Wrike security review: SOC 2, AI training & subprocessors

What Wrike publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
100/100
SOC 2
SOC 2 Type II
ISO 27001
Claimed
Trains AI on your data?
See quotes
Subprocessors
37 listed
DPA
Not found

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Wrike train AI on your data?

Statements differ between pages

Wrike's own words (wrike.com/security/terms):

Wrike does not use Customer Data or permit others to use Customer Data to train the machine learning methods and data models underlying Wrike AI.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
“Wrike AI” means any features or functionality made available by Wrike as part of, or in the course of providing, the Service or as an Add-On that utilize generative artificial intelligence trained by machine learning using Wrike and/or third-party data models to create new co…
wrike.com/security/terms
Customer’s use of Wrike AI does not grant Wrike any right or license to use Customer Data in a manner that is inconsistent with the Agreement or to train Wrike’s machine learning methods or data models unless otherwise agreed to by Customer.
wrike.com/security/terms

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications Wrike claims

Certification or reportMentioned on
SOC 2 Type IIwrike.com/security/privacy
ISO/IEC 27001wrike.com/security/privacy
ISO/IEC 27018wrike.com/security/privacy
HIPAAwrike.com/security/terms

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Wrike for the SOC 2 report or ISO certificate.

Wrike subprocessors

Wrike lists 37 subprocessors on wrike.com/legal/subprocessors-list:

Security features mentioned

SSO / SAMLNot found
SCIM provisioningNot found
Multi-factor authenticationNot found
Encryption at restNot found
Encryption in transitNot found
Penetration testingNot found
Bug bounty / disclosure programNot found
Audit logsMentioned
Data residencyMentioned EU, European Union, US
security.txt contacthttps://www.wrike.com/security/report/

Key documents

Trust / security centerwrike.com/security
Privacy policywrike.com/security/privacy
Subprocessor listwrike.com/legal/subprocessors-list
Data processing agreement (DPA)Not found
AI policyNot found
Termswrike.com/security/terms
Status pagestatus.wrike.com

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15Yes
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from Wrike's public pages. It is not a rating of how secure Wrike is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Productivity vendors

Airtable · Asana · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · DocuSign · Dropbox · Evernote · Figma

Source: Wrike's own public website (5 pages read on October 10, 2026). Stormap is not affiliated with Wrike. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.