VendorScore · Online whiteboard · Data-access posture

Can Miro read your boards?

A plain-language answer from Miro's Help Center, subprocessor list, Customer DPA, AI Features Addendum and security whitepaper. EKM lets you revoke Miro's access to your encrypted data; it isn't end-to-end encryption.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): Miro processes boards in plaintext; EKM lets you revoke your AWS key so Miro can no longer decrypt, but it isn't end-to-end encryption.

61 / 100 overall

Scored configuration: Miro Enterprise with Enterprise Guard EKM (key in your AWS KMS), EU data residency, AI training off (Enterprise default), SSO/SCIM and admin audit logs.

Default setup without EKM (Miro-managed keys) scores lower; the report estimates Overall ~55.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Miro's public documentation:

  • help.miro.com blocks automated fetches: the EKM, AI Admin security and data-residency articles were read via a fetch tool, and the AI quality-improvements article via a search index only.
  • Miro's Trust Center (trust.miro.com) is a JavaScript app and was only partly rendered.
  • Zero-data-retention terms with Miro's model providers aren't published.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Miro data access, AI training, GDPR and residency

Can Miro read your boards?

Yes, by design (with controls): Miro processes boards in plaintext; EKM lets you revoke your AWS key so Miro can no longer decrypt, but it isn't end-to-end encryption. VendorScore rates Miro 61/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Miro Enterprise with Enterprise Guard EKM (key in your AWS KMS), EU data residency, AI training off (Enterprise default), SSO/SCIM and admin audit logs.

Is Miro end-to-end encrypted? What does Miro EKM do?

No. Miro encrypts boards with AES-256 at rest and TLS 1.3 in transit. Its security whitepaper says this "helps ensure end-to-end encryption throughout the data lifecycle"; that describes server-side and transport encryption, not E2EE, while Miro's help docs describe the encryption accurately. With EKM (Enterprise Guard add-on), your key lives in your AWS KMS and you can "revoke your key, rendering all encrypted data inaccessible to both Miro and end users", with key use logged in CloudTrail. Miro still decrypts in normal operation, so EKM gives custody and revocation, not zero access.

Can Miro employees see my boards?

Rarely, per Miro. Its whitepaper says "Only a small number of engineers" have access, limited "to troubleshooting tasks and only with users' explicit consent", and that "Miro support personnel do not have access to board content unless explicitly invited". Board content is still processed server-side, including by AI features and third-party model providers, and we found no customer-visible log of staff access.

Does Miro AI train on my boards?

Not on Enterprise unless you opt in. Miro says: "Miro doesn't use customer data for training or refining models… Enterprise customers will be opt-out by default and need to explicitly opt in." Non-Enterprise customers get "reasonable means to object" under the AI Features Addendum, and a Miro help article (which we could read only via a search index) says AI interaction data from Free plans has been collected for quality improvements since 2025-02-03.

Is Miro GDPR compliant? Where is the Miro DPA?

VendorScore doesn't certify compliance; Miro publishes a DPA at https://miro.com/legal/customer-data-processing-addendum/. Miro's Customer DPA gives 10 days' prior notice of new subprocessors if you subscribe and 30 days to object, with SCC Modules 2/3. On-site audits are limited to cases after a confirmed incident or a regulator request.

Who are Miro's subprocessors? Which AI providers see my boards?

Miro's list (last updated 8 July 2026) at https://miro.com/legal/subprocessors-list/ includes AWS, Anthropic, ElevenLabs (captions/transcripts), Google, Microsoft, OpenAI, PartnerHero (support), Intercom and Zendesk, among others. Third-party models include Amazon, Anthropic, OpenAI and StabilityAI. Miro doesn't publish zero-data-retention terms with each model provider.

Can I keep Miro data in the EU (data residency)?

Yes, on all plans: EU hosting (Ireland primary, Germany backup) is marked as the default. US, AU and JP regions are Enterprise-only. AI processing and real-time video calls may be processed outside the region.

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (miro.md), evidence dated 2026-10-07.