Trello

Australia · trello.com · 51 vendors

Trello is a web-based, Kanban-style list-making application and project management tool. It enables teams to organize tasks, workflows, and projects visually using boards, lists, and cards. The platform facilitates real-time collaboration and helps users track progress efficiently.

Resilience scores

Disruption prediction

Trello has a 56% probability of disruption in the next 6 months.

All systems operational (last checked 2026-09-18 16:25 UTC)

24 of Trello's 51 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 51 sub-vendors.

Insights

Last updated 2026-08-15 · revision 10

51 direct vendors, 378 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Trello exhibits very high migration readiness, scoring 90. This is primarily due to its highly modern and flexible internal tech stack, which is "Cloud-only (SaaS)" and built on "AWS" using a "Microservice Architecture." This architecture inherently promotes modularity, portability, and scalability, making it significantly easier to migrate or re-platform components without extensive re-engineering. The use of "REST API" and "Webhooks" further facilitates seamless integration and data transfer, which are critical for any migration effort. Trello's robust regulatory compliance framework, including adherence to GDPR, SOC2, and ISO 27001, means established processes for data governance and security are already in place, simplifying the task of maintaining compliance in a new environment. Furthermore, the company's ability to offer data residency options and its global data center operations with legal safeguards (EU Standard Contractual Clauses, EU-U.S. Data Privacy Framework) provide crucial flexibility in meeting diverse data location requirements during a migration. Financially, the high concentration of "Subscription Revenue" (87%) suggests strong financial stability, enabling the company to fund potential migration initiatives. The primary unknown is the "Vendor Lock-in Risk," as the data states "Total Vendors: 0" but "Total Services: 75," which is contradictory. While the microservice architecture generally reduces vendor lock-in, the specific nature and dependencies of these 75 services are not detailed. However, the overall architectural choices and established compliance posture position Trello for a highly efficient and successful migration.

Compliance

9 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

Trello/Atlassian operates as a digital infrastructure and cloud service provider with significant EU operations, which places it in scope for NIS2 as a 'Digital Provider' (specifically a cloud computing service provider and online marketplace/platform). Atlassian far exceeds the size thresholds (50+ employees, €10M+ turnover). Risk is Medium because: (1) NIS2 transposition deadlines across EU member states were October 2024, and enforcement is still maturing; (2) Atlassian's classification as an 'Important Entity' (digital provider) rather than 'Essential Entity' carries somewhat lower immediate enforcement risk; (3) Atlassian has existing ISO 27001 and SOC2 certifications that partially address NIS2 technical requirements. A formal NIS2 gap assessment is required to confirm full compliance status.

Evidence: https://www.atlassian.com/trust/compliance, https://www.atlassian.com/trust/security/security-practices, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

CPRA — Compliant

Trello/Atlassian has a significant US user base including California residents, and Atlassian's revenue and data processing scale clearly meet CCPA/CPRA thresholds. Risk is Medium because: (1) CPRA enforcement by the California Privacy Protection Agency (CPPA) is actively increasing; (2) Atlassian's 2024 data exposure incident may attract CPPA scrutiny; (3) The scale of California users processed means any compliance gap has significant impact. Risk is not High because Atlassian has documented CCPA compliance measures and a mature privacy program.

Evidence: https://www.atlassian.com/legal/privacy-policy, https://www.atlassian.com/trust/privacy, https://www.atlassian.com/trust/compliance/resources/ccpa

GDPR (source) — Compliant

Trello (via Atlassian) serves millions of EU/EEA users globally and processes significant volumes of personal data of EU/EEA residents, making GDPR fully applicable. Atlassian has publicly documented GDPR compliance measures including DPA availability, SCCs, and a dedicated DPO. Risk is rated Medium rather than Low because: (1) Trello's 2023 data exposure incident (public profile data indexed by search engines) demonstrated real-world data handling risks; (2) Atlassian's scale means any compliance gap has large impact; (3) ongoing enforcement by EU DPAs against cloud SaaS providers is increasing. Risk is not High because Atlassian has mature, documented GDPR compliance infrastructure and has not been subject to major GDPR enforcement actions.

Evidence: https://www.atlassian.com/trust/privacy, https://www.atlassian.com/legal/privacy-policy, https://www.atlassian.com/legal/data-processing-addendum, https://www.atlassian.com/trust/compliance/resources/gdpr, https://trello.com/legal

Financials

Three-year financials

Financial Resilience Score: 8/10

Trello does not publish standalone financials as it was acquired by Atlassian Corporation (NASDAQ: TEAM) in February 2017 for approximately US$425 million. As a product line within Atlassian, Trello benefits from being backed by a well-capitalised, US-listed parent with multi-billion-dollar revenue (Atlassian FY2024 consolidated revenue ~US$4.36B), strong SaaS gross margins (~80%+), and positive free cash flow at the group level. This provides significant financial resilience against short-term market pressures. However, Trello faces intense competitive pressure from Asana, Monday.com, Notion, ClickUp, Microsoft Planner/Loop, and cannibalisation risk from Atlassian's own Jira Work Management. Atlassian group has historically reported GAAP operating losses due to heavy stock-based compensation and R&D spend, which is a risk factor at the parent level. The lack of standalone visibility means outside stakeholders cannot independently assess Trello's own P&L performance, and Atlassian may deprioritise or rebrand the product as it has done with other acquisitions.

Key strengths: Backed by well-capitalised US-listed parent Atlassian (NASDAQ: TEAM), Atlassian FY2024 consolidated revenue ~US$4.36B, FY2023 ~US$3.53B, FY2022 ~US$2.80B, Strong SaaS gross margins (~80%+) typical at group level, Positive free cash flow at Atlassian group level, Massive existing distribution via cross-sell to Jira/Confluence customer base, Tens of millions of registered users historically with strong freemium funnel, Diversified across Free, Standard, Premium, and Enterprise tiers, No single customer accounts for material share of revenue (long-tail self-serve SaaS)

Risk factors: No standalone financial visibility for Trello product, Intense competition from Asana, Monday.com, Notion, ClickUp, Microsoft Planner/Loop, Cannibalisation risk within Atlassian's own portfolio (Jira Work Management, Rovo/AI), Atlassian group reports GAAP operating losses due to SBC and R&D spend, Risk of Atlassian deprioritising or rebranding Trello, Product may be sunset as Atlassian did with Jira Core

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report