Atlassian documents edge and network defenses as part of the security it operates for its Cloud services—not as a separately documented customer appliance or product called “Atlassian Edge Security.” Those safeguards protect Atlassian’s environment. They do not remove an organization’s responsibility to secure its own network, identity systems, endpoints, or self-hosted applications.
What does Atlassian Edge Security do?
Atlassian’s Technical and Organisational Security Measures, effective October 7, 2025, describe controls within Atlassian’s environment. These include DDoS mitigation for Cloud products and related infrastructure, firewalls at corporate network edges, network and host defenses, and logical separation of customer data. The material describes security measures Atlassian operates; it does not establish a separately purchasable product named Atlassian Edge Security.
For Atlassian Cloud, these controls contribute to the security of the service Atlassian runs. They should not be read as protection for a customer’s separate public website, self-hosted Jira or Confluence instance, or other independently operated application.
Cloud encryption has stated scope
Atlassian’s Security Practices says Atlassian Cloud customer data is encrypted in transit over public networks using TLS 1.2 or later with Perfect Forward Secrecy. It also says drives holding data for a named set of Cloud products use AES-256 encryption at rest. These statements apply to the product scope described on that page; they should not be generalized to every Atlassian product or deployment.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Does Atlassian’s edge security replace a WAF?
No. Atlassian’s Cloud edge safeguards and a customer-configured web application firewall (WAF) have different operators and scopes. Atlassian describes defenses for its own Cloud environment. A WAF configured for an application or network you operate can filter web requests reaching that infrastructure.
Atlassian’s Data Center security checklist and shared responsibilities describes WAF protection against common threats such as injection attacks, predictable resource location attacks, HTTP DDoS, HTTP request smuggling, file path traversal, server-side request forgery (SSRF), and clickjacking. That list explains the kinds of threats a WAF may help address; it is not a guarantee that a WAF prevents every attack.
Rank #2
A WAF is also not a substitute for identity and operational controls. Atlassian’s checklist treats network placement, timely security fixes, VPN, MFA, SSO, encryption, access controls, and regular backups as distinct parts of securing a Data Center deployment. A WAF does not patch vulnerable software, verify every user’s identity, protect every endpoint, or restore lost data.
Do I still need a firewall or VPN?
That depends on what you operate and how your organization connects to Atlassian:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →- For Atlassian Cloud: Atlassian operates the service-side edge and network controls it describes. Your organization still manages its own network and access policies. If outbound firewall or proxy rules are restrictive, they may need to permit Atlassian’s documented domains and IP ranges.
- For Jira or Confluence Data Center: Your organization operates the deployment and must secure the application and surrounding network. Atlassian’s checklist recommends private network placement and configuration of relevant controls, including a WAF, VPN, MFA, and SSO. Which controls are appropriate depends on your architecture and access requirements.
- For a separate website or application: Atlassian’s Cloud service defenses do not protect infrastructure you run independently. Secure that perimeter and application according to its own exposure and risks.
A VPN controls how users or systems connect to a network; a firewall enforces network traffic rules; and a WAF focuses on web requests. They serve different purposes, so one should not be assumed to replace the others. Atlassian’s checklist frames security as shared responsibility: “This model requires customers to implement practices that continue beyond deployment and extend into operational phases.”
What do I need to configure for Jira or Confluence Data Center?
Use Atlassian’s Data Center security checklist as a starting point for the deployment you operate. Its recommendations cover several layers:
Rank #4
- Network placement: Keep the deployment on a private network where appropriate and control how users and services can reach it.
- Application maintenance: Apply security fixes in a timely way; perimeter filtering cannot compensate for unpatched software.
- Traffic and remote access: Assess and configure a WAF and VPN where they fit your network design.
- Identity and permissions: Configure MFA, SSO, and access controls appropriate to the users and services that need access.
- Data safeguards and recovery: Address encryption and maintain regular backups.
The checklist is guidance, not a declaration that every deployment has identical requirements. Review the exposure, architecture, and access patterns of your own Data Center environment when deciding how to implement each control.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which Atlassian domains should my firewall allow?
Use Atlassian Support’s live IP addresses and domains for Atlassian cloud apps guide to identify the domains and IP ranges your Cloud apps and organization require. Atlassian says the list can change, so consult the current guide when creating or maintaining firewall and proxy rules rather than relying on a copied list.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
One listed domain is *.awswaf.com, which Atlassian identifies as AWS WAF intelligent threat mitigation used to verify browser authenticity and required for Cloud product login and use. If a restrictive proxy or firewall blocks that dependency, users may be unable to complete browser verification or use Cloud products as expected. Follow the current allowlisting guide for the complete set of requirements applicable to your services.
How does Atlassian Guard external-site policy fit in?
Atlassian Guard’s external-site policy can limit access to external Atlassian Cloud sites. Atlassian’s Manage access to external sites guidance says broader coverage requires network infrastructure—such as a proxy, firewall, or SASE platform—to add the policy header to outgoing HTTPS requests sent to Atlassian.
This is an example of an organization-level policy working with network controls, not replacing them. The policy’s reach depends on how outgoing traffic is handled across the organization.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

