VendorScore · Design · Data-access posture
A plain-language answer from Canva's Trust Center, security page, subprocessor list, DPA, Technical & Organisational Measures, Privacy Policy and Canva Shield announcement.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): Canva and its AI providers process designs in plaintext with Canva-managed keys; team plans are excluded from AI training, personal accounts aren't by default.
Scored configuration: Canva Teams/Business/Enterprise (team content never used to improve AI features), SSO and admin group permissions. No customer-managed key option.
Personal Free/Pro accounts score lower because AI training is on by default; the report estimates Overall ~48.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Content from Teams, Business, Enterprise and Education users is not used to improve AI features, and this cannot be turned on.
Evidence: Canva Shield announcementCanva stores your data in the United States; group members in several countries process it.
Evidence: Privacy at CanvaAI subprocessors include Anthropic, OpenAI, Google and ElevenLabs; support is outsourced (e.g. Concentrix in the Philippines).
Evidence: Canva subprocessorsOur report flags these gaps in Canva's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): Canva and its AI providers process designs in plaintext with Canva-managed keys; team plans are excluded from AI training, personal accounts aren't by default. VendorScore rates Canva 50/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Canva Teams/Business/Enterprise (team content never used to improve AI features), SSO and admin group permissions. No customer-managed key option.
Canva encrypts data at rest with AES-256 and in transit with TLS 1.2+ on Canva-managed AWS infrastructure, and makes no E2EE claim. We found no customer-managed key, BYOK or EKM option, and Canva publishes no key-hierarchy detail.
Canva says "Canva staff access to Customer Personal Data is role-based and follows the principle of least privilege." Data is processed by Canva group members in Australia, New Zealand, the Philippines, the UK, Singapore, the EU and the US, and support is outsourced to providers including Concentrix (Philippines), IBEX and Zendesk. We found no customer-visible log of staff access.
Not on team plans. Canva says: "Content from Canva Teams, Business, Enterprise, and Education users is not used to improve AI-powered features, and this cannot be turned on." Personal Free and Pro accounts are different: Canva's Privacy Policy lets it use your activity, content and uploads to train its algorithms, models and AI products by default, and you can manage that in your privacy settings. A labelling subprocessor, Features & Labels, is listed; whether it sees team content isn't stated.
VendorScore doesn't certify compliance; Canva publishes a DPA at https://www.canva.com/policies/data-processing-addendum/. It gives at least 30 days' notice by posting, an objection window of 10 days after notification, and a termination right if the objection isn't resolved.
Canva's list (updated 2026-04-17) at https://www.canva.com/policies/subprocessors/ names AWS (including Canva AI), MongoDB, Snowflake and Google; AI providers Anthropic, OpenAI, ElevenLabs and Features & Labels; support providers including Concentrix, IBEX and Zendesk; and group members including Leonardo.AI. Canva doesn't publish zero-data-retention terms with its AI providers.
No. Canva says: "Canva stores your data in the United States."
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (canva.md), evidence dated 2026-10-07.