Miro Trust Center

Welcome to Miro's Trust Center, where our commitment to data privacy and security is central to our operations. [Miro](https://miro.com/index/) provides a AI powered innovation workspace that enables distributed teams of any size to dream, design, and build the future together. This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data. Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Miro Trust Center
Header background

Miro Trust Center

Welcome to Miro's Trust Center, where our commitment to data privacy and security is central to our operations. Miro provides a AI powered innovation workspace that enables distributed teams of any size to dream, design, and build the future together.

This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data.

Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives.

security@miro.com

AI governance

AI and machine learning features are safeguarded by governance, privacy, and security controls to align with enterprise policies and compliance frameworks.

ISO 42001 management system

The organisation operates an audited framework dedicated to governing the lifecycle and risks of artificial intelligence systems

Administrator control over AI features

Enterprise administrators can enable or disable AI features at the organization or team level, enacting granular usage policies in line with internal governance needs.

AI activity audit logging

Comprehensive audit logs track all AI-related interactions and activities, providing an immutable record for monitoring, compliance, and policy enforcement.

Global AI scope coverage

Certification scope encompasses production and continuous improvement of AI-enabled SaaS across EMEA, USA and other key regions, ensuring consistent controls worldwide

Ongoing surveillance audits

Accredited auditors conduct periodic surveillance to confirm the AI management system continues to meet ISO requirements over time

AI data handling and training restrictions

Customer data is excluded from training AI models, and only opted-in, non-enterprise user data may be used for AI improvement, preserving privacy and regulatory compliance.

Built-in prompt redaction and moderation

Automated prompt redaction and customizable output moderation help protect against prompt injection, sensitive data leakage, and harmful content generation.

ISO/IEC 42001 certification for AI

AI systems development and operation are externally validated according to ISO/IEC 42001, demonstrating responsible design, risk management, and ethical safeguards.

Internal security procedures

Internal security practices and governance ensure consistency, accountability, and continuous improvement in protecting information and systems.

Annual risk assessment

Risks to confidentiality, integrity and availability are identified and scored using ISO and NIST methodologies, guiding mitigation plans

Annual risk assessment and review

A formal risk management process, reviewed at least annually, identifies, evaluates, and drives treatment of risks according to regulatory and customer requirements, ensuring the risk posture adapts to new threats.

Formal security policies

Comprehensive security policies aligned to ISO 27001:2022 and SOC 2 are maintained, reviewed, approved, and distributed at least annually to all employees and relevant third parties, ensuring ongoing relevance and employee awareness.

Semi-annual risk reviews

Risk registers are revisited twice a year to capture changes in the threat landscape and business operations

Incident response plan

Documented procedures outline roles, communication and evidence handling to ensure consistent response to security events

Incident response procedures

A documented incident response plan details structured procedures for detection, reporting, containment, communication, and post-incident analysis to minimize impact and drive continuous improvement.

Internal security audits and monitoring

Regular internal control assessments and audits validate that controls are effectively deployed, operational, and improved as necessary, providing assurance to management and clients.

Post-incident root cause analysis

Every significant incident triggers a lessons-learned review, driving continual control improvements

Cybersecurity insurance

An active policy transfers residual financial risk from severe cyber events, protecting both the company and its customers

Role-based responsibilities and accountability

Key information security roles and responsibilities are formally assigned, with management oversight, board-level involvement, and documented accountability for policy enforcement and control operation.

Access control

Strict access management policies and technical controls ensure only authorized, validated individuals can access systems and sensitive data.

Multi-factor authentication

All workforce and production accounts must use a second factor via the identity platform, significantly reducing the risk of credential compromise

Multi-factor authentication for all systems

Multi-factor authentication is enforced for all user and administrator accounts across production and corporate environments, reducing the risk of unauthorized access due to credential compromise.

Role-based access control

Permissions are assigned through an RBAC matrix that maps job roles to least-privilege groups, ensuring users receive only the access they need

Single sign-on integration

SAML-based SSO through the corporate identity provider streamlines account lifecycle management and enforces centralised security policies

Just-in-time privileged access

Teleport grants time-bound production access only after approval, limiting standing administrator privileges and improving accountability

Automated access reviews

User and administrator access privileges are reviewed at least biannually to validate appropriateness and minimize the risk of privilege creep.

Biannual access reviews

Access rights for all users are re-certified at least twice a year to verify continued business need and remove excess privileges

Account lockout and session timeout

Accounts lock after multiple failed login attempts, while idle sessions automatically expire after a defined period, limiting brute-force attacks and reducing exposure from unattended sessions.

Data security

Comprehensive data protection measures safeguard customer and confidential information throughout its entire lifecycle.

Encryption at rest

All data stores and backups are secured with cloud-native encryption keys managed by the provider, protecting information from unauthorised reading of physical media

Data classification and handling

Company-wide data classification schemes and policies establish protection requirements for each data category, enforcing handling rules and access restrictions based on sensitivity.

Encryption in transit

TLS 1.2 or higher is enforced at every network edge, ensuring data cannot be intercepted or tampered with while moving between clients and services

Encryption at rest and in transit

Sensitive data is encrypted both at rest and during transmission using industry-standard protocols and algorithms, ensuring confidentiality and integrity across all storage and transfer channels.

Data classification programme

A documented policy assigns sensitivity levels and required protections to each data type, enabling consistent handling across the organisation

Customer-controlled encryption keys

Enterprise customers can leverage encryption key management options, including bring-your-own-key capabilities, to maintain autonomy and visibility over their encrypted data.

Backup encryption and replication

Daily encrypted backups with four-hour snapshots are replicated to a secondary region, combining confidentiality with resilience

Secure data retention and disposal

Data retention periods and secure disposal procedures are defined and enforced, ensuring data is not retained longer than necessary and is irretrievably destroyed when no longer required.

Data protection by design and default

Data privacy and protection measures are embedded into product design, system development, and operational workflows to meet regulatory and compliance standards such as GDPR and CCPA.

Secure data deletion

Customer content is purged 30 days after contract termination, aligning with privacy commitments and minimising residual risk

Infrastructure security

Robust infrastructure design and layered controls enhance system resilience and reduce risks to core technology assets.

Web application firewall

A managed WAF inspects all inbound traffic and blocks malicious requests before they reach application workloads

Cloud infrastructure with strong regional controls

Primary systems and backups are hosted in leading public cloud environments with physical security validation, multiple regions for redundancy, and operational control over logical and network security.

Network segmentation and DMZ

Production, development and corporate networks are isolated with default-deny security groups, limiting lateral movement

Network segmentation and firewalls

Critical environments are segmented and protected by network firewalls, security groups, and allow-by-exception rules, minimizing the risk of lateral movement and unauthorized access.

Web application firewall and DDoS protection

A web application firewall inspects all inbound traffic to protect web applications from exploits and denial-of-service attacks, significantly strengthening perimeter defenses.

Infrastructure as code with CIS benchmarks

Systems are provisioned through scripted templates that apply industry-standard hardening baselines consistently and prevent drift

Default-deny security groups

Cloud firewalls start from a deny-all rule set and allow only approved ports and protocols, reducing the exposed attack surface

Continuous vulnerability and patch management

Automated vulnerability scanning, internal and third-party penetration testing, and patch deployment processes help identify and address security flaws before they can be exploited.

Annual penetration testing

Independent testers assess the environment each year, and identified issues are tracked to remediation, validating real-world security posture

Intrusion detection and monitoring

Comprehensive network and host-based intrusion detection systems continuously monitor for anomalies, triggering alerts, and enabling rapid incident response.

Product security

Security is embedded across the product lifecycle, from design to release, to ensure ongoing protection against emerging risks.

Secure software development lifecycle

A documented SDLC integrates security checkpoints, code review, static and dynamic analysis, and vulnerability testing into every phase of software development and deployment.

Secure development lifecycle policy

Documented standards guide design, coding, testing and deployment activities to embed security throughout the software lifecycle

Separation of development and production environments

Production systems are strictly segregated from development and test environments, reducing attack surface and preventing accidental introduction of code or data leakage.

Static code and dependency scanning

Automated SAST, secret scanning and dependency checks run in the CI pipeline to catch issues before code reaches production

Peer code reviews

All pull requests require approval from qualified reviewers, ensuring that security considerations are evaluated before merge

Automated dependency and secret scanning

Automated tools scan for vulnerable dependencies, hardcoded secrets, and misconfigurations, alerting teams prior to integration and production roll-out.

Third-party penetration testing

Annual assessments by independent specialists identify and validate application-layer weaknesses under real-world conditions

Annual third-party penetration testing

Accredited independent security firms conduct annual penetration testing for all production-facing systems, verifying resilience against real-world attack scenarios.

Public bug bounty programme

Continuous crowdsourced testing rewards researchers for responsibly disclosing vulnerabilities, amplifying security coverage

Bug bounty program

A public bug bounty program incentivizes external researchers to report security vulnerabilities, complementing internal testing and driving continuous improvement.

Business continuity and disaster recovery

Comprehensive procedures and resilient infrastructure ensure operational continuity, rapid recovery, and minimal data loss during major incidents or disruptions.

Documented disaster recovery plan

A formal, tested disaster recovery policy defines roles, responsibilities, and step-by-step procedures for restoring systems and data with minimal downtime and data loss.

Disaster recovery policy with defined RTO / RPO

The plan sets an eight-hour recovery time and four-hour recovery point for critical systems, giving customers clear availability guarantees

Automated backups and snapshots

Scripts create daily full backups and four-hour incremental snapshots for core datastores, preserving recent copies for rapid restoration

Automated, encrypted backups with multi-region storage

Critical data is backed up automatically, encrypted, and replicated to geographically separate data centers, with retention policies and quarterly restoration exercises.

Annual disaster recovery testing

Full failover exercises are conducted each year, with results documented and improvements tracked, proving the ability to meet recovery objectives

Defined recovery time and point objectives

Clear RTOs and RPOs for primary and secondary sites are documented and measured to meet contractual and operational requirements.

Multi-region replication

Data is continuously replicated to secondary cloud regions so that services can be restored even if a primary location becomes unavailable

99.5 % uptime service-level agreement

Contractual SLA commits to high availability and includes financial remedies, demonstrating confidence in operational resilience

Business continuity framework based on ISO 22301

The business continuity program encompasses planning, monitoring, regular testing, and continuous improvement to maintain service under adverse conditions.

Employee security and awareness

Employee-focused controls and continual security education reduce insider risk and create a strong culture of security and compliance.

Pre-employment background checks

All new hires undergo identity, employment, education and criminal screening before receiving system access, lowering insider risk

Mandatory background checks

Pre-employment background screening covers employment, education, identity, and, where permitted by law, criminal history to reduce hiring risk.

Annual security awareness training

All personnel complete mandatory security and privacy training at onboarding and annually, covering threats, data handling, phishing, malware, and corporate policies.

Security awareness training

Employees complete mandatory information-security courses during onboarding and annually thereafter to reinforce best practices

Secure coding training

Developers receive annual education aligned with OWASP guidelines to reduce the introduction of software vulnerabilities

Acceptable use and confidentiality agreements

Employees must sign and agree to acceptable use, confidentiality, and security policy acknowledgments as a condition of employment and system access.

Terminations and offboarding controls

Automated offboarding workflows ensure timely revocation of system and facility access, minimizing the risk of orphaned accounts or data leakage.

Progressive disciplinary policy

Documented sanctions for policy violations hold individuals accountable and deter risky behaviour

Certification reimbursement programme

Staff are encouraged to pursue recognised security credentials, supporting continuous improvement of organisational expertise

Disciplinary procedures for policy violations

Violations of security or acceptable use policies are investigated and subject to documented disciplinary actions up to and including termination or referral to authorities.

Physical and environmental security

Physical access to offices, assets, and sensitive areas is tightly controlled, monitored, and audited to prevent unauthorized entry or damage.

Badge and biometric access controls

Office entry points require card swipes or fingerprint scans, ensuring only authorised personnel enter sensitive areas

Badge-based access control and visitor management

Office facilities are secured with badge access, visitor badges, and registration logs, while entry to sensitive areas is reviewed quarterly and limited to authorized personnel.

Video surveillance and retention

Security cameras monitor entrances, exits, and sensitive areas, with footage retained for a minimum of 90 days to support investigations.

CCTV surveillance

Security cameras monitor entrances and critical rooms with footage retained for at least 90 days to support investigations

Visitor management and logging

Guests must pre-register, sign in, wear badges and remain escorted, creating an auditable trail of facility access

Physical media and device protection

Sensitive media and devices are securely stored and destructed according to policy, and all portable storage is required to use encryption and access controls.

Fire detection and suppression systems

Data-relevant office floors include automatic sprinklers and detectors, reducing the impact of fire on operations

Fire suppression and environmental controls

Critical offices are protected by fire detection, suppression systems, and controlled environments to mitigate physical threats and maintain operational uptime.

Secure media disposal

Locked shred bins and third-party destruction services ensure physical documents and retired devices are safely destroyed

Compliance and auditing

Certified compliance with leading standards, external and internal audits, and transparent practices demonstrate commitment to industry best practices.

SOC 2 Type II certification

An independent auditor confirms the design and operating effectiveness of security, availability and confidentiality controls over a year-long period, giving customers third-party assurance of the service’s control environment

ISO/IEC 27001:2022 certification

A certified and regularly audited information security management system (ISMS) covers all relevant operations, systems, and processes organization-wide.

ISO / IEC 27001:2022 certification

A formal information security management system is certified by an accredited body, demonstrating systematic risk management and continual improvement of security controls

SOC 2 Type II and SOC 3 attestation

Annual independent assurance reports attest to the design and operating effectiveness of controls against recognized trust criteria for security, availability, and confidentiality.

ISO 42001:2023 certification

The artificial intelligence management system is certified to the new ISO standard, evidencing structured governance and risk controls over AI-enabled services

GDPR, CCPA, and privacy regulation alignment

Security and privacy programs are designed and operated to meet regulatory obligations and client requirements in multiple jurisdictions.

Vendor due diligence and compliance management

A formal program evaluates, contracts, and reviews vendors for compliance with security, privacy, and regulatory requirements before and during the relationship.

Cyber Essentials certification

Certification to the UK government-backed scheme shows foundational cyber hygiene measures have been independently assessed and found effective

Annual internal control reviews

Management performs scheduled assessments of key controls between external audits to ensure they remain properly designed and functioning

Privacy policy transparency and data subject rights

A published privacy policy details personal data processing, third-party sharing, and user controls, enabling customers to comply with modern privacy regulations.

Third-party and supply chain management

Vendors and partners are systematically assessed, monitored, and contractually required to meet security, confidentiality, and privacy standards.

Vendor due-diligence assessments

Security, compliance and financial standing are reviewed before any new provider is approved, reducing supply-chain risk

Due diligence and onboarding assessments

Critical vendors are screened prior to engagement for security controls, regulatory adherence, financial stability, and service fit, mitigating third-party risk.

Annual vendor re-evaluation

Key suppliers are re-assessed each year, including review of their SOC 2 or ISO reports, to verify continued alignment with requirements

Annual review and reassessment of vendors

Vendors are reviewed annually for ongoing compliance, with up-to-date documentation (e.g., SOC reports, ISO certificates) and risk reassessment.

Contractual data protection agreements

Data processing addenda and non-disclosure agreements require vendors to meet stringent data protection and confidentiality commitments.

Non-disclosure agreements

All vendors sign legally binding NDAs before sensitive information is shared, protecting proprietary and customer data

Centralised vendor inventory

A maintained register records purpose, risk classification and contract status for every third-party relationship

Published subprocessor list and notification process

A list of authorized third-party data processors is maintained and updated, with customer notification and opt-out procedures for new subprocessors.

Contractual security obligations

Service agreements define roles, responsibilities, SLAs and data-protection clauses to enforce expected control levels

Device and endpoint security

Robust controls ensure all endpoint devices are protected against threats through technical enforcement and managed configurations.

Mobile device management

Jamf enforces configuration baselines, disk encryption and approved software on all corporate laptops and mobile devices

Device inventory and management

All company-owned and authorized endpoints are inventoried and managed, with policies enforced through mobile device management solutions.

Disk encryption

FileVault ensures that data on employee devices remains unreadable if hardware is lost or stolen

Antivirus and endpoint protection

Mandatory endpoint protection software with automatic updates, periodic scans, and prohibited removable media reduces malware risk and meets compliance standards.

Full disk encryption for endpoints

Laptop and mobile device disk encryption is enforced at the hardware or OS level to prevent data exposure in case of loss or theft.

Next-generation antivirus and EDR

SentinelOne provides real-time behaviour analysis, automatic quarantine and regular signature updates across servers and workstations

Forced operating system updates

Automated policies deploy OS and security patches within defined timelines, closing vulnerabilities promptly

Automatic screen lock and clear desk policy

Endpoints are configured for automatic screen lock, and staff are educated to clear workspaces of sensitive information when unattended.

Removable media restrictions

USB access is blocked or limited to read-only, mitigating the risks of malware introduction and data exfiltration

Change management

System changes are subject to rigorous processes for approval, testing, and review to minimize the risk of errors or vulnerabilities in production.

Infrastructure as code change process

All infrastructure modifications follow pull-request workflows with documented purpose, approvals and automated testing

Formal change management policy

All infrastructure and application changes must be formally requested, assessed for risk, tested in pre-production, and approved before implementation.

Infrastructure as code for deployments

Deployment pipelines leverage infrastructure as code for consistent, auditable, and rapid system provisioning and rollback, limiting human error.

Automated rollback plans

Deployment pipelines include predefined rollback steps, enabling rapid recovery if a change negatively impacts the service

Automated testing and rollback plans

Automated testing and defined rollback procedures are prerequisites for production changes, ensuring swift remediation in case of issues.

Segregated environments

Development, staging and production are isolated to prevent untested code from affecting live customer data

Separation of duties for code changes

Code reviews and separation of developer and approver roles prevent unauthorized or untested changes from reaching critical environments.

Continuous configuration reviews

Hardening standards and Terraform templates are revisited throughout the year to incorporate evolving best practices

Comprehensive testing standards

Unit, integration and regression tests are mandated for every change, decreasing the likelihood of defects reaching production

Monitoring and logging

Centralized monitoring and audit logging deliver visibility across environments, supporting threat detection, incident response, and compliance verification.

Centralised log aggregation

System and security logs are collected in searchable storage for at least one year, supporting investigations and compliance evidence

Centralized log collection and retention

Critical system and security event logs are collected centrally, retained according to policy, and protected from tampering, supporting investigations and compliance.

Security operations centre monitoring

A dedicated team reviews alerts around the clock, triages incidents and coordinates response actions to minimise impact

Continuous security monitoring

Automated security monitoring systems and real-time alerts enable rapid response to suspicious activity and potential breaches.

Audit logging and privileged access monitoring

All privileged administrative actions and critical system events are logged and monitored, with alerting on anomalous activities.

IDS / IPS coverage

Network and host-based intrusion detection systems analyse traffic and endpoints for malicious behaviour, providing layered visibility

File integrity monitoring

Cloud-native tooling tracks critical file changes across all systems and raises alerts on unauthorised modifications

Integration with security event and information management (SIEM)

Event data is integrated into SIEM solutions for advanced correlation, analysis, and case management by security teams.

Automated alerting and ticketing

OpsGenie and incident.io create actionable tickets for anomalous events, ensuring timely escalation to the appropriate responders