Close

Marketplace App Trust

Customize freely. Scale securely.

Extend your Atlassian platform with confidence

Customizing your digital workplace should be seamless, powerful, and secure. Whether you're adding your first workflow integration or scaling tools across multiple departments, the Atlassian Marketplace delivers specialized solutions with security built right in.

Trust isn't an add-on in our Marketplace—it’s the foundation. With platform guardrails, continuous automated monitoring, and rigorous trust programs, your teams can move quickly and work with confidence.

Setting a privacy & security baseline

Atlassian enforces comprehensive security and privacy standards across the Atlassian Marketplace through platform-level baselines, continuous automated oversight, and third-party security initiatives.

Mandatory Security Baselines for Cloud Apps

Every Marketplace cloud app must adhere to Atlassian’s mandatory app security requirements. Governed by comprehensive security assessments during initial listing and ongoing updates, these requirements enforce active risk reduction and ensure platform-wide adherence to security best practices.

Maintaining security through continuous scanning

Atlassian centrally manages a comprehensive vulnerability scanning and management program powered by our proprietary Ecoscanner platform. Ecoscanner performs ongoing automated security checks across all Marketplace cloud apps—proactively screening for supply chain risks, malware, static code vulnerabilities, and security misconfigurations while continuously evaluating configuration hygiene.

If an app fails to meet any security requirement, Atlassian initiates immediate remediation.

Timely resolution of security issues

To ensure swift resolution of any identified risks, Marketplace Partners are contractually required to adhere to strict security bug-fix SLAs aligned with Atlassian’s internal standards, remediating and deploying fixes within mandatory, defined timelines.

Proactive Crowdsourced Defense via Bug Bounty

Through Atlassian’s ecosystem Bug Bounty program, partners engage vetted security researchers to uncover and remediate vulnerabilities early. Running public programs establishes a transparent, documented, and incentivized channel for responsible vulnerability disclosure. While optional across the broader Marketplace, participation in bug bounties is mandatory for apps to qualify for Cloud Fortified and Atlassian Enterprise Certified badges.

Ensuring transparency through privacy requirements

All Marketplace Partners must publish a comprehensive Privacy Policy detailing their data collection, processing, storage, and retention practices—including sub-processor transparency and geographic data storage. Furthermore, Atlassian requires partners to maintain explicit end-user consents and adhere to strict data-handling obligations under the Atlassian Developer Terms.

Specialized application penetration testing

Atlassian centrally manages the Marketplace Penetration Testing Program connecting Marketplace Partners with CREST-certified security experts for deep, platform-tailored testing. The program streamlines scoping, vulnerability logging, and remediation tracking to uncover complex attack vectors before they impact production environments. Customers can easily discover participating apps using the Penetration Testing filter on the Atlassian Marketplace.

Find apps built for your highest security and reliability standards

Every app on the Atlassian Marketplace meets our foundational cloud requirements for security, reliability, and performance. For teams with advanced governance needs, badges like Atlassian Enterprise Certified and Runs on Atlassian help you easily identify apps that have gone above and beyond Atlassian's baseline standards to deliver a secure and reliable cloud experience.

The requirements for each badge are as follows:

 

 

All Cloud apps

Cloud Fortified apps

Runs on Atlassian

Privacy

App privacy policies

All Cloud apps

Cloud Fortified apps

Runs on Atlassian

Security

Base cloud app security requirements

All Cloud apps

Cloud Fortified apps

Runs on Atlassian

Monitored by Atlassian’s app vulnerability scanning platform, Ecoscanner

All Cloud apps

Cloud Fortified apps

Runs on Atlassian

Additional app security requirements and fix timeframes defined by Atlassian

All Cloud apps

Cloud Fortified apps

Runs on Atlassian

Participates in Marketplace Bug Bounty Program

All Cloud apps

 

Cloud Fortified apps

Runs on Atlassian

 

Has a complete Privacy & Security tab

All Cloud apps

 

Cloud Fortified apps

Runs on Atlassian

 

Hosted on Atlassian

All Cloud apps

 

Cloud Fortified apps

 

Runs on Atlassian

Data stored within Atlassian

All Cloud apps

 

Cloud Fortified apps

 

Runs on Atlassian

Data residency compliant

All Cloud apps

 

Cloud Fortified apps

 

Runs on Atlassian

Reliability

Additional checks for service reliability and performance at scale

All Cloud apps

 

Cloud Fortified apps

Runs on Atlassian

 

Incident and review processes integrated with Atlassian’s for faster recovery and continuous improvement

All Cloud apps

 

Cloud Fortified apps

Runs on Atlassian

 

Support

Commercially reasonable efforts to provide support

All Cloud apps

Cloud Fortified apps

Runs on Atlassian

24 hour response time, 5 days a week SLA for all T1 tickets

All Cloud apps

 

Cloud Fortified apps

Runs on Atlassian

 

Atlassian Enterprise Certified

The Atlassian Enterprise Certified badge highlights Marketplace apps that meet common enterprise needs for compliance, security, reliability, privacy, accessibility, and responsible AI use.

Runs on Atlassian

Runs on Atlassian (RoA) apps are hosted on the Forge platform, limit data egress, and offer data residency.

Cloud Fortified

Cloud Fortified apps demonstrate an extra layer of trust through Bug Bounty participation, reliability at scale, and dedicated 24/5 critical support.

Note: This badge will be sunsetted as of December 31st, 2026.

Venn Diagram spot

The Shared Responsibility Model: Trust in Practice

Building a secure digital workplace is a collaborative partnership across three key pillars:

Marketplace Partners

Marketplace partners design apps and operational processes according to their legal obligations, Atlassian’s requirements, and general industry best practices for reliable, compliant, and secure apps.

Atlassian

Atlassian provides information and capabilities to help Marketplace Partners build trustworthy apps, while giving customers the centralized visibility, transparency, and controls needed to vet and govern them confidently.

You

You are responsible for assessing app suitability and reviewing partner policies. Installing an app establishes a separate, direct relationship between your organization and the third-party partner.

Atlassian enforces comprehensive security and privacy standards across the Atlassian Marketplace through platform-level baselines, continuous automated oversight, and third-party security initiatives.

Frequently asked questions

What does Atlassian do to ensure the security of Marketplace apps?
  

Atlassian has programs and requirements in place to ensure a baseline of security and privacy across 3rd party Marketplace apps, as well as opt-in programs to encourage additional investment. We also regularly share educational materials to help Marketplace Partners build trustworthy cloud apps.

To maintain the baseline of security and privacy best practices across all 3rd party cloud apps, Atlassian regularly scans all cloud apps listed on the Marketplace. Specific Cloud Security Requirements are enforced via a set of security scanners powered by Atlassian’s EcoScanner platform.

Marketplace Partners must also complete a set of security questionnaires as part of the existing App Onboarding and App Review Processes. This ensures continual assurance that apps meet or exceed the bar Atlassian has set for app security and that Marketplace Partners adhere to organizational best practices.

In addition, all Marketplace Partners must undergo a Personal and Business Identification (KYC/KYB) process. They must also accept and comply with Atlassian Developer Terms, Marketplace Partner Agreement, and Security Bug Fix Policy for Marketplace apps, which outline legal and privacy requirements and SLAs for security bugs.

Alongside our baseline security requirements, we also issue badges for the Marketplace to apps that have made additional investments in security, reliability, and support. These badges identify:

For trust-related information (data protection, security, privacy, compliance) about specific apps, you can also view the answers provided by the app’s vendor in the Privacy & Security tab of their app listing on the Atlassian Marketplace.

Can Marketplace apps access, process or store my data?
  

Most apps require access to data in your instance to perform their core functions. Admins must review and consent to requested permissions during the installation flow.

Where and how data is handled depends on the app's architecture and certifications:

  • Runs on Atlassian (RoA): Apps with this badge process and store customer data exclusively on Atlassian cloud infrastructure, while giving administrators visibility and control over any external data egress (such as analytics).
  • Atlassian Enterprise Certified (AEC): If an AEC app processes or stores data off-Atlassian, its hosting environments and data handling controls have been rigorously verified against AEC requirements.
  • Privacy & Security Tab: Check any app listing for granular details on permissions, data processing, storage, and retention.
Are there controls to block Marketplace Partners from accessing or extracting customer data?
  

With the app access rule under data security policies, customers can limit app access to certain content in selected projects or spaces. You can create an app access rule to limit an app’s ability to access and modify certain data in a Confluence space or Jira project, particularly user-generated content such as pages, blog posts, attachments, and other content that a user adds to a Confluence space or Jira project. This feature enables org admins to block all apps from spaces and projects, whereas Atlassian Access customers can make a selection and block a subset of installed apps. Learn more about blocking app access.

Atlassian is building more data loss prevention capabilities, such as data classification, to our Cloud offerings. Atlassian Guard is an easy way to defend your data and improve security posture. You can stay up-to-date on the development of these features by following our Cloud roadmap.

Additionally, there are vendors in the Atlassian Marketplace who provide DLP solutions that may meet your needs.

Do I have to go through a security assessment for each Marketplace app I am using?
  

Yes. Marketplace partners are independent businesses, and installing an app establishes a direct relationship with that partner.

Atlassian sets strict baselines to protect our customers. All Marketplace partners must comply with our security requirements for cloud apps, though Atlassian is not directly responsible for third-party products or services. Customers are responsible for reviewing third-party apps, agreements, and privacy policies against their internal standards.

To simplify your evaluation, every cloud app listing includes a Privacy & Security tab detailing security practices, permissions, and compliance certifications.

You can also explore our trust programs to identify apps meeting higher enterprise standards:

  • Runs on Atlassian (RoA): Indicates apps built exclusively on Atlassian-hosted infrastructure (About Forge), while giving administrators visibility and control over any external data egress (such as analytics).
  • Atlassian Enterprise Certified (AEC): Highlights apps vetted against comprehensive enterprise security, reliability, and support requirements—including independent verification of external data handling for apps hosting data off-Atlassian.

If you have additional questions about a specific tool, we recommend contacting the partner directly via the security contact on their listing to ensure it meets your organization’s requirements.

How does Atlassian help Marketplace partners protect customer data?
  

Atlassian provides programs, developer tools, educational resources, and compliance frameworks to ensure third-party Marketplace apps protect your data.

Key safeguards include:

  • Strict security standards: Mandatory Security requirements for cloud apps
  • Trust programs: Runs on Atlassian and Atlassian Enterprise Certified badges, helping you easily identify apps meeting higher reliability and security standards.
  • Secure infrastructure: Forge, offering built-in security controls and data isolation.
  • Compliance capabilities: APIs and services to help partners support data residency requirements: Understand data residency | Atlassian Support

If a partner fails to meet these standards, Atlassian enforces accountability by removing badges, pausing or hiding app listings, or listing non-compliant apps on a public transparency page.

What administrative controls does Atlassian provide to manage Marketplace apps?
  

Administrators have centralized visibility and granular control through admin.atlassian.com, including:

  • Centralized monitoring: Manage, review, and track all installed apps across your organization from a single console.
  • Installation guardrails: Restrict end-user app installs and establish approval workflows before apps are added to your workspace.
  • Granular access controls: Limit app data access to specific spaces, projects, or selected content.
  • Audit & activity tracking: ReviewView audit log activities | Atlassian Supportto audit actions, changes, and access events.
  • Listing transparency: Access mandatory partner privacy policies and detailed security disclosures directly on the Marketplace.
How can I evaluate an app’s security and privacy before installing it?
  

We recommend a 5-step evaluation process:

  1. Check the Privacy & Security tab: Review permissions, certifications, and data handling practices.
  2. Read the partner’s privacy policy: Confirm data retention and usage terms.
  3. Visit the partner trust center (if available): Review external audits, certifications, and security whitepapers.
  4. Reach out directly: Use the dedicated security contact listed on the Marketplace page for specific compliance inquiries.
  5. Track version updates: Use the Connected Apps tab in admin.atlassian.com to monitor ongoing changes and updates.

Trust & Security Community

Join the Trust & Security group on the Atlassian Community to receive information, tips, and best practices for using Atlassian products in a secure and reliable way.