The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Wrike is a work management platform that delivers real-time project and task insight to its
For each regulation, how many of the requirements it places on your vendors Wrike’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
14 documents listed on Wrike’s trust centre
security.wrike.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where are your servers located and how is the infrastructure secured ?
“Global Presence Wrike hosts its mission-critical servers in dedicated cages within data centers located in the US and EU, hosting is hybrid, combining private and public clouds. USA (for our US clients): - Energy Group Networks, LLC, our primary data center in the US is SOC2 compliant. The facility is located in Santa Clara, California. - Google Cloud Platform and Amazon Web Services in the USA. The facilities are...”
Regions named: EU, US, Franceas of 21 Sep 2026Source
Encryption
Do you encrypt data at rest and in transit ?
“Data Encryption Wrike uses Transport Layer Security (TLS) 1.2 with a preferred AES 256 bit algorithm in CBC mode and 2048-bit server key length with industry-leading modern browsers. When you access Wrike via web browser, mobile applications, email add-in, or browser extension, TLS technology protects your information using both server authentication and data encryption. This is equivalent to network security meth...”
as of 21 Sep 2026Source
Encryption
Do you support customer managed encryption / BYOK ?
“Wrike Lock The Wrike Lock add-on for Wrike’s Enterprise plan adds an additional layer of security by encrypting the encryption keys for Wrike workspace data (including tasks, folders, projects, workflows, and comments) and Wrike attachments with a master Customer-Managed Key (CMK), which is stored in Amazon Web Services’ Key Management Service (AWS KMS) or Microsoft Azure Key Vault (MS AKV). By using AWS KMS or MS...”
as of 21 Sep 2026Source
Use of customer data to train models
Do you use customer data to train AI models ?
“No, customer data is NOT used to improve AI models including Microsoft and other third-party products and services, and machine learning models. The manner in which Microsoft Azure OpenAI Service processes data and the relevant protections and security measures are set out in Microsoft's Data, Privacy, and Security Policy for the Azure OpenAI Service. General data, such as anonymized search-related historical usag...”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.