protected from tampering, supporting investigations and compliance. Security operations centre monitoring A dedicated team reviews alerts around the clock, triages incidents and coordinates response actions to minimise impact Continuous security monitoring Automated security monitoring systems and real-time alerts enable rapid response to suspicious activity and potential breaches. Audit logging and privileged access monitoring All privileged administrative actions and critical system events are logged and monitored, with alerting on anomalous activities. IDS / IPS coverage Network and host-based intrusion detection systems analyse traffic and endpoints for malicious behaviour, providing layered visibility File integrity monitoring Cloud-native tooling tracks critical file changes across all systems and raises alerts on unauthorised modifications Integration with security event and information management (SIEM) Event data is integrated into SIEM solutions for advanced correlation, analysis, and case management by security teams. Automated alerting and ticketing OpsGenie and incident.io create actionable tickets for anomalous events, ensuring timely escalation to the appropriate responders Documentation Featured ISO/IEC 42001:2023 Certificate ISO/IEC 27001 Certificate IRAP Attestation Letter SOC 2 Type II Report 2025-2026 SOC 3 System and Organization Controls Report 2025-2026 Certifications ISO/IEC 42001:2023 Certificate ISO/IEC 27001 Certificate SOC 2 Type II Report 2025-2026 SOC 3 System and Organization Controls Report 2025-2026 Cyber Essentials Certificate of Assurance 3rd Party Penetration Tests Miro Penetration Test Summary 2025-2026 Security Miro Security and Compliance Overview Miro Enterprise Plan - AI Security Miro AI Workflows - AI Security Enterprise Guard Data Security Overview Policies Acceptable Use Policy Antivirus Policy Business Continuity Policy Cryptographic Key Management and Control Policy Data Management Policy Disaster Recovery Policy and Plan Incident Response Policy Information Security Policy Risk Management Policy Secure Software Development Lifecycle Policy Teleworking Policy Third Party Risk Management Standard Threat Intelligence Policy Privacy & Legal Data Processing Addendum (DPA) Privacy Policy Transfer Impact Assessment (TIA) Questionnaires Consensus Assessments Initiative Questionnaire Shared Assessments SIG Questionnaire Other IRAP Attestation Letter Diagrams and Reports Miro Accessibility Conformance Report Miro Dataflow Diagram Miro Network Diagram Amazon Web Services, Inc. · United States* (data residency available for AUS, EU, US, Japan) Infrastructure United States* (data residency available for AUS, EU, US, Japan) Anthropic · United States AI Functionality United States Braze, Inc. · United States Service Related Emails United States ElevenLabs · United States Live Captions, Transcripts United States Gainsight, Inc. · United States Customer Success/Support United States Google LLC · United States Sensitive Data Discovery (Enterprise Guard) United States Intercom · United States Customer Support (Chatbot) United States Microsoft Corporation · United States Accessibility | OCR functionality | AI United States OpenAI · United States AI Functionality United States PartnerHero, Inc. · United States Customer Support United States Skilljar, Inc. · United States Customer Training (Miro Academy) United States Zendesk, Inc. · United States Customer Support Tickets United States Loading content... Updates Overview