Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Atlassian Cloud security is shared: Atlassian operates and protects its applications and hosting environment, while your organization manages users, permissions, stored content, Marketplace apps, and its own compliance and recovery needs. Data residency applies to specific in-scope app data, not every piece of information associated with your organization; IP allowlisting can restrict access to supported apps and plans, but documented exceptions mean it is not a universal network perimeter.

Where is my Atlassian Cloud data stored?

Atlassian data is hosted across AWS regions. For apps whose data residency is set to a particular location, Atlassian keeps the documented in-scope data in that location. If residency is “Not set,” the app’s location is dynamically assigned across AWS regions for operational and performance needs. Residency is configured at the app level, not separately for a project, client, or user. Atlassian’s data residency guide provides the current product-by-product scope and location table.

Atlassian’s architecture page reviewed on October 4, 2026, lists 11 regions. The support guide names these location labels and associated AWS regions:

Residency location AWS region or regions listed
Australia Sydney
Canada Central
EU Frankfurt and Dublin
Germany Frankfurt
India Mumbai
Japan Tokyo
Singapore Singapore
South Korea Seoul
Switzerland Zurich
United Kingdom London
USA North Virginia and Oregon

A location label is not a promise of a specific city or data center. In particular, “USA” covers North Virginia and Oregon; customers cannot select East versus West, and Atlassian may manage data between those regions. India is not assigned by default, including for organizations based in India. Location availability and product eligibility can change, so confirm the live support guide for the specific app and organization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does data residency keep all Atlassian data in one country?

No. Residency controls the location of designated, in-scope data for an app. It does not mean every organization-related data type is stored only in the selected country. Atlassian’s examples include Jira issues and field content, comments, attachments, search data, and project configuration. For Confluence, in-scope examples include page and blog content, comments, attachments, search data, whiteboards, databases, and some metadata. The exact inclusions and exclusions vary by product.

User account information such as names, email addresses, and avatars is managed by a central identity service with globally distributed replicas, so it is out of scope for app-level residency. Logs, analytics, AI data, integrations, and other categories may also be excluded depending on the app. Check the product-specific tables in Atlassian’s residency guide before treating a location pin as a complete data-localization guarantee.

Atlassian lists Jira, Jira Service Management, Jira Product Discovery, and Confluence among products with residency availability on its Cloud architecture and security practices page. The support guide has its own product and plan scope and also references Loom in relevant contexts. Availability depends on product and plan; verify current eligibility for the app you intend to pin.

What happens when an app is moved?

Atlassian says a residency move may require app downtime of up to 24 hours, and search may be unavailable during re-indexing for up to three days, depending on data size. These are documented upper bounds, not a forecast for a specific site. Schedule the move within an appropriate change window.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I restrict Atlassian Cloud access by IP address?

Yes, for supported apps and plans, organization administrators can create an IP allowlist that limits access to covered app content to specified IP addresses or locations. Atlassian says users outside the allowed range cannot access covered pages or use the app programmatically through its APIs. Eligibility is plan-specific: the support guide lists Premium for Jira, Jira Service Management, Confluence, and Compass; Enterprise for Atlassian Analytics and Focus; and at least one of those listed plans for Rovo IP allowlist controls. Confirm current entitlements in Atlassian’s IP access guide.

Do not treat an app allowlist as a guarantee that every route to related information is blocked. Atlassian documents exceptions and additional configuration needs, including some Rovo experiences, recent-history and notification details, Smart Links, and specified OAuth, Connect, and Forge integration pathways. Without applicable Rovo allowlisting, titles, previews, and paraphrased content from restricted objects may still surface in Rovo. Map the apps, APIs, integrations, and AI experiences your organization uses before relying on an allowlist as a boundary.

Customer IP allowlisting is distinct from Atlassian’s own infrastructure network controls. Atlassian describes internal network zones, environment separation, service authentication allowlists, VPC routing, firewalls, software-defined networking, and encrypted connections into sensitive networks. Those are Atlassian-operated controls, not customer-managed settings.

What security controls does Atlassian provide?

Atlassian documents several controls for its Cloud services. These describe the platform’s stated practices; they are not an independent assessment of a particular customer’s configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Encryption in transit: TLS 1.2 or higher with Perfect Forward Secrecy for customer data traveling over public networks.
  • Encryption at rest: AES-256 encryption for data drives holding customer data and attachments in named Cloud products.
  • Tenant separation: Logical separation and service-level authorization in a multi-tenant architecture.
  • Support access: Access is limited to authorized personnel; customers must explicitly consent before support engineers access customer data stored in applications.

Regular Atlassian Cloud is not single-tenant infrastructure. Atlassian states, “We do not offer a single tenant architecture in our regular Atlassian Cloud,” and points to Isolated Cloud as its single-tenant offering. See Atlassian’s architecture and operational practices for its description of these controls.

What security responsibilities stay with my organization?

Atlassian is responsible for the security, availability, and performance of the applications it provides, their systems, and their hosting environments. Your organization remains responsible for how it uses and configures the service, including its policies and compliance obligations, users and accounts, customer-stored information, and Marketplace apps. Atlassian’s shared responsibility guidance highlights several customer-side safeguards:

  • Verify domains and use centralized identity and account management where appropriate.
  • Apply centralized authentication controls and review access as roles and needs change.
  • Set permissions deliberately, especially for sensitive projects and spaces.
  • Evaluate Marketplace apps and their access to organizational information.
  • Govern public sharing: information made public may be copied or redistributed in ways Atlassian cannot prevent.

For centralized identity administration, authentication enforcement, and security capabilities, Atlassian presents Guard Standard and Guard Premium. The right choice depends on the controls your organization needs; see Atlassian Guard for current service details.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do Atlassian Cloud backups restore data users deleted?

No. Atlassian explicitly says it does not use its backups to reverse customer-initiated destructive changes, such as deleted work items, projects, or sites. Platform backups are for Atlassian’s service recovery, not a customer-facing version history or general-purpose undelete feature.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Atlassian describes daily automated Amazon RDS snapshots retained for 30 days, encrypted with AES-256, replicated among data centers within a particular AWS region, and quarterly backup testing. Its architecture page says Bitbucket storage snapshots are retained for seven days. Those platform practices do not replace a customer backup and recovery plan designed for your data and business needs. See Atlassian’s security practices.

What recovery targets does Atlassian publish?

Atlassian’s resilience page states a one-hour recovery point objective (RPO) and six-hour recovery time objective (RTO) target for an unplanned event affecting Cloud product reliability. These are Atlassian-published targets, not a guarantee of a particular tenant’s recovery result. Atlassian handles infrastructure and product recovery; your organization still needs business continuity and disaster recovery plans for its own operations. See Atlassian’s resilience approach.

How should I evaluate Atlassian Cloud security for compliance?

Start with the precise obligation you need to satisfy, then validate the relevant product and configuration rather than treating “Atlassian Cloud” as one uniform scope. Check which data types are in scope for residency, whether the required geography and product plan are available, and whether allowlisting covers the access paths your team actually uses. Include customer-managed identity, permissions, apps, backups, and continuity in the review.

Atlassian directs customers to its current Compliance page and authenticated Customer Trust Portal for reports, certifications, and detailed materials. Compliance scope varies by product and program; for an audit or procurement decision, verify the applicable product, report period, and certification in the live portal instead of assuming every Cloud product shares the same coverage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.