Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The main difference is who operates and patches the environment. Atlassian runs the Cloud hosting environment and applications, while customers still manage their data, users, access choices, trusted Marketplace apps, and compliance obligations. With Data Center, Atlassian supplies product releases and application-level security fixes, but customers operate the deployment and must apply updates and secure the underlying infrastructure. Neither option removes the customer’s security responsibilities.

Who is responsible for security in Atlassian Cloud and Data Center?

Atlassian describes Cloud security as a shared responsibility: Atlassian secures and operates the applications, systems, and hosting environment; customers manage the data in their accounts, users and account access, Marketplace apps they choose to trust, and their own compliance obligations. Atlassian summarizes the customer side this way: “You, our customers, manage the data within your accounts, the users and user accounts accessing your data, and control which Marketplace Apps (formerly called ‘add-ons’) you install and trust.” See Atlassian’s Cloud shared-responsibility overview.

Data Center is installed on customer-managed systems. Atlassian provides product releases and application-level security fixes, but the customer operates the deployment and is responsible for its infrastructure, operating systems, dependencies, secure configuration, access controls, encryption, and backups. Atlassian’s Data Center security checklist states: “Atlassian doesn’t take responsibility for self-managed hardware infrastructure.” Atlassian still provides product-level security releases and guidance; operating the environment is the customer’s job.

Responsibility by security area

Area Atlassian Cloud Atlassian Data Center
Hosting and systems Atlassian operates the hosting environment and systems. The customer operates the self-managed hardware and infrastructure.
Application fixes Atlassian operates the Cloud applications and service. Atlassian supplies product fixes; the customer installs them.
Operating systems and dependencies Underlying service systems fall within Atlassian’s general Cloud responsibility model; confirm product-specific boundaries for detailed requirements. The customer applies operating-system security updates, hardens systems, and maintains secure dependencies.
Data, users, and access The customer manages account data, users, and access decisions. The customer configures the product securely and manages access controls.
Marketplace apps The customer chooses which apps to install and trust. The customer evaluates apps and dependencies as part of the self-managed environment.
Encryption and backups The customer remains responsible for its data and compliance decisions; exact Cloud features and contractual controls depend on the relevant product and plan. The customer implements encryption according to policy and performs regular backups.
Continuity and recovery Atlassian manages Cloud infrastructure, product, and service reliability and recoverability; customers maintain their own continuity and disaster-recovery plans. The customer plans and operates recovery for the self-managed environment.

The table reflects Atlassian’s general guidance in its Cloud responsibility overview, Data Center security checklist, and Cloud resilience overview. Exact boundaries can vary by product, plan, contract, and configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who patches Jira Data Center?

For Data Center, Atlassian develops and publishes product releases and application-level fixes; the organization running the instance must install them. Administrators also maintain the operating system, dependencies, and infrastructure around the product. Atlassian advises customers to upgrade promptly to address known vulnerabilities, but its guidance does not establish a universal number of days in which every customer must deploy each fix.

That makes patching a combined process: Atlassian must release a fix, and the customer must evaluate and roll it out to its own environment. A vendor’s remediation target is not the same as a deadline or guarantee that a customer-managed instance has been patched.

Atlassian’s vulnerability remediation targets

Atlassian’s Security Bug Fix Policy sets targets of 90 days for verified Critical, High, and Medium vulnerabilities and 180 days for verified Low vulnerabilities. These are Atlassian product-fix targets. They do not mean Atlassian has installed the fix on each Data Center customer’s instance, nor do they define a customer’s deployment SLA.

Cloud patching

Because Atlassian operates the Cloud service and its applications, customers generally do not install application or hosting patches themselves. Their security work remains active: they manage accounts and access, handle data appropriately, choose trusted Marketplace apps, and meet their own compliance obligations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why Data Center version support matters

Patching is not only about installing an individual fix; it also means staying on a supported release. Atlassian says Data Center feature and Long Term Support (LTS) releases are supported for two years after their initial release. Releases that reach end of support no longer receive support. Atlassian recommends upgrading to the latest feature or LTS release; check the current End of Support Policy and the relevant product lifecycle page for version-specific dates, which differ by release and can change.

A team choosing Data Center needs a process to track its installed version, plan upgrades, and apply fixes within its own change-management and testing procedures. The two-year support period is a release support window, not a statement that every vulnerability will take two years to fix.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to compare the security workload

Neither deployment model is categorically more secure. The practical difference is the boundary between Atlassian’s operational work and the customer’s. Compare the models against the organization’s actual staffing, controls, and obligations:

  • Patch operations: Decide whether the organization wants Atlassian to operate the Cloud service or has the people and processes to install Data Center product fixes and operating-system updates.
  • Infrastructure ownership: Consider whether the organization needs to operate self-managed infrastructure or prefers Atlassian to run the hosted environment.
  • Identity and configuration: Both models require customer attention to users and access. Data Center additionally calls for customer configuration of access controls, MFA or SSO options, encryption, and secure settings.
  • Lifecycle discipline: Data Center requires a reliable way to track supported versions and upgrade before support ends.
  • Compliance and continuity: Separate Atlassian’s platform controls from the customer’s compliance program, recovery planning, and business-continuity duties. Verify requirements against the specific product, plan, contract, and regulatory context.

Cloud reduces the customer’s infrastructure and application-patching workload, but leaves important account, data, app-trust, and compliance decisions with the customer. Data Center provides operational control alongside responsibility for patch deployment and infrastructure security. The right choice depends on which responsibilities the organization can meet consistently.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.