Atlassian

atlassian.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
69 / 100C
Procurement decision
Do not approve on current evidence
1 condition outstanding
  • Vendor discloses an unfavourable answer: Will they train on your data?

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

16 / 41responsibilities inherited under consumption model B — direct model-provider API. 10 without current evidence — unmanaged risk until verified.

Responsibility transfers. Accountability doesn’t — and everything you inherit, you have to verify.

View the inherited responsibilities
Physical and cloud infrastructure securityEvidence held
Evidence owed: Existing cloud attestations (ISO 27001, SOC 2, IRAP as applicable) · Owner under model B: MP · Evidenced by: OpenAI
TrustyCyber holds and has reviewed: o1 system card, dated 2024-12; o3-mini system card, dated 2025-01; Deep Research system card, dated 2025-02; Disrupting malicious uses of our models, February 2025 update, dated 2025-02; ChatGPT Agent system card, dated 2025-07; GPT-5 system card, dated 2025-08
Inference availability, capacity and localityEvidence held
Evidence owed: SLAs; region and locality attestations; support-personnel location disclosure · Owner under model B: MP · Evidenced by: OpenAI
TrustyCyber holds and has reviewed: o1 system card, dated 2024-12; o3-mini system card, dated 2025-01; Deep Research system card, dated 2025-02; Disrupting malicious uses of our models, February 2025 update, dated 2025-02; ChatGPT Agent system card, dated 2025-07; GPT-5 system card, dated 2025-08
Tenancy isolation: platform data planeEvidence held
Evidence owed: Multi-tenancy architecture attestation · Owner under model B: MP · Evidenced by: OpenAI
TrustyCyber holds and has reviewed: o1 system card, dated 2024-12; o3-mini system card, dated 2025-01; Deep Research system card, dated 2025-02; Disrupting malicious uses of our models, February 2025 update, dated 2025-02; ChatGPT Agent system card, dated 2025-07; GPT-5 system card, dated 2025-08
Tenancy isolation: application data plane (per-tenant retrieval scoping, RBAC before the model)Verify
Evidence owed: Architecture documentation showing data filtered by tenant and role before any model call · Owner under model B: AB
Training data provenance, rights and quality (base model)Evidence held
Evidence owed: Model card: data categories, rights basis, quality and contamination controls · Owner under model B: MP · Evidenced by: OpenAI
TrustyCyber holds and has reviewed: o1 system card, dated 2024-12; o3-mini system card, dated 2025-01; Deep Research system card, dated 2025-02; Disrupting malicious uses of our models, February 2025 update, dated 2025-02; ChatGPT Agent system card, dated 2025-07; GPT-5 system card, dated 2025-08
Safety training, alignment and baseline capability and safety evaluationsEvidence held
Evidence owed: Published evaluation results; system card; known-limitations disclosure · Owner under model B: MP · Evidenced by: OpenAI
TrustyCyber holds and has reviewed: o1 system card, dated 2024-12; o3-mini system card, dated 2025-01; Deep Research system card, dated 2025-02; Disrupting malicious uses of our models, February 2025 update, dated 2025-02; ChatGPT Agent system card, dated 2025-07; GPT-5 system card, dated 2025-08
Model weights security and integrityEvidence held
Evidence owed: Weights-handling attestation; supply-chain integrity statement · Owner under model B: MP to AB to DP · Evidenced by: OpenAI
TrustyCyber holds and has reviewed: o1 system card, dated 2024-12; o3-mini system card, dated 2025-01; Deep Research system card, dated 2025-02; Disrupting malicious uses of our models, February 2025 update, dated 2025-02; ChatGPT Agent system card, dated 2025-07; GPT-5 system card, dated 2025-08
Model change management and version noticeVerify
Evidence owed: Versioning policy; advance change notice with materiality classification · Owner under model B: AB
Absorbing model changes (regression testing the application against new versions)Verify
Evidence owed: Regression and evaluation results per model version, retained and dated · Owner under model B: AB
Fine-tuning governance (model D only): data rights, safety re-testing after tuningVerify
Evidence owed: Fine-tuning data record; post-tuning safety evaluation demonstrating no degradation
System prompt and orchestration designVerify
Evidence owed: Documented prompt and orchestration design under change control · Owner under model B: AB
Grounding (RAG) pipeline: access control, chunking, provenance of what reaches the modelVerify
Evidence owed: Pipeline architecture; retrieval scoping rules · Owner under model B: AB
Output filtering and application-layer safety guardrailsVerify
Evidence owed: Guardrail configuration and test results · Owner under model B: AB
Confidence display, citations, explainabilityVerify
Evidence owed: Design documentation showing rationale and confidence surfaced to users · Owner under model B: DP
Inter-agent identity and trust boundaries (multi-agent, MCP and A2A-class interoperability)Verify
Evidence owed: Agent identity model; inter-agent authentication design · Owner under model B: AB and DP
Human oversight design (affordances that make oversight possible)Verify
Evidence owed: Oversight design documentation · Owner under model B: DP

Before you sign

Vendor discloses an unfavourable answer: Will they train on your data?Blocking

Why it matters: Atlassian's privacy policy states information from customer support may be used to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.

What to ask for: Resolve this directly with the vendor before proceeding — this is a confirmed disclosure, not a gap to fill in.

Evidence
Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.
Vendor publishedPrivacy Policy | Atlassianretrieved Aug 28, 2026
to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Safeguard against misuse with data policies and controls that restrict LLM providers from storing or training models using your inputs or outputs.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings,

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Concern / gap

Atlassian's privacy policy states information from customer support may be used to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.

Requires written confirmation — see Before you sign ↓

Evidence
Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.
Vendor publishedPrivacy Policy | Atlassianretrieved Aug 28, 2026
to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Safeguard against misuse with data policies and controls that restrict LLM providers from storing or training models using your inputs or outputs.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings,
How long do they keep your data?Clear

Third-party hosted LLM partners — OpenAI, Anthropic, and Google — operate under strict zero data retention agreements.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Vendor publishedData Processing Addendum | Atlassianretrieved Aug 28, 2026
Following expiration or termination of the Agreement, Atlassian must, in accordance with the Documentation, delete all Customer Personal Data.
!Who else can access your data?Ask the vendor

Atlassian says it maintains restrictive policies with its LLM providers and discloses how those providers secure their platforms on its subprocessor page; the providers are not named in the fetched pages themselves.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
!Where is your data processed?Ask the vendor

Data residency is supported for Rovo: with it enabled, in-scope app data remains stored in the selected region.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
With data residency for Rovo turned on, all of your in-scope app data will remain stored in the region you've
!What happens in a security incident?Ask the vendor

Atlassian runs a Bugcrowd-partnered bug bounty and publishes a signed security.txt with vulnerability reporting channels and security advisories.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedCloud Security | Atlassianretrieved Aug 28, 2026
We've partnered with Bugcrowd to reward unique vulnerability research.
Vendor publishedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Stay in the know on current security advisories. See security advisories

Key findingsclick a row for the evidence

Explicit no-third-party-LLM-training commitment for RovoStrong

Atlassian states plainly that customer inputs and outputs are not used to train, fine-tune or improve any third-party LLM, with end-to-end encryption, permission-respecting AI, admin audit logs and an organisation-wide AI off-switch.

This directly answers the first question buyers ask of an embedded AI assistant, in unambiguous language, with the control surface to enforce it.

Evidence
Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.
Rovo respects all user permissions and access controls across Atlassian and connected third-party apps.
!Product content protected, but support data may train Atlassian's own modelsGap

The Rovo commitment covers third-party LLMs; the privacy policy separately permits information from support channels to be used for development, training or fine-tuning of Atlassian's own ML/AI models. These are different scopes a buyer could easily conflate.

A buyer relying on the headline 'not used to train' statement should understand it does not extend to everything Atlassian holds — support-channel content is carved out for Atlassian-internal model training.

Question for vendor: Which categories of customer information can feed Atlassian-internal model training, and is there an opt-out for support-channel content?

Evidence
Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.
Vendor publishedPrivacy Policy | Atlassianretrieved Aug 28, 2026
to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.
AI-product-scoped external assessment claimed for RovoStrong

Atlassian claims Rovo itself has completed external assessment and certifications for SOC 2 and ISO 27001 — scoping assurance to the AI product rather than only the company.

Product-scoped assurance is materially stronger than an organisational certificate that may exclude new AI services.

Question for vendor: Can Atlassian provide the SOC 2 report section or ISO 27001 scope statement covering Rovo specifically?

Evidence
Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001.
Vendor publishedCloud Security | Atlassianretrieved Aug 28, 2026
SOC 2 SOC 3 PCI DSS ISO/IEC 27001 ISO/IEC 27018 GDPR
Regulatory posture: EU AI Pact and Data Privacy FrameworksStrong

EU AI Pact participation with a published report, DPF certification across EU/UK/Swiss transfers, and a pre-signed DPA give the legal-transparency domain unusually complete coverage.

Signals active regulatory engagement on AI ahead of enforcement deadlines, reducing buyer-side legal review effort.

Evidence
Atlassian is taking steps towards compliance with the EU AI Act as a proud participant of the European Commission's EU AI Pact.
Vendor publishedPrivacy Policy | Atlassianretrieved Aug 28, 2026
Atlassian complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
?Intercom observed but not named in public materialsObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder, which the vendor's public trust materials do not name.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Intercom appears to be involved as a application builder — can you confirm and disclose this relationship?

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
?Technical dependency observed: IntercomObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
You can also learn more about how each feature uses LLMs on our transparency page
?Technical dependency observed: AWSObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on AWS as a platform provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — AWS appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
You can also learn more about how each feature uses LLMs on our transparency page
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
You can also learn more about how each feature uses LLMs on our transparency page
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
You can also learn more about how each feature uses LLMs on our transparency page
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
You can also learn more about how each feature uses LLMs on our transparency page

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score60
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedHow We Handle Data Privacy | Atlassianretrieved Aug 28, 2026
Atlassian staff that access and process customer personal data are trained on how to handle it, and are bound to maintain its confidentiality and security.
Atlassian is guided by its Responsible Technology Principles, which focus on transparency, trust, accountability, human-centricity, and teamwork.
Rovo respects all user permissions and access controls across Atlassian and connected third-party apps.

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score33
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Power teamwork with AI built responsibly Rovo is thoughtfully designed and deployed to uphold our Responsible Technology Principles
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
Planned expansions to our data residency program are highlighted in Atlassian’s  cloud roadmap

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: not publicly evidenced.

Model10% of the score75
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Covered
Evidence — Model & provider transparency
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
You can also learn more about how each feature uses LLMs on our transparency page
Customer data15% of the score92
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Covered
Evidence — Customer data treatment
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Safeguard against misuse with data policies and controls that restrict LLM providers from storing or training models using your inputs or outputs.
Externally corroboratedAI Trust | Atlassianretrieved Aug 28, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings,
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
With data residency for Rovo turned on, all of your in-scope app data will remain stored in the region you've
Vendor publishedData Processing Addendum | Atlassianretrieved Aug 28, 2026
Following expiration or termination of the Agreement, Atlassian must, in accordance with the Documentation, delete all Customer Personal Data.
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
right to be forgotten (or right to erasure) clause by making it easy to delete personal data from Atlassian Cloud products.
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
encrypts data in transit and at rest
Your inputs and outputs are not used to train, fine-tune, or improve any third-party LLM models or services, and are protected with end-to-end encryption.
Vendor publishedCloud Security | Atlassianretrieved Aug 28, 2026
Repositories are encrypted at rest (AES-256) and encrypted in transit (TLS 1.2+) so your code is always secure.
Vendor publishedPrivacy Policy | Atlassianretrieved Aug 28, 2026
to repair and improve the Services, including for development, training, or fine-tuning of machine learning and artificial intelligence models.
AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Security Measures Security & Trust Center OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features For the provision of Atlassian
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Center AI and Analytics Service Providers Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features Categories
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 28, 2026
Atlassian uses the third-party entities listed below (each, a “Sub-processor” ) to process Customer Personal Data on behalf of Atlassian customers and developers
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards.
get a deeper look at how our LLM providers secure their platforms on our subprocessor page
Externally corroboratedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Hosted on AWS to provide additional resiliency and recovery capabilities.
Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedComprehensive Data Protection | Atlassianretrieved Aug 28, 2026
Stay in the know on current security advisories. See security advisories
Vendor publishedCloud Security | Atlassianretrieved Aug 28, 2026
We've partnered with Bugcrowd to reward unique vulnerability research.

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score74
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedAI Trust | Atlassianretrieved Aug 28, 2026
Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001.
Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001.
Vendor publishedCloud Security | Atlassianretrieved Aug 28, 2026
SOC 2 SOC 3 PCI DSS ISO/IEC 27001 ISO/IEC 27018 GDPR
Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 25, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO 22301retrieved Aug 25, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Independent assurance: vendor-evidenced, not yet independently corroborated.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedGDPR | Atlassianretrieved Aug 28, 2026
publishes an annual  Transparency Report  with information about government requests for users' data as well as government requests to remove content or suspend accounts
Vendor publishedData Processing Addendum | Atlassianretrieved Aug 28, 2026
Following expiration or termination of the Agreement, Atlassian must, in accordance with the Documentation, delete all Customer Personal Data.
Atlassian is taking steps towards compliance with the EU AI Act as a proud participant of the European Commission's EU AI Pact.
Vendor publishedPrivacy Policy | Atlassianretrieved Aug 28, 2026
Atlassian complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Publish Testing & evaluation evidenceAI System 3353
+2Have Governance & accountability disclosures independently corroboratedOrganisation 6075
+2Publish independently corroborated ISO/IEC 42001 (AI management system) certificationOrganisation 6072
+1Have AI system description disclosures independently corroboratedAI System 3338
+1Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 69 → up to 85 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTUREAtlassianAtlassianRovoRovoAtlassian IntelligenceAtlassian IntelligenceOpenAIOpenAIAnthropicAnthropicGoogleGoogleAmazon Web ServicesAmazon Web Services
View as list
Rovo Uses AI Service OpenAI
Rovo Uses AI Service Anthropic
Rovo Uses AI Service Google
Atlassian Uses Infrastructure Amazon Web Services
Assurance evidence: certifications 11 — registry checks and verification ladders, click to view
SOC 2Claimed & corroborated

Three SOC documents held: Confluence Cloud SOC 2 Type 2 (+HIPAA) and Jira Align SOC 2 Type 2, both KPMG Assurance and Consulting Services LLP, period 1 Oct 2024 - 30 Sep 2025; Isolated Cloud SOC 2 + HIPAA Type 1 as of 26 June 2026. Vault: Gated/Atlassian/2025-11_atlassian-confluence-cloud-soc2-type2-hipaa.pdf, 2025-11_atlassian-jira-align-soc2-type2.pdf, 2026-06_atlassian-isolated-cloud-soc2-hipaa-type1.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current
ISO/IEC 27001Claimed & corroborated

DIN EN ISO/IEC 27001:2024 edition. Scope covers the Atlassian Trust Management System underlying the Atlassian Cloud offering and its microservices. Certificate 13080125, issued by KPMG Cert GmbH Umweltgutachterorganisation, accredited by DAkkS; record last updated 17 August 2026.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current
SOC 3Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

PCI DSSVendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27018Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy FrameworkClaimed & corroborated

EU-U.S., Swiss-U.S. and UK Extension all Active; Non-HR Data; +6 covered entities, matching the subsidiaries named in Atlassian's privacy policy. Verified on the official participant list, 20 Aug 2026.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

ISO 22301Claimed & corroborated

Business continuity management for delivery and operations of Atlassian products including ROVO/AI, Jira, Confluence, Bitbucket and Jira Service Management. Certified by KPMG Cert GmbH (DAkkS).

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 25, 2026: Verified on the registry

IRAPClaimed & corroborated

IRAP Cloud Security Assessment by CyberCX, completed March 2025 (letter dated 27 March 2025): Atlassian Cloud (Jira, Jira Service Management, Confluence), Australian regions, PROTECTED classification, ISM December 2024, ACSC framework Phase 1a. Consumers grant their own Authority to Operate. Vault: Gated/Atlassian/2025-03_atlassian-irap-assessment-letter.pdf (+ full report).

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IRAP Letter of Assessment held in the TrustyCyber vault (Atlassian trust portal), Aug 25, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 36 — click to view
AI Trust | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
Trust Center | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Data Processing Addendum | Atlassian
DPA · Vendor · retrieved Aug 28, 2026
List of Data Subprocessors | Atlassian
Subprocessor List · Vendor · retrieved Aug 28, 2026
Privacy Policy | Atlassian
Privacy Notice · Vendor · retrieved Aug 28, 2026
Comprehensive Data Protection | Atlassian
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Connect Compass to Your Developer Toolchain | Atlassian
Technical Architecture Documentation · Vendor · retrieved Aug 28, 2026
Atlassian Legal | Atlassian
Terms · Vendor · retrieved Aug 28, 2026
Building an internal API Catalog with Atlassian Compass | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
Rovo: Unlock organizational knowledge with GenAI | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
Comprehensive Data Protection | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
GDPR | Atlassian
DPA · Vendor · retrieved Aug 28, 2026
How We Handle Data Privacy | Atlassian
Privacy Notice · Vendor · retrieved Aug 28, 2026
Design Effective Scorecards in Compass | Atlassian
Technical Architecture Documentation · Vendor · retrieved Aug 28, 2026
Atlassian Customer Agreement | Atlassian
Terms · Vendor · retrieved Aug 28, 2026
Prioritize Jira Backlog and Reduce Tech Debt with Compass | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
Rovo AI Security | Trusted AI built responsibly and securely | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
https://www.atlassian.com/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Impressum | Atlassian
Terms · Vendor · retrieved Aug 28, 2026
State of Developer Experience Report 2024 | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
AI & Bitbucket | AI-native coding workflows | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
Cloud Security | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
How To Achieve Team Alignment With Confluence | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
Rovo in Confluence: AI features | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
FedRAMP | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Increase engagement in Confluence | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
Tips and tricks for using AI | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
Resilience At Scale | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Automate your content workflow with Confluence and Rovo | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
Get Started with Confluence’s AI Features | Atlassian
AI Documentation · Vendor · retrieved Aug 28, 2026
Global Category: Compliance Resource Center | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Building better content libraries with Confluence databases | Atlassian
Technical Article · Vendor · retrieved Aug 28, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 25, 2026
IAF CertSearch record — ISO 22301
External Registry Or Certification Evidence · Registry · retrieved Aug 25, 2026
IRAP Letter of Assessment held in the TrustyCyber vault (Atlassian trust portal) record — IRAP
External Registry Or Certification Evidence · Registry · retrieved Aug 25, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Atlassian at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.