VendorScore · Project management · Data-access posture

Can Asana read your project data?

A plain-language answer from Asana's public Trust, Terms and Trust Center pages. Asana holds the keys by default, and EKM's scope isn't documented on the pages we could fetch.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, Asana can read your workspace data by design (with controls). Asana holds the keys by default. EKM lets you bring your own key, but its scope isn't documented on the public pages we could fetch, and authorized staff can access data when their job requires it.

57 / 100 overall

Scored configuration: Asana Enterprise+ with Enterprise Key Management (EKM) as advertised; EKM's technical scope couldn't be verified.

Default (no EKM): Asana-managed keys; the report estimates Overall ~53.

Report confidence: Medium. Asana's EKM help article returned no content, so EKM's scope is Unknown.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Asana's public documentation:

  • EKM details (key provider, data in scope, revocation behaviour, plan minimums) are in a help article that returned no content: Unknown.
  • No customer-approval gate (Lockbox-style) for staff access was found in the pages we read.
  • Trust Center documents are behind access requests; report contents weren't reviewed.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Asana data access, AI training, GDPR and residency

Can Asana read your project data?

Yes, Asana can read your workspace data by design (with controls). Asana holds the keys by default. EKM lets you bring your own key, but its scope isn't documented on the public pages we could fetch, and authorized staff can access data when their job requires it. VendorScore rates Asana 57/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Asana Enterprise+ with Enterprise Key Management (EKM) as advertised; EKM's technical scope couldn't be verified.

Does Asana encrypt my data? What does Asana EKM do?

Asana's Data Security Standards say it encrypts Customer Data in transit and at rest using industry-standard algorithms (e.g. TLS 1.2, AES-256). Asana advertises Enterprise Key Management for "using your own encryption key on your Asana data", but the help article describing EKM's scope, key provider and revocation behaviour returned no content, so the public docs we could read don't state what EKM covers. Neither is E2EE.

Can Asana employees see my project data?

Yes, when their job requires it. Asana's Data Security Standards say: "Access to Customer Data is restricted to authorized Asana personnel who are required to access Customer Data to perform functions as part of the delivery of services," with least privilege and MFA. VendorScore found no customer-approval gate for staff access. Asana's customer support also uses AI processors (Anthropic, OpenAI, Intercom).

Does Asana AI train on my data?

On metadata, yes, when AI features are on. Asana's privacy statement says: "When features powered by Asana AI are enabled in your domain, we use metadata related to your domain's use of Asana to train machine learning models. Depending on the model and the feature, these machine learning models power features, both in your domain and other Asana domains." It also says its third-party LLM providers are contractually prohibited from using customer data to train their models.

Is Asana GDPR compliant? Where is the Asana DPA?

VendorScore doesn't certify compliance; Asana publishes a DPA at https://asana.com/terms/data-processing. The DPA gives 10 business days' notice of new subprocessors, lets you object within 30 days, and grants a customer audit right once a year on 14 days' notice.

Who are Asana's subprocessors, and which LLM providers see my data?

Asana's list (last updated September 11, 2026) names AWS, Google Cloud and Fireworks AI for infrastructure. OpenAI and Anthropic appear as "LLM Provider" under Analytics & Data Warehouse (alongside Amplitude, Databricks, Segment and Tableau), separately from the feature-specific AI subprocessors such as AWS Bedrock, Anthropic, Google Gemini Enterprise Agent Platform, Recall.ai transcription and OpenAI. Support uses Anthropic, Intercom, OpenAI and Salesforce Service Cloud. The list is published at https://asana.com/terms/subprocessors.

Can I keep Asana data in the EU (data residency)?

Yes. Asana says it "offers global data residency options with data centers in Europe, Australia and Japan."

Compare Asana

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (asana.md), evidence dated 2026-10-07.