This article answers frequently asked questions about Miro's data privacy and security.
Where is Miro data stored?
Under EU Data Center Residency, the compute infrastructure and all Customer Content (production data, backup data and metadata) is hosted within the EU by default.
✏️ Data residency is also available in Australia, Japan, and the United States. To learn more, see Data residency at Miro.
Can anyone at Miro access my boards?
No, without your request and permission no one can view your board content. Miro restricts access to the production environment to a limited number of IP addresses and employees.
The content we create is very sensitive. How do we make sure we don't share boards outside of our Miro teams?
Miro Enterprise provides the following features to help you ensure team members can collaborate in Miro while maintaining security and privacy.
- Sharing policy allows you to set a list of trusted domain. Only users with emails in listed domains can be invited to your subscription.
- Link access controls allow you to disable users from sharing boards via a public link, ensuring only users who are part of your subscription can access specific boards.
- Domain control allows you to verify ownership of corporate domains and provides the control needed to maintain a centrally-managed Enterprise subscription.
How do I make sure that only I have access to my board?
Learn how to create a private board. You can always check who has access to your board on the board share dialog.
Does Miro sell data to third-party vendors?
No, we do not sell our user data as stated in our Privacy Policy.
Does Miro govern Engage activity data?
Yes. Engage activities, and activities data, are hosted on Miro infrastructure and covered by Miro's data policies.
I need my clients to allow access to my Miro board but their firewall may block it. How do they allow access?
Learn how to add Miro to allowed domains.
Does Miro comply with requirements under the General Data Protection Regulation (GDPR)?
Yes, please check our Privacy Policy for more information.
Does Miro provide the same level of data protection to all users?
Yes, regardless of which Miro plan rest assured your data is securely managed and held. With TLS 1.2 or higher for transit and AES 256 at rest, in compliance with GDPR and CCPA standards, your data is secured to the highest levels at no additional cost.
For advanced security, privacy, and administrative controls, please contact us to learn more about Miro Enterprise.
Where can I access legal information about Miro?
You can find our Terms of Service, Privacy Policy, Data Processing Addendum (DPA) and Cookies Policy in the Miro Trust Center.
Where can I download the SOC3 report?
Read and download our System and Organization Controls Report (SOC 3).
Does Miro have a bug bounty program?
Yes. Miro runs two security programs on Bugcrowd:
- (Rewarded) Bug bounty program
Sign up and participate through the Bugcrowd platform if you're a security researcher who wants to actively test Miro and earn rewards for qualifying vulnerabilities. This is a private, invitation-based program, and only valid submissions made through Bugcrowd are eligible for a reward. - (Not rewarded) Vulnerability Disclosure Program
Use our Vulnerability Disclosure Program if you've found a security issue and just want to report it. The disclosure program is open to everyone, offers no monetary reward, and gives you a secure channel to report vulnerabilities and help keep Miro safe.