Atlassian
atlassian.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Vendor discloses an unfavourable answer: Will they train on your data?
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
Responsibility transfers. Accountability doesn’t — and everything you inherit, you have to verify.
View the inherited responsibilities
Before you sign
Why it matters: Atlassian's privacy policy states information from customer support may be used to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.
What to ask for: Resolve this directly with the vendor before proceeding — this is a confirmed disclosure, not a gap to fill in.
“Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.”
“to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.”
“Safeguard against misuse with data policies and controls that restrict LLM providers from storing or training models using your inputs or outputs.”
“Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings,”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✗Will they train on your data?Concern / gap
Atlassian's privacy policy states information from customer support may be used to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.
Requires written confirmation — see Before you sign ↓
“Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.”
“to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.”
“Safeguard against misuse with data policies and controls that restrict LLM providers from storing or training models using your inputs or outputs.”
“Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings,”
✓How long do they keep your data?Clear
Third-party hosted LLM partners — OpenAI, Anthropic, and Google — operate under strict zero data retention agreements.
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“Following expiration or termination of the Agreement, Atlassian must, in accordance with the Documentation, delete all Customer Personal Data.”
!Who else can access your data?Ask the vendor
Atlassian says it maintains restrictive policies with its LLM providers and discloses how those providers secure their platforms on its subprocessor page; the providers are not named in the fetched pages themselves.
Confirm in writing: Ask the vendor to state this in writing before signing.
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
!Where is your data processed?Ask the vendor
Data residency is supported for Rovo: with it enabled, in-scope app data remains stored in the selected region.
Confirm in writing: Ask the vendor to state this in writing before signing.
“With data residency for Rovo turned on, all of your in-scope app data will remain stored in the region you've”
!What happens in a security incident?Ask the vendor
Atlassian runs a Bugcrowd-partnered bug bounty and publishes a signed security.txt with vulnerability reporting channels and security advisories.
Confirm in writing: Ask the vendor to state this in writing before signing.
“We've partnered with Bugcrowd to reward unique vulnerability research.”
“Stay in the know on current security advisories. See security advisories”
Key findingsclick a row for the evidence
✓Explicit no-third-party-LLM-training commitment for RovoStrong
Atlassian states plainly that customer inputs and outputs are not used to train, fine-tune or improve any third-party LLM, with end-to-end encryption, permission-respecting AI, admin audit logs and an organisation-wide AI off-switch.
This directly answers the first question buyers ask of an embedded AI assistant, in unambiguous language, with the control surface to enforce it.
“Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.”
“Rovo respects all user permissions and access controls across Atlassian and connected third-party apps.”
!Product content protected, but support data may train Atlassian's own modelsGap
The Rovo commitment covers third-party LLMs; the privacy policy separately permits information from support channels to be used for development, training or fine-tuning of Atlassian's own ML/AI models. These are different scopes a buyer could easily conflate.
A buyer relying on the headline 'not used to train' statement should understand it does not extend to everything Atlassian holds — support-channel content is carved out for Atlassian-internal model training.
Question for vendor: Which categories of customer information can feed Atlassian-internal model training, and is there an opt-out for support-channel content?
“Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.”
“to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.”
✓AI-product-scoped external assessment claimed for RovoStrong
Atlassian claims Rovo itself has completed external assessment and certifications for SOC 2 and ISO 27001 — scoping assurance to the AI product rather than only the company.
Product-scoped assurance is materially stronger than an organisational certificate that may exclude new AI services.
Question for vendor: Can Atlassian provide the SOC 2 report section or ISO 27001 scope statement covering Rovo specifically?
“Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001.”
“SOC 2 SOC 3 PCI DSS ISO/IEC 27001 ISO/IEC 27018 GDPR”
✓Regulatory posture: EU AI Pact and Data Privacy FrameworksStrong
EU AI Pact participation with a published report, DPF certification across EU/UK/Swiss transfers, and a pre-signed DPA give the legal-transparency domain unusually complete coverage.
Signals active regulatory engagement on AI ahead of enforcement deadlines, reducing buyer-side legal review effort.
“Atlassian is taking steps towards compliance with the EU AI Act as a proud participant of the European Commission's EU AI Pact.”
“Atlassian complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
?Intercom observed but not named in public materialsObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder, which the vendor's public trust materials do not name.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Intercom appears to be involved as a application builder — can you confirm and disclose this relationship?
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
?Technical dependency observed: IntercomObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers”
“We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.”
“You can also learn more about how each feature uses LLMs on our transparency page”
?Technical dependency observed: AWSObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on AWS as a platform provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — AWS appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers”
“We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.”
“You can also learn more about how each feature uses LLMs on our transparency page”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers”
“We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.”
“You can also learn more about how each feature uses LLMs on our transparency page”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers”
“We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.”
“You can also learn more about how each feature uses LLMs on our transparency page”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers”
“We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.”
“You can also learn more about how each feature uses LLMs on our transparency page”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score60
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Atlassian staff that access and process customer personal data are trained on how to handle it, and are bound to maintain its confidentiality and security.”
“Atlassian is guided by its Responsible Technology Principles, which focus on transparency, trust, accountability, human-centricity, and teamwork.”
“Rovo respects all user permissions and access controls across Atlassian and connected third-party apps.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score33
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Power teamwork with AI built responsibly Rovo is thoughtfully designed and deployed to uphold our Responsible Technology Principles”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“Planned expansions to our data residency program are highlighted in Atlassian’s cloud roadmap”
AI system description: vendor-evidenced, not yet independently corroborated.
Testing & evaluation: not publicly evidenced.
Model10% of the score75
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“You can also learn more about how each feature uses LLMs on our transparency page”
Customer data15% of the score92
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Safeguard against misuse with data policies and controls that restrict LLM providers from storing or training models using your inputs or outputs.”
“Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.”
“Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings,”
“With data residency for Rovo turned on, all of your in-scope app data will remain stored in the region you've”
“Following expiration or termination of the Agreement, Atlassian must, in accordance with the Documentation, delete all Customer Personal Data.”
“right to be forgotten (or right to erasure) clause by making it easy to delete personal data from Atlassian Cloud products.”
“encrypts data in transit and at rest”
“Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.”
“Repositories are encrypted at rest (AES-256) and encrypted in transit (TLS 1.2+) so your code is always secure.”
“to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.”
AI supply chain10% of the score75
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian”
“Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories”
“OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo”
“Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers”
“We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.”
“get a deeper look at how our LLM providers secure their platforms on our subprocessor page”
“Hosted on AWS to provide additional resiliency and recovery capabilities.”
Security foundation15% of the score85
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Stay in the know on current security advisories. See security advisories”
“We've partnered with Bugcrowd to reward unique vulnerability research.”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the score74
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001.”
“Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001.”
“SOC 2 SOC 3 PCI DSS ISO/IEC 27001 ISO/IEC 27018 GDPR”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Independent assurance: vendor-evidenced, not yet independently corroborated.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“publishes an annual Transparency Report with information about government requests for users' data as well as government requests to remove content or suspend accounts”
“Following expiration or termination of the Agreement, Atlassian must, in accordance with the Documentation, delete all Customer Personal Data.”
“Atlassian is taking steps towards compliance with the EU AI Act as a proud participant of the European Commission's EU AI Pact.”
“Atlassian complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 69 → up to 85 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
Assurance evidence: certifications 11 — registry checks and verification ladders, click to view
Three SOC documents held: Confluence Cloud SOC 2 Type 2 (+HIPAA) and Jira Align SOC 2 Type 2, both KPMG Assurance and Consulting Services LLP, period 1 Oct 2024 - 30 Sep 2025; Isolated Cloud SOC 2 + HIPAA Type 1 as of 26 June 2026. Vault: Gated/Atlassian/2025-11_atlassian-confluence-cloud-soc2-type2-hipaa.pdf, 2025-11_atlassian-jira-align-soc2-type2.pdf, 2026-06_atlassian-isolated-cloud-soc2-hipaa-type1.pdf.
DIN EN ISO/IEC 27001:2024 edition. Scope covers the Atlassian Trust Management System underlying the Atlassian Cloud offering and its microservices. Certificate 13080125, issued by KPMG Cert GmbH Umweltgutachterorganisation, accredited by DAkkS; record last updated 17 August 2026.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
EU-U.S., Swiss-U.S. and UK Extension all Active; Non-HR Data; +6 covered entities, matching the subsidiaries named in Atlassian's privacy policy. Verified on the official participant list, 20 Aug 2026.
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry
Business continuity management for delivery and operations of Atlassian products including ROVO/AI, Jira, Confluence, Bitbucket and Jira Service Management. Certified by KPMG Cert GmbH (DAkkS).
Checked against IAF CertSearch, Aug 25, 2026: Verified on the registry
IRAP Cloud Security Assessment by CyberCX, completed March 2025 (letter dated 27 March 2025): Atlassian Cloud (Jira, Jira Service Management, Confluence), Australian regions, PROTECTED classification, ISM December 2024, ACSC framework Phase 1a. Consumers grant their own Authority to Operate. Vault: Gated/Atlassian/2025-03_atlassian-irap-assessment-letter.pdf (+ full report).
Checked against IRAP Letter of Assessment held in the TrustyCyber vault (Atlassian trust portal), Aug 25, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry
Sources 36 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Atlassian at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
