{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"canva","name":"Canva","domain":"canva.com","category":"Design tools","one_liner":"Canva, Inc. is an Australian multinational software company launched in 2013","trust_center_url":"https://trust.canva.com/","security_page_url":null,"url":"https://certreports.com/vendors/canva/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 19 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/canva/soc-2","evidence":[{"source_type":"trust_center","source_name":"Canva trust centre (Drata)","url":"https://trust.canva.com/","fetched_at":"2026-09-19 07:32:41.499494+00","content_hash":"f10884c395993c69d3ce235f6afc7d4bfea80282b0554b78bcbe312da2a94195","wayback_url":null,"quote":"SOC 2 Type 2","confidence":1}]},{"framework":"gdpr","framework_name":"GDPR","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a data processing agreement on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states GDPR on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/canva/gdpr","evidence":[{"source_type":"trust_center","source_name":"Canva trust centre (Drata)","url":"https://trust.canva.com/","fetched_at":"2026-09-19 07:32:41.499494+00","content_hash":"f10884c395993c69d3ce235f6afc7d4bfea80282b0554b78bcbe312da2a94195","wayback_url":null,"quote":"GDPR","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/canva/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Canva trust centre (Drata)","url":"https://trust.canva.com/","fetched_at":"2026-09-19 07:32:41.499494+00","content_hash":"f10884c395993c69d3ce235f6afc7d4bfea80282b0554b78bcbe312da2a94195","wayback_url":null,"quote":"PCI DSS","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/canva/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Canva trust centre (Drata)","url":"https://trust.canva.com/","fetched_at":"2026-09-19 07:32:41.499494+00","content_hash":"f10884c395993c69d3ce235f6afc7d4bfea80282b0554b78bcbe312da2a94195","wayback_url":null,"quote":"ISO/IEC 27001","confidence":1}]},{"framework":"soc-3","framework_name":"SOC 3","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a public SOC 3 report on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states SOC 3 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/canva/security","evidence":[{"source_type":"trust_center","source_name":"Canva trust centre (Drata)","url":"https://trust.canva.com/","fetched_at":"2026-09-19 07:32:41.499494+00","content_hash":"f10884c395993c69d3ce235f6afc7d4bfea80282b0554b78bcbe312da2a94195","wayback_url":null,"quote":"SOC 3","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Drata) as of 19 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-19","under_review":false,"source":"drata","url":"https://certreports.com/vendors/canva/security","evidence":[{"source_type":"trust_center","source_name":"Canva trust centre (Drata)","url":"https://trust.canva.com/","fetched_at":"2026-09-19 07:32:41.499494+00","content_hash":"f10884c395993c69d3ce235f6afc7d4bfea80282b0554b78bcbe312da2a94195","wayback_url":null,"quote":"CCPA","confidence":1}]}],"brief":{"summary":"According to Canva's trust centre, as of 19 Sep 2026, the company has a SOC 2 Type II report on file. Canva's trust centre also states, as of 19 Sep 2026, that the company meets GDPR requirements. As of 19 Sep 2026, Canva states on its trust centre that it holds PCI DSS. Canva states on its trust centre, as of 19 Sep 2026, that it holds ISO/IEC 27001. Canva's trust centre further states, as of 19 Sep 2026, that the company holds SOC 3 and meets CCPA/CPRA requirements.","bullets":["SOC 2 Type II report: vendor states on trust centre, as of 19 Sep 2026","SOC 3, PCI DSS, ISO/IEC 27001: vendor states on trust centre, as of 19 Sep 2026","GDPR and CCPA/CPRA: vendor states on trust centre, as of 19 Sep 2026"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 10:38:09.90144+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T19:51:01.349Z"}