Hi @Jelena Vatavuk, @Frederik Nordahl Jul Sabroe, and @Ryan Kennedy,
I just wanted to provide an update here.
Customer data is encrypted in transit and at rest in Atlassian cloud products.
All customer data stored within Atlassian cloud products and services is encrypted in transit over public networks using Transport Layer Security (TLS) 1.2+ with Perfect Forward Secrecy (PFS) to protect it from unauthorized disclosure or modification.
Data drives on servers holding customer data and attachments in Jira Software Cloud, Jira Service Desk Cloud, Jira Core Cloud, Confluence Cloud, Statuspage, OpsGenie, and Trello use full disk, industry-standard AES-256 encryption at rest. To learn more, please see our Security Practices page.
We post updates related to security, privacy, compliance, and more in our Trust & Security group. Feel free to post related questions and feedback there!
Best,
Lauren
Application database backups for Atlassian Cloud occur on the following frequencies: On-site backups are performed daily and retained for seven days; Tape backups are taken weekly, which are then stored off-site and retained for four weeks. All backup data is encrypted.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for your response, but this didn't fully answer my question.
I am looking for data that is not only backed up - rather active data that is in transit or at rest.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Atlassian is compliant with SOC2, and their SOC2 report can be obtained here: https://www.atlassian.com/trust/compliance
Unfortunately the report clearly states on page 29 that "Data is not encrypted at rest. Data in transit is encrypted with the TLS cryptographic protocol."
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
We are an Atlassian Solution Partner and we've just released something that might help. It's called Team Secrets and it protects sensitive file attachments in JIRA with end-to-end encryption for attachment uploads and 2 factor verification for downloads.
https://marketplace.atlassian.com/plugins/io.teamsecrets.jira.prod/cloud/overview
Please try it and let us know if this helps!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I am also looking for the same data.
I need to know if the data at rest is encrypted or in any other way secured?
I also need to know if a 3rd party vendor can access/decrypt the data their facility is hosting?
Also, I need to know of any vendor has access to non-encrypted, non-public data in our instance?
I have not found a clear statement in your online documentation
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
This is the Atlassian Cloud Security document: https://www.atlassian.com/cloud/security/
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Again, thank you for your response, but this didn't fully answer my question.
I am looking for data that is not only backed up - rather active data that is in transit or at rest.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Old response:
I believe that data sent over public networks uses HTTPS and should have all of the security properties that HTTPS provides. Data at rest is not as simple as "it is all decrypted" or "it is all encrypted". Some data is and some data is not and I cannot give you a full breakdown of that information. Please raise a request at support.atlassian.com to get our excellent support team to gather that information for you.
Please see the latest answer down the bottom. My comment is old and no longer relevant.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.