← Trust Directory

Atlassian

atlassian.com · 2 assessments

Atlassian - organisation
Do not approve on current evidence
1 blocking issue to resolve before signing
Assessed Aug 28, 2026 · public evidence coverage 68% · evidence confidence medium high · methodology 0.6.0

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

Rovo
Approve with conditions
1 item to confirm in writing
Assessed Aug 31, 2026 · public evidence coverage 70% · evidence confidence medium high · methodology 0.6.1

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2
Claimed & corroborated

Three SOC documents held: Confluence Cloud SOC 2 Type 2 (+HIPAA) and Jira Align SOC 2 Type 2, both KPMG Assurance and Consulting Services LLP, period 1 Oct 2024 - 30 Sep 2025; Isolated Cloud SOC 2 + HIPAA Type 1 as of 26 June 2026. Vault: Gated/Atlassian/2025-11_atlassian-confluence-cloud-soc2-type2-hipaa.pdf, 2025-11_atlassian-jira-align-soc2-type2.pdf, 2026-06_atlassian-isolated-cloud-soc2-hipaa-type1.pdf.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27001
Claimed & corroborated

DIN EN ISO/IEC 27001:2024 edition. Scope covers the Atlassian Trust Management System underlying the Atlassian Cloud offering and its microservices. Certificate 13080125, issued by KPMG Cert GmbH Umweltgutachterorganisation, accredited by DAkkS; record last updated 17 August 2026.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
SOC 3
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
PCI DSS
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27018
Vendor claimed only
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
EU-U.S. Data Privacy Framework
Claimed & corroborated

EU-U.S., Swiss-U.S. and UK Extension all Active; Non-HR Data; +6 covered entities, matching the subsidiaries named in Atlassian's privacy policy. Verified on the official participant list, 20 Aug 2026.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 28, 2026

ISO/IEC 42001
Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
CSA STAR Level 2
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Aug 28, 2026

ISO 22301
Claimed & corroborated

Business continuity management for delivery and operations of Atlassian products including ROVO/AI, Jira, Confluence, Bitbucket and Jira Service Management. Certified by KPMG Cert GmbH (DAkkS).

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · IAF CertSearch · checked Aug 25, 2026

IRAP
Claimed & corroborated

IRAP Cloud Security Assessment by CyberCX, completed March 2025 (letter dated 27 March 2025): Atlassian Cloud (Jira, Jira Service Management, Confluence), Australian regions, PROTECTED classification, ISM December 2024, ACSC framework Phase 1a. Consumers grant their own Authority to Operate. Vault: Gated/Atlassian/2025-03_atlassian-irap-assessment-letter.pdf (+ full report).

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · IRAP Letter of Assessment held in the TrustyCyber vault (Atlassian trust portal) · checked Aug 25, 2026

FedRAMP Authorization
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 28, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: OpenAI, Anthropic, Google
Infrastructure: Amazon Web Services

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. This record reflects the evidence available on Aug 28, 2026.