VendorScore · Project management · Data-access posture
A plain-language answer from ClickUp's security page, Security Policy, DPA, subprocessor list, AI Terms and Help Center. ClickUp offers no customer-managed keys, and its AI features use a long list of model providers.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): ClickUp processes your workspace in plaintext with AWS-managed keys; staff can access data for support or incidents and many AI providers handle AI features.
Scored configuration: ClickUp Enterprise with data residency (US, EU-Ireland or APAC), SSO/SCIM, ClickUp AI at defaults and audit logs. No customer-managed key option, so the default setup has the same key custody.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Employees may access customer data for incident response or customer support, in an auditable manner.
Evidence: ClickUp Security PolicyLLM subprocessors include Anthropic, OpenAI, Azure AI Foundry and China-based Kling 3.0 and Seedance 2.0.
Evidence: ClickUp subprocessorsAI data for EU-hosted workspaces isn't processed in the EU; a downvote exposes AI traces to ClickUp engineers.
Evidence: ClickUp AI models, privacy & security FAQOur report flags these gaps in ClickUp's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): ClickUp processes your workspace in plaintext with AWS-managed keys; staff can access data for support or incidents and many AI providers handle AI features. VendorScore rates ClickUp 50/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: ClickUp Enterprise with data residency (US, EU-Ireland or APAC), SSO/SCIM, ClickUp AI at defaults and audit logs. No customer-managed key option, so the default setup has the same key custody.
ClickUp uses TLS 1.2 in transit and "AES-256 encryption from Amazon KMS" at rest, with keys rotated yearly and key use monitored and logged. We found no customer-managed key, BYOK or EKM option. ClickUp's security page has an "End-to-End Security" heading about its AWS hosting, but it doesn't claim end-to-end encryption.
Yes, in limited cases. ClickUp's Security Policy lets employees access customer data "For the purpose of incident response, or customer support" and "In an auditable manner", with emergency exceptions. We found no customer-visible log of that access. For ClickUp AI, engineers can see an AI trace when a user downvotes a response.
ClickUp says no: "ClickUp AI is not trained on data from your Workspace… zero data retention agreements with all of the large language model (LLM) organizations". Its security page adds that AI partners are prohibited from training on your data: "This means zero third-party data retention." But ClickUp's AI Terms say healthcare use requires that "Zero Data Retention or access to otherwise-HIPAA compliant workflows or endpoints are enabled", which implies zero data retention isn't universal. The two statements conflict, and we don't resolve that. The DPA also lets ClickUp create anonymised or aggregated data and share it with third parties.
VendorScore doesn't certify compliance; ClickUp publishes a DPA at https://clickup.com/terms/dpa. It gives at least 30 days' email notice of new subprocessors, and you must object within ten business days.
ClickUp's list (updated 2026-09-28) at https://clickup.com/terms/dpa/subprocessors names AWS hosting, about 32 platform subprocessors (for example Daily, Recall, Nylas and Google Gemini) and LLM providers including Anthropic, AssemblyAI, Baseten, Azure AI Foundry, OpenAI, Vercel and two China-based providers, Kling 3.0 and Seedance 2.0. ClickUp doesn't document which features route to which model provider.
Partly. Enterprise can host in the US, the EU (Ireland) or APAC, but ClickUp AI data for EU-hosted workspaces isn't processed in the EU.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (clickup.md), evidence dated 2026-10-07.