VendorScore · Project management · Data-access posture

Can Trello read your boards?

A plain-language answer from Atlassian Trust, Legal and Support pages that name Trello. Trello's own security page returned no content, so treat this score as low-confidence.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Thin evidence, low confidence. Treat this score as provisional; see where public evidence is thin.

Yes, Atlassian can read your Trello boards by design. Trello uses Atlassian-managed encryption with no customer-key option and no E2EE, so access is limited by policy, not cryptography. Evidence is thin.

50 / 100 overall

Scored configuration: Trello Enterprise on Atlassian Cloud (shared Atlassian infrastructure, privacy policy and subprocessor list). No customer-managed key option, so the default and scored configuration are the same.

Report confidence: Low. Trello's own security page returned no content; evidence comes from Atlassian umbrella pages that name Trello.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Trello's public documentation:

  • trello.com/security returned only an empty JavaScript shell; no Trello-specific security whitepaper was reviewed.
  • Whether Atlassian's support consent checker, Guard audit logs or SOC 2 scope cover Trello is Unknown. Confirm with Atlassian.
  • Trello-specific AI data handling isn't separately documented; the default of Atlassian's data-contribution setting is Unknown.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Trello data access, AI training, GDPR and residency

Can Trello read your boards?

Yes, Atlassian can read your Trello boards by design. Trello uses Atlassian-managed encryption with no customer-key option and no E2EE, so access is limited by policy, not cryptography. Evidence is thin. VendorScore rates Trello 50/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Trello Enterprise on Atlassian Cloud (shared Atlassian infrastructure, privacy policy and subprocessor list). No customer-managed key option, so the default and scored configuration are the same.

Is Trello encrypted? Can I use my own keys (BYOK) with Trello?

Trello data is encrypted, but not with your keys. Atlassian says data drives holding customer data and attachments in Trello "use full disk, industry-standard AES-256 encryption at rest", with TLS 1.2+ in transit and keys in the cloud provider's KMS. Atlassian's BYOK/CMK covers only Jira, Jira Service Management and Confluence, not Trello. There's no E2EE.

Can Atlassian employees see my Trello boards?

Public docs don't confirm Trello's process. Atlassian says "only authorized Atlassians have access to customer data stored within our applications" and requires explicit consent through a consent control checker before support access, but its examples are Jira and Confluence and it doesn't state that Trello uses the same checker. Outsourced support providers e-Core and Telus are listed for Trello and handle data shared in support-ticket attachments.

Does Atlassian AI train on my Trello data?

Atlassian's AI trust page, which applies across its products, says: "Atlassian does not share customer metadata or in-app data with our third-party-hosted LLM providers for them to use to train or improve their services." Atlassian may fine-tune open-source models on de-identified metadata "subject to data contribution settings". Trello-specific AI data handling isn't documented, so the Trello default is Unknown.

Is Trello GDPR compliant? Where is the Trello DPA?

VendorScore doesn't certify compliance; Atlassian publishes a DPA at https://www.atlassian.com/legal/data-processing-addendum. Trello sits under Atlassian's legal and privacy program (trello.com/privacy redirects to the Atlassian Privacy Policy). The DPA gives 30 days' notice of new subprocessors; if you object, your remedy is termination.

Who are Trello's subprocessors?

Trello appears in Atlassian's subprocessor list with AWS (hosting), Clumio (S3 backup), Bird and Twilio (notifications), Cloudflare (CDN) and e-Core/Telus (support). Databricks is listed as an infrastructure provider for machine learning development, processing and training, and AWS Bedrock, Google Vertex AI and OpenAI apply when Atlassian Intelligence or Rovo is enabled. The list is published at https://www.atlassian.com/legal/sub-processors.

Can I keep Trello data in the EU (data residency)?

Public docs don't offer it. Atlassian's data-residency documentation covers Jira, Jira Service Management, Jira Product Discovery, Loom and Confluence only; Trello isn't listed.

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (trello.md), evidence dated 2026-10-07.