VendorScore · Project management · Data-access posture
A plain-language answer from Atlassian's public Trust Center, support docs and legal pages. Customer-managed keys give you custody and revocation; Atlassian still decrypts content to run Jira and Confluence.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, Atlassian can read your Jira and Confluence data by design (with controls). CMK puts the root key in your AWS account and lets you revoke it, but Atlassian still decrypts content to run the product and some data stays on Atlassian keys. Support access requires your explicit consent.
Scored configuration: Jira, Jira Service Management and Confluence Cloud Enterprise with the Customer-managed keys (CMK) add-on (customer AWS KMS).
Default (Atlassian-managed keys): the report estimates Overall ~55.
Report confidence: Medium-high.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Atlassian support engineers must get your explicit consent through a "consent control checker" before they can access customer data in Jira or Confluence.
Evidence: Atlassian security practicesCustomer-managed keys are a paid Cloud Enterprise add-on for new sites only. Out-of-scope data such as the Confluence search index and email notifications stays on Atlassian-managed keys.
Evidence: Data managed with encryptionOur report flags these gaps in Atlassian (Jira & Confluence)'s public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, Atlassian can read your Jira and Confluence data by design (with controls). CMK puts the root key in your AWS account and lets you revoke it, but Atlassian still decrypts content to run the product and some data stays on Atlassian keys. Support access requires your explicit consent. VendorScore rates Atlassian (Jira & Confluence) 63/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Jira, Jira Service Management and Confluence Cloud Enterprise with the Customer-managed keys (CMK) add-on (customer AWS KMS).
Yes. Atlassian cloud data is encrypted at rest with full-disk AES-256 and in transit with TLS 1.2+ with Perfect Forward Secrecy; by default it's "automatically encrypted using Atlassian managed keys". Customer-managed keys (CMK) put the root key in your own AWS KMS, let you revoke Atlassian's access and log key use in AWS CloudTrail. CMK is a paid Cloud Enterprise add-on for new sites, covers Jira, Jira Service Management and Confluence only, and leaves out-of-scope data such as the Confluence search index and email notifications on Atlassian-managed keys. BYOK is "no longer offered to new customers". None of this is E2EE: Atlassian still decrypts content to run the product.
Only in defined cases. Atlassian says hosted data is accessed for application health monitoring and system maintenance, "or upon customer request via our support system", and that "before our support engineers are able to access customer data stored within our applications, our customers must provide their explicit consent" through a consent control checker. Unauthorized access is treated as a security incident. Access is limited by policy and consent, not prevented by cryptography.
Not third-party LLMs. Atlassian's AI trust page says: "Atlassian does not share customer metadata or in-app data with our third-party-hosted LLM providers for them to use to train or improve their services." Its LLM partners operate under zero data retention agreements. Atlassian may fine-tune open-source models inside its own infrastructure on de-identified, aggregated metadata, "subject to data contribution settings"; the page doesn't state that setting's default. Separately, Atlassian's privacy policy lets it use support information (not in-product data) for training or fine-tuning machine learning models.
VendorScore doesn't certify compliance; Atlassian publishes a DPA at https://www.atlassian.com/legal/data-processing-addendum. The DPA promises at least 30 days' notice before a new subprocessor; if you object, your remedy is to terminate the affected product. It also gives audit rights.
Atlassian's public list gives product, purpose, data category and location for each entry. Infrastructure includes AWS, Clumio, Databricks, Microsoft (Jira Align) and MongoDB; communications include Mailgun, Bird and Twilio. When Atlassian Intelligence or Rovo is enabled, AI processors include AWS Bedrock, Google Vertex AI and OpenAI. Outsourced support includes e-Core, SoftServe and Telus. The list is published at https://www.atlassian.com/legal/sub-processors.
Yes. Jira, Jira Service Management, Jira Product Discovery, Loom and Confluence on Standard, Premium or Enterprise can pin in-scope data to the EU (Frankfurt + Dublin), Germany, Switzerland, the UK, the US and other locations. User account data is out of scope.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (atlassian.md), evidence dated 2026-10-07.