Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

As a customer, how can I Marketplace App security attestations?

Tyler Gibson May 8, 2025

I am evaluating several marketplace apps, but have been stopped dead in my tracks by this question.


The data privacy guidance https://developer.atlassian.com/platform/marketplace/data-privacy-guidelines/


Says that it is solely the App developers responsibility to fill in this information accurately, and the the EcoScanner https://developer.atlassian.com/platform/marketplace/ecoscanner/ does not validate any of these data attestations.

What is preventing any 3rd party app developer from saying their application does not egress data to external hosts - but just doing it anyway?

Every other platform with a 3rd party ecosystem has data policies reinforced by 1st party validation of these policies.

I hope I'm just missing something here, but is the official policy really that every customer has to individually vet and monitor every single Marketplace Application release and update to try and ensure their data isn't put at risk?

2 answers

0 votes
Laura Campbell
Community Champion
May 9, 2025

Hi @Tyler Gibson ,

The website https://www.forge-apps.com/ may be useful for you if you are looking to find specifically apps that have no data egress

0 votes
Walter Buggenhout
Community Champion
May 8, 2025

Hi @Tyler Gibson,

I am not working at Atlassian, so can't make any statements as if I was inside their legal department. That as a bit of context up front.

Having said that, Atlassian offers a platform and an ecosystem that engages many hundreds - if not thousands - of partners all with their own legal entities across all global regions. In Atlassian's Trust Center you can read up on Atlassian's vision of shared responsibility for data security, privacy and compliance, where the responsibilities of Atlassian, 3rd party suppliers and customers are described.

They do have systems and shared information in place to make information available as much and as transparent as possible. A good starting point when you evaluate apps, is to look at the privacy and security page on the apps Marketplace listing. You should be able to find consolidated information there already in most cases. Often also with links to vendors' official agreements, certifications and so forth.

If you can't find what you are looking for there, yes: contacting the vendor in question is the way forward to get that information from the involved party directly.

Hope this helps! 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events