Asana
work-management · asana.com · last read 2026-10-07
Identity
No identity observation recorded yet.
Data location
| Region | EU data location | Minimum plan | Source | Observed |
|---|---|---|---|---|
| EU | Enterprise only | Enterprise | help.asana.com | 2026-10-05 |
EU: Data residency (including Frankfurt, Germany) is available to be purchased as an add-on in Enterprise organizations and divisions and is included in Enterprise+ tiers. Customers must contact the Sales team to opt in to data residency.
Subprocessor chain
33 third parties · 17 of the vendor's own group companies · 34 with a country outside the EEA · all read 2026-10-05
| Subprocessor | Country | Purpose |
|---|---|---|
| Amazon Web Services Inc (AWS Bedrock) | US, EU | Artificial intelligence enabled functionality |
| Amazon Web Services, Inc. | US, DE, IE, AU, JP | Cloud service provider |
| Amplitude, Inc. | US | Analytics and Data Visualization |
| Anthropic, PBC | — | — |
| Anthropic, PBC | — | AI chat functionality |
| Anthropic, PBC | US | Artificial intelligence enabled functionality |
| Anthropic, PBC | US | Artificial intelligence functionality for customer support |
| Anthropic, PBC | US | LLM Provider |
| Apple, Inc. | US | Mobile push notifications |
| AWS Bedrock | — | — |
| Cloudflare, Inc. | US | Model Context Protocol (MCP) server |
| Databricks, Inc. | US | Data Warehouse |
| Databricks, Inc. | — | data warehouse |
| Fireworks AI, Inc. | US | Cloud service provider |
| Google, LLC | US | Mobile push notifications |
| Google, LLC (Gemini Enterprise Agent Platform) | US, BE, DE, GB, ES, IT, CH | Artificial intelligence enabled functionality for Google Gemini |
| Google, LLC (Google Cloud) | US, BE, DE, GB, ES, IT, CH | Cloud service provider |
| Hyperdoc Inc. (Recall.ai) | US, DE, JP | Transcription service provider |
| Intercom, Inc | US | Artificial intelligence chatbot for customer support |
| KMC Solutions | PH | — |
| OpenAI OpCo, LLC | US, NO | Artificial intelligence enabled functionality |
| OpenAI OpCo, LLC | US, NO | Artificial intelligence functionality for customer support |
| OpenAI OpCo, LLC | US, NO | LLM Provider |
| OpenAI, LLC | — | — |
| OpenAI, LLC | — | AI chat functionality |
| Segment (Twilio, Inc.) | US | Customer Data Platform |
| Segment (Twilio, inc.) | — | customer data platform |
| Service Cloud (Salesforce, Inc.) | US | Customer and sales support |
| Service Cloud (Salesforce, Inc.) | — | customer and sales support |
| Tableau Software, LLC (Salesforce, Inc.) | US | Analytics and Data Visualization |
| Tray.io | — | — |
| Tray.io | US | Integration infrastructure provider |
| Vimeo, LLC | US | Video messaging |
Asana's own group companies listed as subprocessors (17)
| Company | Country | Purpose |
|---|---|---|
| Asana France SAS | FR | — |
| Asana Germany Gmbh | DE | — |
| Asana Ireland Technology Limited | IE | — |
| Asana Japan KK | JP | — |
| Asana Poland sp. z o.o | PL | — |
| Asana Poland sp. z o.o | — | — |
| Asana Software Australia Pty Ltd | AU | — |
| Asana Software Canada Ltd | CA | — |
| Asana Software Iceland ehf | IS | — |
| Asana Software Ireland Limited | IE | — |
| Asana Software Singapore Pte Ltd | SG | — |
| Asana Software UK Limited | GB | — |
| Asana Switzerland GmbH | CH | — |
| Asana Switzerland GmbH | CH | — |
| Asana, Inc. | US | — |
| Eigen, Inc. dba StackAI | US | — |
| KMC Solutions | PH | — |
The count outside the EEA is arithmetic over the country column, not a judgement about lawfulness. A transfer outside the EEA can be perfectly lawful; whether this one is depends on your use, not on the vendor.
Assurance
| Scheme | Status | Scope | Source | Observed |
|---|---|---|---|---|
| California Consumer Privacy Act · CCPA | Claimed | — | asana.com | 2026-10-05 |
| CSA STAR Level 1 · CSA | Claimed | Cloud security controls compliance self-assessment | asana.com | 2026-10-05 |
| GDPR | Claimed | Data protection and data subject rights for EU residents | asana.com | 2026-10-05 |
| General Data Protection Regulation · GDPR | Claimed | — | asana.com | 2026-10-05 |
| HIPAA | Claimed | Protection of patient health information in the United States | asana.com | 2026-10-05 |
| ISO/IEC 27001:2022 · ISO27001 | Claimed | Global standard for information security management systems | asana.com | 2026-10-05 |
| ISO/IEC 27017:2015 · ISO27017 | Claimed | Code of practice for information security controls for cloud services | asana.com | 2026-10-05 |
| ISO/IEC 27018:2019 · ISO27018 | Claimed | Code of practice for protecting personally identifiable information (PII) | asana.com | 2026-10-05 |
| ISO/IEC 27701:2019 · ISO27701 | Claimed | Privacy information management standard supporting compliance with global privacy laws | asana.com | 2026-10-05 |
| APPI and other global privacy laws | Claimed | — | asana.com | 2026-10-05 |
| FERPA | Claimed | Privacy rights for educational information and records | asana.com | 2026-10-05 |
| GLBA | Claimed | Privacy Rule and Safeguards Rule for financial institutions | asana.com | 2026-10-05 |
| US State Privacy Laws | Claimed | Compliant with relevant US state privacy laws in California, Colorado, Virginia, and more | asana.com | 2026-10-05 |
| SOC 2 (Type 2) · SOC2T2 | Claimed | Security, availability, confidentiality, and privacy trust services criteria | asana.com | 2026-10-05 |
| SOC 3 · SOC3 | Claimed | Overview of Service Organization Controls | asana.com | 2026-10-05 |
Claimed means the vendor asserts the scheme on its own page and offers nothing further. Available on request means the report or certificate exists but sits behind a request, a login or an NDA. Neither is a certificate we have seen. That is a distinction an auditor makes, so we make it too.
Official registers
| Register | Offering, as the register names it | Status | Level | Valid until | Observed |
|---|---|---|---|---|---|
| Data Privacy Framework List (US) | EU-U.S. Data Privacy Framework · Asana | Active | non-HR data | 2027-08-12 | 2026-10-07 |
| Data Privacy Framework List (US) | Swiss-U.S. Data Privacy Framework · Asana | Active | non-HR data | 2027-08-12 | 2026-10-07 |
| Data Privacy Framework List (US) | UK Extension to the EU-U.S. DPF · Asana | Active | non-HR data | 2027-08-12 | 2026-10-07 |
| FedRAMP Marketplace (US) | Asana · Asana Inc. | FedRAMP In Process | Moderate | — | 2026-10-07 |
- ACN qualified cloud (Italy): checked 2026-10-07, no entry under Asana
- Data Privacy Framework List (US): checked 2026-10-07, 3 entries under Asana
- FedRAMP Marketplace (US): checked 2026-10-07, 1 entry under Asana
What the authority publishes, not what the vendor claims. An entry covers the offering it names and nothing else: a FedRAMP authorisation for a government edition says nothing about the commercial service. No entry is not a finding about security - most vendors never apply - and an entry filed under a name not listed above would not have been found.
Support window
Not yet collected. This row will say not declared only once we have read a lifecycle or security page and found no period stated — see support windows.
Documents
| Document | Disclosure | Transcription | HTTP | Observed |
|---|---|---|---|---|
| certifications | Public | full | 200 | 2026-10-05 |
| residency | Public | full | 200 | 2026-10-05 |
| subprocessors | Public | full | 200 | 2026-10-05 |
History
Nothing has moved since we started watching this vendor on 2026-10-05. Changes appear here only after a human has reviewed them.