
Canva
Security and trust center evidence
Canva, Inc. is an Australian multinational software company launched in 2013
Summary
Canva has 6 vendor-stated rows in the CertReports index, last verified 19 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 Type 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
Canva states it holds a SOC 2 Type II report. Canva states it holds a data processing agreement. Canva states it holds a PCI DSS attestation of compliance. Canva states it holds an ISO/IEC 27001 certificate.
- SOC 2: Vendor states SOC 2 Type 2 on its trust centre (as of 19 Sep 2026)
- GDPR: Vendor states GDPR on its trust centre (as of 19 Sep 2026)
- PCI DSS: Vendor states PCI DSS on its trust centre (as of 19 Sep 2026)
Facts only, each dated; nothing here is inferred, scored or advised.
Evidence count
0verified rows
Compliance grid
SOC 2Vendor-statedVendor states SOC 2 Type 2 on its trust centre
as of 19 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 19 Sep 20261 source
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 19 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 19 Sep 20261 source
SOC 3Vendor-statedVendor states SOC 3 on its trust centre
as of 19 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 19 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.