VendorScore · Online whiteboard · Data-access posture
A plain-language answer from Miro's Help Center, subprocessor list, Customer DPA, AI Features Addendum and security whitepaper. EKM lets you revoke Miro's access to your encrypted data; it isn't end-to-end encryption.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): Miro processes boards in plaintext; EKM lets you revoke your AWS key so Miro can no longer decrypt, but it isn't end-to-end encryption.
Scored configuration: Miro Enterprise with Enterprise Guard EKM (key in your AWS KMS), EU data residency, AI training off (Enterprise default), SSO/SCIM and admin audit logs.
Default setup without EKM (Miro-managed keys) scores lower; the report estimates Overall ~55.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
EKM: revoking your AWS KMS key renders all encrypted data inaccessible to both Miro and end users; key use is logged in CloudTrail.
Evidence: Miro EKM overviewSubprocessors include Anthropic, OpenAI, Google, Microsoft and ElevenLabs; third-party models also include Amazon and StabilityAI.
Evidence: Miro subprocessor listMiro's security whitepaper describes AES plus TLS as helping ensure 'end-to-end encryption'; that's server-side and transport encryption, not E2EE.
Evidence: Miro Security & Compliance whitepaperOur report flags these gaps in Miro's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): Miro processes boards in plaintext; EKM lets you revoke your AWS key so Miro can no longer decrypt, but it isn't end-to-end encryption. VendorScore rates Miro 61/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Miro Enterprise with Enterprise Guard EKM (key in your AWS KMS), EU data residency, AI training off (Enterprise default), SSO/SCIM and admin audit logs.
No. Miro encrypts boards with AES-256 at rest and TLS 1.3 in transit. Its security whitepaper says this "helps ensure end-to-end encryption throughout the data lifecycle"; that describes server-side and transport encryption, not E2EE, while Miro's help docs describe the encryption accurately. With EKM (Enterprise Guard add-on), your key lives in your AWS KMS and you can "revoke your key, rendering all encrypted data inaccessible to both Miro and end users", with key use logged in CloudTrail. Miro still decrypts in normal operation, so EKM gives custody and revocation, not zero access.
Rarely, per Miro. Its whitepaper says "Only a small number of engineers" have access, limited "to troubleshooting tasks and only with users' explicit consent", and that "Miro support personnel do not have access to board content unless explicitly invited". Board content is still processed server-side, including by AI features and third-party model providers, and we found no customer-visible log of staff access.
Not on Enterprise unless you opt in. Miro says: "Miro doesn't use customer data for training or refining models… Enterprise customers will be opt-out by default and need to explicitly opt in." Non-Enterprise customers get "reasonable means to object" under the AI Features Addendum, and a Miro help article (which we could read only via a search index) says AI interaction data from Free plans has been collected for quality improvements since 2025-02-03.
VendorScore doesn't certify compliance; Miro publishes a DPA at https://miro.com/legal/customer-data-processing-addendum/. Miro's Customer DPA gives 10 days' prior notice of new subprocessors if you subscribe and 30 days to object, with SCC Modules 2/3. On-site audits are limited to cases after a confirmed incident or a regulator request.
Miro's list (last updated 8 July 2026) at https://miro.com/legal/subprocessors-list/ includes AWS, Anthropic, ElevenLabs (captions/transcripts), Google, Microsoft, OpenAI, PartnerHero (support), Intercom and Zendesk, among others. Third-party models include Amazon, Anthropic, OpenAI and StabilityAI. Miro doesn't publish zero-data-retention terms with each model provider.
Yes, on all plans: EU hosting (Ireland primary, Germany backup) is marked as the default. US, AU and JP regions are Enterprise-only. AI processing and real-time video calls may be processed outside the region.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (miro.md), evidence dated 2026-10-07.