Trello's statement regarding security of attachments on cards states:
File attachments to Trello cards are stored in Amazon’s S3 service. Each such attachment is assigned a unique link with an unguessable, cryptographically strong random component, and are only accessible using a secure HTTPS connection.
That said, if the direct URL of the attachment is known/shared one can view the object from a non public Board / Card without authentication.
We use Trello to track project status, and sometimes we add architecture docs to cards. Our assumption was that there's an authentication wall you need to get through to see the content of the cards, but now looking a little closer at this, the objects attached to the cards are being offloaded into S3 but the bucket policy allows one to get the object without authenticating.
Would a better way to achieve this be: Ensure that the Trello servers / infrastructure perform the GET of the object from S3 on your behalf? That way Trello ensures the retrieval from S3 is at least authenticated with the use of either an oauth key or at the very least an HTTP referer on the S3 bucket policy.