Compliance frameworks, security audits, and quality certifications this company maintains.
Miro maintains SOC 2 Type II certification, providing enterprise customers with assurance that Miro's cloud infrastructure for whiteboard data storage, real-time collaboration, and board sharing meets rigorous controls for security, availability, and confidentiality.
Miro holds ISO 27001 certification for its information security management system, ensuring that enterprise customers' whiteboard content, user data, and API integrations are protected under internationally recognized security standards.
Miro is GDPR-compliant, offering EU enterprise customers data processing agreements, EU data residency options, data subject request workflows, and standard contractual clauses — enabling companies to use Miro for sensitive strategic and product planning work without violating European data protection law.
Miro supports CCPA compliance for California-based enterprise customers, providing data deletion workflows, opt-out mechanisms, and privacy disclosures so companies can deploy Miro company-wide while meeting California consumer privacy obligations.
Miro offers HIPAA-compliant configuration for healthcare enterprise customers through a Business Associate Agreement (BAA) program, enabling hospitals, health systems, and healthcare SaaS companies to use Miro for clinical workflow planning and patient journey mapping.
Miro is pursuing FedRAMP authorization to enable US federal government agencies to use Miro's visual collaboration platform for mission planning, process mapping, and distributed team workshops in compliance with federal cloud security requirements.
Miro holds ISO 27017 certification for cloud service security controls, providing enterprise customers with additional assurance that Miro's cloud-specific security practices meet international standards for protecting data in multi-tenant SaaS environments.
Miro is ISO 27018 certified for protection of personally identifiable information in cloud services, demonstrating that Miro's handling of user data within its whiteboard platform meets international privacy standards for cloud PII processing.
Miro Enterprise supports SAML 2.0 SSO with identity providers including Okta, Azure AD, and Google Workspace, enabling large organizations to provision and deprovision Miro access automatically as part of their centralized identity management infrastructure.
Security
Penetration Testing
CertifiedMiro undergoes annual third-party penetration tests of its whiteboard infrastructure, real-time collaboration APIs, and board sharing systems, with results made available to enterprise customers under NDA as part of Miro's security review process.