Atlassian Intelligence
atlassian.comThe two documents supplied — a Third-Party Code Policy and a Security Practices page — describe Atlassian's software licensing terms and its security program in detail, but neither is a privacy policy, terms of service, or DPA. As a result, the core AI-governance questions a professional user cares about (input/output ownership, training data usage, human review of prompts, third-party sharing, opt-out) are essentially unaddressed in the supplied text. The security posture that IS documented is strong and mature (SOC 2, ISO 27001, ISO 27018, CSA STAR, FedRAMP, GDPR alignment, encryption at rest/in transit, bug bounty, defined retention windows), which pulls the rating up. However, neither supplied document mentions Atlassian Intelligence, Rovo, AI/ML processing, or model training at all, so most data-governance categories must be rated on silence and cannot be verified against the AI product being assessed. Review the actual Privacy Policy and DPA (referenced but not supplied) before entrusting sensitive or proprietary data to the AI features.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Neither supplied document addresses ownership of user-submitted prompts, files, or content in the AI product. The Third-Party Code Policy concerns licensing of software components, not customer data, and the Security page treats customer content as something customers 'store' and 'retain control over' but does not assert an ownership position. This silence is a gap.
Output Data Ownership
The supplied documents are entirely silent on ownership of AI-generated outputs. There is no license grant, assignment, or disclaimer relating to generated content in either the Third-Party Code Policy or the Security Practices page. This cannot be assessed without the Customer Agreement or Product-Specific Terms.
Training Data Usage
Neither document states whether customer inputs are used to train or improve AI models. Given that the product surface markets an AI-native, agent-driven platform (Rovo, Rovo Dev), the absence of any training-use statement in the supplied policy text is a material gap. No no-training commitment is present.
Data Retention & Deletion
The Security Practices page gives concrete retention and deletion figures: sites are deactivated 15 days after subscription end, with data retained for 15 days (evaluation) or 60 days (paid) thereafter, and log retention is 30 days hot / 365 days cold. Deletion mechanisms and self-service export/import tools are referenced, and backup retention (RDS snapshots for 30 days) is specified. This is unusually explicit.
Third-Party Data Sharing
The Security page references sub-processors and a Marketplace ecosystem of third-party apps, and notes that public-access settings mean 'Atlassian has no control over' redistributed data. However, the supplied documents do not describe what customer data is shared with which third parties or under what terms — that detail would live in the Privacy Policy and sub-processor list, which were not supplied. No selling of data is disclosed.
Opt-Out Rights
The supplied documents mention data subject rights (deletion, access) and a consent control checker for support access to data, but do not describe any opt-out mechanism for AI/model training use or third-party sharing. There is a customer-controlled consent gate for support-engineer access, which is a positive control, but broader opt-out rights are not addressed in the supplied text.
Compliance & Certifications
Atlassian explicitly claims and points to evidence for multiple relevant frameworks: ISO 27001 (with certificate link), ISO 27018, SOC 2 (with report link), CSA STAR (registry entry), GDPR alignment, FedRAMP (Government Cloud), and SOX audits. For an enterprise_saas / developer_infra tool this is a strong compliance posture backed by named attestations. Notably, no AI-specific framework (ISO 42001, EU AI Act, NIST AI) is mentioned despite the product being AI-native.
Model Explainability & Auditability
The supplied documents do not address AI model explainability, transparency into model behavior, or enterprise auditing of AI features. Extensive audit logging is described for security/incident purposes, but nothing about model decision transparency. This is a gap for an AI product.
Security Practices & Breach History
The Security Practices page is thorough: AES-256 encryption at rest, TLS 1.2+ with Perfect Forward Secrecy in transit, Zero Trust access, role-based access control with 2FA/FIDO2, an industry-recognized bug bounty (Bugcrowd), internal red team, penetration testing, SIEM logging, and a defined incident response and breach-notification process. A dedicated Trust Center is referenced. No specific breaches are disclosed, but the control set disclosed is comprehensive.
Enterprise vs. Consumer Risk Delta
The Security page notes a data-retention difference between evaluation (15 days) and paid subscription (60 days) sites, and points to Atlassian Guard for enhanced enterprise administration. Beyond retention windows, the supplied documents do not detail material data-handling differences between free and paid tiers, particularly with respect to AI features.
Human Review of User Inputs
The Security page describes tight controls on staff access to customer data, restricting it to authorized personnel, requiring 2FA, and — importantly — requiring explicit customer consent via a 'consent control checker' before support engineers can access customer data. Unauthorized access is treated as a security incident. This addresses human access to stored data, though it does not specifically address human review of AI prompts/outputs.
Regulatory & Litigation Exposure
Atlassian publishes an annual Transparency Report on government data requests and content/account actions, and states it responds to government requests in accordance with published Guidelines for Law Enforcement. This transparency posture is favorable, though the underlying guidelines documents were not supplied for review.
PII & SPI Data Inventory
The supplied documents acknowledge that Atlassian processes personal data (referencing PII protection under ISO 27018 and data subject deletion rights) but do not enumerate the specific categories of PII or SPI collected or processed — that inventory belongs in the Privacy Policy, which was not supplied. The Security page shows strong controls around whatever personal data exists, but the lack of an itemized data inventory in the supplied text limits assessment.
Policy–Product Currency
The Third-Party Code Policy carries an effective date of November 22, 2024 (about 20 months before the analysis date), and the Security page references recent artifacts (bug bounty reports dated 2025-12), suggesting active maintenance. However, the product surface markets a heavily AI-native platform (Rovo, agents, AI orchestration), and neither supplied document mentions AI/ML processing, model training, or third-party model providers. The Security page lists Rovo only in encryption/scope contexts. Coverage of the AI capabilities being shipped is therefore partial at best, capping this at YELLOW.
Cross-Document Consistency
Two documents were supplied — a Third-Party Code Policy and a Security Practices page — covering largely different subject matter (software licensing versus security controls). No contradictions were found between them; they do not make conflicting claims on retention, licensing, opt-out, training, or jurisdiction. Note, however, that neither is a privacy policy or DPA, so the most consequential cross-document consistency check (Terms vs Privacy vs DPA) could not be performed.
You've read all 15 risk ratings for Atlassian Intelligence. Create a free account to see the exact policy wording behind each rating.