What Asana publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.
"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.
Says it does not train AI on customer data
Asana's own words (asana.com/features/admin-security):
Explore apps Splunk Okta Microsoft Entra ID Google Workspace Microsoft Power Automate Microsoft Defender Mulesoft IBM App Connect ServiceNow Netskope 1 2 3 4 Asana is committed to AI safety and transparency Learn more Your data is protected Our AI partners do not use your data…
Our third-party LLM service providers are contractually prohibited by us from using customer data to train their models.
asana.com/terms/privacy-statement
| Certification or report | Mentioned on |
|---|---|
| SOC 2 Type II | asana.com/terms/data-processing |
| ISO/IEC 27001 | asana.com/terms/data-processing |
| ISO/IEC 27017 | asana.com/terms/data-processing |
| ISO/IEC 27018 | asana.com/terms/data-processing |
| ISO/IEC 27701 | asana.com/terms/data-processing |
| HIPAA | asana.com/features/admin-security |
Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.
A certification on a website is a claim. For anything sensitive, ask Asana for the SOC 2 report or ISO certificate.
Asana lists 46 subprocessors on asana.com/terms/subprocessors:
| SSO / SAML | Mentioned |
| SCIM provisioning | Mentioned |
| Multi-factor authentication | Mentioned |
| Encryption at rest | Mentioned |
| Encryption in transit | Mentioned |
| Penetration testing | Mentioned |
| Bug bounty / disclosure program | Not found |
| Audit logs | Mentioned |
| Data residency | Mentioned United States |
| security.txt contact | https://bugcrowd.com/asana |
| Trust / security center | asana.com/features/admin-security |
| Privacy policy | asana.com/terms/privacy-statement |
| Subprocessor list | asana.com/terms/subprocessors |
| Data processing agreement (DPA) | asana.com/terms/data-processing |
| AI policy | asana.com/ai-principles |
| Terms | asana.com/terms/terms-of-service |
| Status page | status.asana.com |
| Check | Points | Result |
|---|---|---|
| Security or trust page | 15 | Yes |
| Certifications listed | 20 | Yes |
| Privacy policy | 10 | Yes |
| Subprocessor list | 15 | Yes |
| DPA available | 10 | Yes |
| AI training policy stated | 15 | Yes |
| security.txt contact | 5 | Yes |
| Status page | 10 | Yes |
The score measures how much of a standard security review our reader could answer from Asana's public pages. It is not a rating of how secure Asana is, and a "No" can mean the document exists where our reader couldn't see it.
Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.
Airtable · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · DocuSign · Dropbox · Evernote · Figma · Fireflies.ai
Source: Asana's own public website (8 pages read on October 10, 2026). Stormap is not affiliated with Asana. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.