VendorScore · Project management · Data-access posture
A plain-language answer from Atlassian Trust, Legal and Support pages that name Trello. Trello's own security page returned no content, so treat this score as low-confidence.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Thin evidence, low confidence. Treat this score as provisional; see where public evidence is thin.
Yes, Atlassian can read your Trello boards by design. Trello uses Atlassian-managed encryption with no customer-key option and no E2EE, so access is limited by policy, not cryptography. Evidence is thin.
Scored configuration: Trello Enterprise on Atlassian Cloud (shared Atlassian infrastructure, privacy policy and subprocessor list). No customer-managed key option, so the default and scored configuration are the same.
Report confidence: Low. Trello's own security page returned no content; evidence comes from Atlassian umbrella pages that name Trello.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Atlassian's customer-managed keys don't cover Trello. The encryption FAQ lists only Jira, Jira Service Management and Confluence.
Evidence: Atlassian encryption FAQTrello isn't in Atlassian's data-residency scope, which covers Jira, JSM, Jira Product Discovery, Loom and Confluence.
Evidence: Understand data residencyOur report flags these gaps in Trello's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, Atlassian can read your Trello boards by design. Trello uses Atlassian-managed encryption with no customer-key option and no E2EE, so access is limited by policy, not cryptography. Evidence is thin. VendorScore rates Trello 50/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Trello Enterprise on Atlassian Cloud (shared Atlassian infrastructure, privacy policy and subprocessor list). No customer-managed key option, so the default and scored configuration are the same.
Trello data is encrypted, but not with your keys. Atlassian says data drives holding customer data and attachments in Trello "use full disk, industry-standard AES-256 encryption at rest", with TLS 1.2+ in transit and keys in the cloud provider's KMS. Atlassian's BYOK/CMK covers only Jira, Jira Service Management and Confluence, not Trello. There's no E2EE.
Public docs don't confirm Trello's process. Atlassian says "only authorized Atlassians have access to customer data stored within our applications" and requires explicit consent through a consent control checker before support access, but its examples are Jira and Confluence and it doesn't state that Trello uses the same checker. Outsourced support providers e-Core and Telus are listed for Trello and handle data shared in support-ticket attachments.
Atlassian's AI trust page, which applies across its products, says: "Atlassian does not share customer metadata or in-app data with our third-party-hosted LLM providers for them to use to train or improve their services." Atlassian may fine-tune open-source models on de-identified metadata "subject to data contribution settings". Trello-specific AI data handling isn't documented, so the Trello default is Unknown.
VendorScore doesn't certify compliance; Atlassian publishes a DPA at https://www.atlassian.com/legal/data-processing-addendum. Trello sits under Atlassian's legal and privacy program (trello.com/privacy redirects to the Atlassian Privacy Policy). The DPA gives 30 days' notice of new subprocessors; if you object, your remedy is termination.
Trello appears in Atlassian's subprocessor list with AWS (hosting), Clumio (S3 backup), Bird and Twilio (notifications), Cloudflare (CDN) and e-Core/Telus (support). Databricks is listed as an infrastructure provider for machine learning development, processing and training, and AWS Bedrock, Google Vertex AI and OpenAI apply when Atlassian Intelligence or Rovo is enabled. The list is published at https://www.atlassian.com/legal/sub-processors.
Public docs don't offer it. Atlassian's data-residency documentation covers Jira, Jira Service Management, Jira Product Discovery, Loom and Confluence only; Trello isn't listed.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (trello.md), evidence dated 2026-10-07.