Rovo

atlassian.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
56 / 100C
Procurement decision
Approve with conditions
1 condition outstanding
  • No clear commitment that your data will not train their models

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 31, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
The LLM providers we use do not use your inputs and outputs to improve their services. Neither OpenAI nor any other LLM provider retains your inputs and outputs.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings, and we apply robust safeguards, including de-identifying and aggregating all contributed metadata before use.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

Atlassian states its third-party LLM providers neither retain customer inputs and outputs nor use them to improve their own services.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
The LLM providers we use do not use your inputs and outputs to improve their services. Neither OpenAI nor any other LLM provider retains your inputs and outputs.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings, and we apply robust safeguards, including de-identifying and aggregating all contributed metadata before use.
How long do they keep your data?Clear

Atlassian states its third-party hosted LLM partners operate under zero data retention agreements, naming OpenAI, Anthropic and Google.

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
!Who else can access your data?Ask the vendor

Atlassian names the specific model families Rovo uses: open models (Gemma, GPT-oss, Llama, Nemotron) plus third-party hosted models from OpenAI, Anthropic and Google, selected per request by dynamic routing.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
By default, when using Rovo, data is transferred outside of the current site to third party LLM providers (e.g., OpenAI) in order to generate a response.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Where is your data processed?Clear

Data residency is supported for Rovo; with it enabled, in-scope app data remains stored in the customer's selected region.

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Yes, data residency support is available for Rovo. With data residency for Rovo turned on, all of your in-scope app data will remain stored in the region you've selected.
!What happens in a security incident?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Confirm in writing: Ask the vendor to state this in writing before signing.

Key findingsclick a row for the evidence

Model providers are named, and the subprocessor register backs the namingStrong

Atlassian names the specific model families behind Rovo and registers the generative AI providers — OpenAI, AWS Bedrock and Google Vertex AI — in its contractual subprocessor list, with processing locations.

Most AI vendors describe their model supply chain only in marketing prose. Naming providers in the subprocessor register puts them inside the DPA's change-notification machinery, so a buyer can track changes contractually rather than by re-reading a webpage.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
!Anthropic is named as a model provider but is not a registered subprocessorGap

The AI Trust page states Rovo uses Anthropic's Claude series, but Anthropic does not appear in the subprocessor register. AWS Bedrock is registered, which is the plausible route by which Claude reaches the product.

If Claude is consumed through Bedrock, the buyer's contractual protection runs to AWS, not to Anthropic, and Anthropic's own commitments are not directly owed to the customer. That is a materially different assurance position from a direct provider relationship, and it is not stated either way.

Question for vendor: Is Anthropic's Claude consumed through AWS Bedrock rather than directly, and if so, which entity carries the zero-data-retention obligation for those requests?

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
!Third-party providers are barred from training, but Atlassian reserves its own fine-tuning rightGap

Rovo's third-party LLM providers are under zero-data-retention terms and cannot train on inputs or outputs. Atlassian separately reserves the right to fine-tune its own in-boundary open-source models on de-identified, aggregated customer metadata, subject to data contribution settings.

The headline commitment a buyer remembers is 'providers do not train on your data', which is true and unusually clear. The carve-out is Atlassian's own training on metadata — a narrower and better-controlled practice, but one a buyer should confirm the setting for rather than assume off.

Question for vendor: What is the default state of the data contribution setting for our tenant, and what specifically falls within 'metadata' for Rovo?

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
The LLM providers we use do not use your inputs and outputs to improve their services. Neither OpenAI nor any other LLM provider retains your inputs and outputs.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings, and we apply robust safeguards, including de-identifying and aggregating all contributed metadata before use.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
!Rovo cannot be fully switched off, and opt-out is only app-levelGap

Rovo Apps are a non-removable part of the Atlassian Cloud Platform. Admins can deactivate AI-powered features per app, but Rovo Search, Studio and Bookmarks are always on, and opt-out controls exist only at app level.

An organisation that has not yet approved AI use cannot reach a fully AI-free state on Atlassian Cloud, and cannot scope an opt-out more finely than a whole app. That constrains a staged rollout and needs to be known before, not after, a governance sign-off.

Question for vendor: Which Rovo features remain active on a tenant with every available AI opt-out applied, and what customer data do they process?

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Rovo Apps are a core part of the Atlassian Cloud Platform, similar to other apps (like Projects and Goals). These Platform apps are not removable. However, Organization admins can manage (activate or deactivate) AI-powered Rovo features for Atlassian Apps in Atlassian Administration .
Certification is claimed for Rovo specifically, not just for AtlassianStrong

Atlassian states Rovo itself has completed SOC 2 and ISO 27001 external assessment, and commits to including AI capabilities in the annual compliance audit going forward. The claim is vendor-published; no certificate or scope statement naming Rovo was found in this collection.

Product-level certification scope is the usual gap in AI assurance — parent-company certificates routinely predate the AI feature. A vendor asserting the product is in scope is a strong signal, but the assertion is worth resolving against the certificate's actual scope statement before it is relied on.

Question for vendor: Can you provide the ISO 27001 certificate and SOC 2 report scope statements that name Rovo?

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Yes, Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001. Moving forward, Atlassian's AI capabilities will be included as part of Atlassian’s annual compliance audit.
Reliability limits are disclosed plainly rather than buriedStrong

Atlassian states directly that Rovo's models are probabilistic and can be inaccurate, incomplete or unreliable, and advises against using them where current and accurate facts are required.

Candid limitation disclosure is a governance signal in itself and gives an organisation defensible ground for its own acceptable-use guidance. It also distinguishes vendors that describe their systems honestly from those that market them as authoritative.

Evidence
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Because of this approach, these models can sometimes behave in ways that are inaccurate, incomplete, or unreliable. For example, the responses that you receive may not accurately reflect the content they are based on, or generate content that sounds reasonable but is incomplete and should not be relied on.
!Declared AWS Bedrock, technically observed AWSGap

The vendor's own materials name AWS Bedrock as the platform provider, but DNS, certificate, or HTTP evidence points to AWS in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether AWS Bedrock or AWS is the actual platform provider?

Evidence
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
?Technical dependency observed: IntercomObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Rovo honors all existing permissions within each feature. Users will not be able to create or generate content based on resources they do not have access to.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Rovo Apps are a core part of the Atlassian Cloud Platform, similar to other apps (like Projects and Goals). These Platform apps are not removable. However, Organization admins can manage (activate or deactivate) AI-powered Rovo features for Atlassian Apps in Atlassian Administration .
AI system15% of the score38
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Covered
Evidence — AI system description
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Rovo combines open-source, self-hosted models, and third-party hosted models to deliver an artificial intelligence experience tailored to you, your teams, and your workflows.
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Because of this approach, these models can sometimes behave in ways that are inaccurate, incomplete, or unreliable. For example, the responses that you receive may not accurately reflect the content they are based on, or generate content that sounds reasonable but is incomplete and should not be relied on.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score75
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Covered
Evidence — Model & provider transparency
Externally corroboratedAI Trust | Atlassianretrieved Aug 31, 2026
We use a diverse range of open models, including models from the Gemma series, GPT-oss series, LLama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers.
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Customer data15% of the score72
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
The LLM providers we use do not use your inputs and outputs to improve their services. Neither OpenAI nor any other LLM provider retains your inputs and outputs.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Atlassian may use metadata to fine-tune open-source models that operate strictly within Atlassian's infrastructure, solely to improve the quality of responses and experiences we deliver to customers. This use of contributed data is subject to data contribution settings, and we apply robust safeguards, including de-identifying and aggregating all contributed metadata before use.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Our third-party hosted LLM partners, including OpenAI, Anthropic, and Google, operate under strict zero data retention (ZDR) agreements.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
By default, when using Rovo, data is transferred outside of the current site to third party LLM providers (e.g., OpenAI) in order to generate a response.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Yes, data residency support is available for Rovo. With data residency for Rovo turned on, all of your in-scope app data will remain stored in the region you've selected.

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
OpenAI, L.L.C. Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence, Loom AI, or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Vendor publishedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Amazon Web Services, Inc. (AWS Bedrock) Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product
Externally corroboratedList of Data Subprocessors | Atlassianretrieved Aug 31, 2026
Google Vertex AI Applicable Cloud Products All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo Nature and Purpose of Processing Generative AI services provider for intelligence product features
Security foundation15% of the scoreorganisation-level evidence25

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Not Evidenced

Vulnerability & incident handling: not publicly evidenced.

Independent assurance evidence10% of the score85
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Yes, Rovo has completed the external assessment and compliance certifications for SOC 2 and ISO 27001. Moving forward, Atlassian's AI capabilities will be included as part of Atlassian’s annual compliance audit.

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 31, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO 22301retrieved Aug 31, 2026

Read from the registry record above — cited, not reproduced.

Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
Yes, the Atlassian Customer Agreement covers Rovo.
Vendor publishedAI Trust | Atlassianretrieved Aug 31, 2026
The following features are currently out of scope and must not be used with Protected Health Information (PHI) :

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+9Publish Vulnerability & incident handling evidenceSecurity Foundation 2585
+3Publish Change management evidenceAI System 3858
+3Complete the Governance & accountability disclosureOrganisation 4060
+2Have Customer data treatment disclosures independently corroboratedData 7287
+2Publish independently corroborated ISO/IEC 42001 (AI management system) certificationOrganisation 4052

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 56 → up to 80 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSAtlassianAtlassianRovoRovoOpenAI, L.L.C.OpenAI, L.L.C.Amazon Web Services (AWS Bedrock)Amazon Web Services (AWS …Google Vertex AIGoogle Vertex AIOpenAI GPT seriesOpenAI GPT seriesAnthropic Claude seriesAnthropic Claude seriesGoogle Gemini seriesGoogle Gemini seriesOpen models (Gemma, GPT-oss, Llama, Nemotron)Open models (Gemma, GPT-o…
View as list
Atlassian Uses AI Service Rovo
Rovo Contracted Subprocessor OpenAI, L.L.C.
Rovo Contracted Subprocessor Amazon Web Services (AWS Bedrock)
Rovo Contracted Subprocessor Google Vertex AI
Rovo Embedding Provider OpenAI GPT series
Rovo Embedding Provider Anthropic Claude series
Rovo Embedding Provider Google Gemini series
Rovo Routing Or Fallback Open models (Gemma, GPT-oss, Llama, Nemotron)

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 7 — registry checks and verification ladders, click to view
SOC 2Vendor claimed only

Atlassian states Rovo has completed SOC 2 external assessment. No report or scope statement naming Rovo was in this collection.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001Vendor claimed only

Claimed for Rovo specifically. The certificate's own scope statement was not available in this collection, so product coverage rests on the vendor's assertion.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 31, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 31, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 31, 2026: Verified on the registry

ISO 22301Claimed & corroborated

Scope names ROVO/AI explicitly among the certified products, so this certificate covers the assessed product rather than only its parent. Ported from the registry check already held on the Atlassian organisation record (IAF CertSearch, 25 Aug 2026).

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 31, 2026: Verified on the registry

Sources 16 — click to view
AI Trust | Atlassian
AI Documentation · Vendor · retrieved Aug 31, 2026
Trust Center | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 31, 2026
Data Processing Addendum | Atlassian
DPA · Vendor · retrieved Aug 31, 2026
List of Data Subprocessors | Atlassian
Subprocessor List · Vendor · retrieved Aug 31, 2026
Privacy Policy | Atlassian
Privacy Notice · Vendor · retrieved Aug 31, 2026
Atlassian Javadoc Home
Product Documentation · Vendor · retrieved Aug 31, 2026
Connect Compass to Your Developer Toolchain | Atlassian
Technical Architecture Documentation · Vendor · retrieved Aug 31, 2026
Atlassian Legal | Atlassian
Terms · Vendor · retrieved Aug 31, 2026
Building an internal API Catalog with Atlassian Compass | Atlassian
Technical Article · Vendor · retrieved Aug 31, 2026
Rovo: Unlock organizational knowledge with GenAI | Atlassian
AI Documentation · Vendor · retrieved Aug 31, 2026
Comprehensive Data Protection | Atlassian
Trust Or Security Page · Vendor · retrieved Aug 31, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
IAF CertSearch record — ISO 22301
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).
Requirements for bodies auditing/certifying AIMS · Published (Jul 2025) — turns AI management systems into a certification and assessor-competence conversation. Builds on ISO/IEC 17021-1.

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.