Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Canva, your compliance team needs documented proof they can be trusted. ThirdProof investigated Canva across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
24 sources queried. 80% confidence. Every Canva investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Canva's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 34% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Canva is ISO 27001 certified and undergoes periodic external surveillance and recertification audits.
Q41
Not found in FedRAMP marketplace
Q40
Canva does not sign Business Associate Agreements and is not HIPAA compliant, with no indication of plans to become compliant.
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Canva's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Canva is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
21
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Canva
Canva (canva.com) is a well-established graphic design and visual communications platform that presents a moderate overall risk posture, consistent with its Tier 3 rating. The vendor is a globally recognized brand with a 24-year domain history, clean sanctions screening, and no current security or regulatory enforcement concerns. Canva demonstrates several meaningful security strengths:
Independence Statement
All evidence in this report was sourced independently through external data providers, public registries, and open-source intelligence — the vendor had no participation in or knowledge of this investigation.
5 findings identified for Canva
CANVA INDIA PRIVATE LIMITED was first registered in the LEI system less than 1 year ago (2025-11-21T17:36:01Z).
A critical data source was unavailable during this investigation. Manual verification is recommended.
canva.com is missing 3 recommended security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options.
2 article(s) mention "Canva" with risk keywords, severity reduced due to article age: "Aussie tech darling Canva hacked" (Information Age | ACS) https://news.google.com/rss/articles/CBMifEFVX3lxTE1qdDZsMGJBd2VvY19KdGhuSXFMYUp5VXJGWHlBWHpwaTd5NW1pNmd2OHQzLUgySW1ZN3Y2b19IUzNGMnV6ZThyMTQ2NnF5bXJoWmx6bzVVMnlNY3V0ajU0RlRyUnd4RW00SlAtcVFOczV2R09XWWxtYzU0MXg?oc=5; "Canva – Online web development firm in Australia suffers hacking incident" (iZOOlogic) https://news.google.com/rss/articles/CBMilwFBVV95cUxQLVliaTZGaVFHQnBkdGhDTG9aZ1p3RGZ2WmxteDk4R2JCbkk2RTdvemZGLVV3RnozVHltNVJ5elVsUV9LMmxGNktkOGU2LTZ2RzJKeUJtUkw4Y1Jsbmh1TGx3S0toS0JGTkpxdnh3SURWM2VYeFZKZTgyM2RaOUoxWWlDRXpiajZqU0VPaTd6enExVTVTUk80?oc=5
canva.com may use customer data for AI training unless customers opt out. Review the opt-out process.
24 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (24+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Notable Tech Community Presence
Tech Community Sentiment →Minimal Tech Community Discussion
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Certificate Data from TLS Handshake
Certificate Transparency →Web Archive History Unavailable
Web Archive History →Domain in 13 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: PCI DSS
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: CCPA
Trust & Compliance Page Scan →Subprocessor Page Found, No Entries Parsed
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for Canva
Request Canva's SOC 2 Type II report and bridge letter — contact their security team via https://trust.canva.com, which indicates audit reports are available on request. Ask for the most recent report period (ideally covering the last 12 months) and a bridge letter confirming no material changes since issuance.
Exercise the AI data opt-out before deploying Canva to users who work with sensitive or proprietary content — review account privacy settings or contact Canva's privacy team. Confirm the opt-out scope in writing via their DPA.
Manually review the subprocessor list at https://trust.canva.com/subprocessors to identify downstream data processors. Cross-reference any AI, analytics, or infrastructure providers against your organization's approved third-party list and GDPR Article 28 requirements.
Request Canva's ISO/IEC 27001 certificate — ask for the certificate number, issuing body, and expiry date, then independently verify it on IAF CertSearch (https://www.iafcertsearch.org) to confirm the certification is active and in scope.
Ask Canva's security team for a brief description of the 2019 breach remediation — specifically, what controls were implemented post-incident. This is standard due diligence for any vendor with a known historical breach and will support documentation in your vendor risk register.
Obtain Canva's Data Processing Agreement (DPA) to confirm GDPR and CCPA commitments are contractually binding — Canva's trust page references both frameworks, but regulatory compliance claims require contractual backing for your organization's use case.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Canva? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Canva on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Canva's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Canva a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Canva appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Canva's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Canva's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Canva claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Canva depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Canva appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate Canva and every other vendor in your stack — average report time: 7 minutes. Get Canva's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Canva across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.