Compliance frameworks, security audits, and quality certifications this company maintains.
Asana maintains SOC 2 Type II attestation covering security, availability, and confidentiality trust service criteria, providing enterprise customers assurance that Asana's work management platform securely handles sensitive project and organizational data.
Asana holds ISO 27001 certification for its information security management system, demonstrating systematic controls over the security of its cloud infrastructure and the work data entrusted to Asana by 150,000+ enterprise customers.
Asana's platform is designed for GDPR compliance, offering EU data residency options, Standard Contractual Clauses for international transfers, and Data Processing Agreements that govern how Asana processes personal data on behalf of European enterprise customers.
Asana complies with the California Consumer Privacy Act, providing enterprise customers with data subject request capabilities and privacy controls required for organizations managing California-based employee and customer data within Asana projects.
Asana offers HIPAA-eligible configurations with Business Associate Agreements for healthcare enterprise customers, enabling clinical operations and administrative teams to manage workflows involving protected health information within the Asana platform.
Regulatory
FedRAMP Moderate
In ProgressAsana is pursuing FedRAMP Moderate authorization to serve U.S. federal government agency customers with work management capabilities, with the authorization process ongoing to meet federal security requirements for cloud services handling controlled data.
Asana has achieved CSA STAR Level 1 self-assessment certification, demonstrating transparency in its cloud security controls and enabling enterprise customers to evaluate Asana against the Cloud Security Alliance's Cloud Controls Matrix.
Privacy
Privacy Shield Successor (DPF)
CompliantAsana participates in the EU-U.S. Data Privacy Framework (DPF), committing to its principles for handling personal data transferred from the EU to Asana's U.S.-based infrastructure as a supplemental safeguard alongside Standard Contractual Clauses.
Asana maintains PCI DSS Level 1 compliance for payment card data handled in its subscription billing workflows, ensuring that enterprise customer payment information processed through Asana commerce systems meets the highest card industry security standards.
Asana designs its work management platform to meet WCAG 2.1 AA accessibility standards, enabling users with visual, motor, and cognitive disabilities to fully participate in team project planning and collaboration using Asana.