VendorScore · Project management · Data-access posture

Can Atlassian read your Jira and Confluence data?

A plain-language answer from Atlassian's public Trust Center, support docs and legal pages. Customer-managed keys give you custody and revocation; Atlassian still decrypts content to run Jira and Confluence.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, Atlassian can read your Jira and Confluence data by design (with controls). CMK puts the root key in your AWS account and lets you revoke it, but Atlassian still decrypts content to run the product and some data stays on Atlassian keys. Support access requires your explicit consent.

63 / 100 overall

Scored configuration: Jira, Jira Service Management and Confluence Cloud Enterprise with the Customer-managed keys (CMK) add-on (customer AWS KMS).

Default (Atlassian-managed keys): the report estimates Overall ~55.

Report confidence: Medium-high.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Atlassian (Jira & Confluence)'s public documentation:

  • CMK only applies to new sites, one policy per org; migrating existing sites wasn't reviewed.
  • The default of Atlassian's data-contribution setting (which governs fine-tuning on de-identified metadata) isn't stated: Unknown.
  • SOC report contents weren't reviewed, and Atlassian's compliance page showed no certificate list in the fetched HTML.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Atlassian (Jira & Confluence) data access, AI training, GDPR and residency

Can Atlassian read your Jira and Confluence data?

Yes, Atlassian can read your Jira and Confluence data by design (with controls). CMK puts the root key in your AWS account and lets you revoke it, but Atlassian still decrypts content to run the product and some data stays on Atlassian keys. Support access requires your explicit consent. VendorScore rates Atlassian (Jira & Confluence) 63/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Jira, Jira Service Management and Confluence Cloud Enterprise with the Customer-managed keys (CMK) add-on (customer AWS KMS).

Does Atlassian support BYOK or customer-managed keys? Is Jira data encrypted at rest?

Yes. Atlassian cloud data is encrypted at rest with full-disk AES-256 and in transit with TLS 1.2+ with Perfect Forward Secrecy; by default it's "automatically encrypted using Atlassian managed keys". Customer-managed keys (CMK) put the root key in your own AWS KMS, let you revoke Atlassian's access and log key use in AWS CloudTrail. CMK is a paid Cloud Enterprise add-on for new sites, covers Jira, Jira Service Management and Confluence only, and leaves out-of-scope data such as the Confluence search index and email notifications on Atlassian-managed keys. BYOK is "no longer offered to new customers". None of this is E2EE: Atlassian still decrypts content to run the product.

Can Atlassian employees see my Confluence pages?

Only in defined cases. Atlassian says hosted data is accessed for application health monitoring and system maintenance, "or upon customer request via our support system", and that "before our support engineers are able to access customer data stored within our applications, our customers must provide their explicit consent" through a consent control checker. Unauthorized access is treated as a security incident. Access is limited by policy and consent, not prevented by cryptography.

Does Atlassian Intelligence or Rovo train on my data?

Not third-party LLMs. Atlassian's AI trust page says: "Atlassian does not share customer metadata or in-app data with our third-party-hosted LLM providers for them to use to train or improve their services." Its LLM partners operate under zero data retention agreements. Atlassian may fine-tune open-source models inside its own infrastructure on de-identified, aggregated metadata, "subject to data contribution settings"; the page doesn't state that setting's default. Separately, Atlassian's privacy policy lets it use support information (not in-product data) for training or fine-tuning machine learning models.

Is Atlassian GDPR compliant? Where is the Atlassian DPA?

VendorScore doesn't certify compliance; Atlassian publishes a DPA at https://www.atlassian.com/legal/data-processing-addendum. The DPA promises at least 30 days' notice before a new subprocessor; if you object, your remedy is to terminate the affected product. It also gives audit rights.

Who are Atlassian's subprocessors?

Atlassian's public list gives product, purpose, data category and location for each entry. Infrastructure includes AWS, Clumio, Databricks, Microsoft (Jira Align) and MongoDB; communications include Mailgun, Bird and Twilio. When Atlassian Intelligence or Rovo is enabled, AI processors include AWS Bedrock, Google Vertex AI and OpenAI. Outsourced support includes e-Core, SoftServe and Telus. The list is published at https://www.atlassian.com/legal/sub-processors.

Can I keep Jira and Confluence data in the EU (data residency)?

Yes. Jira, Jira Service Management, Jira Product Discovery, Loom and Confluence on Standard, Premium or Enterprise can pin in-scope data to the EU (Frankfurt + Dublin), Germany, Switzerland, the UK, the US and other locations. User account data is out of scope.

Compare Atlassian (Jira & Confluence)

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (atlassian.md), evidence dated 2026-10-07.