Yes
According to their security page, all Trello traffic runs over TLS.
Yes
Trello meets the recommended cryptographic profiles for TLS as published by the NCSC. Trello currently gets an ‘A+’ rating from SSL Labs. Note that this was performed on their top level domain, and not all subdomains that may be used for API calls.
Unknown
At this time, it is unknown whether Trello protects internal data in transit using encryption.
Unknown
At this time, it is unknown whether Trello protects internal data in transit using correctly configured certificates.
Yes
According to their documentation, Trello’s API makes use of OAuth.
Yes
Multiple permission levels exist in Trello and can be applied on a per-board basis.
Yes
Does the SaaS provider collect logs of events?
Types of log may include security logs and resource logs
Unknown
No
Does the SaaS provider have a clear incident response and patching system in place to remedy any publicly reported issues in their service, or libraries that the service makes use of?
The provider’s previous track record on this is a good metric to see how they’ll cope with a new issue occurring.
Yes
Source: NCSC