1,639 words, 63 clausesno date on the pageread 11/10/2026source
·Ascend to new heights with Atlassian Cloud. Data Center support ends on March 28, 2029. Together, we'll make this transition a success. Learn more and get support ->
·Welcome to our Security Testing hub, dedicated to providing you with comprehensive information on the security testing initiatives implemented by Atlassian to ensure the safety and protection of our products and valued customers.
·Looking for something specific? Fast-track your search using one of the links below, or continue reading to delve deeper into Atlassian's external Security Testing program.
·Atlassian takes a multifaceted approach towards external security assurance of our products. We have an always-on, always-testing model leveraging a crowd-sourced bug bounty, which is complimented by regular white box penetration testing performed by external security consultancies and our internal Security Testing team.
·Atlassian is well known for our values, which genuinely influence everything we do - including our approach to security testing. In practice, our values have led us to the following philosophies and approaches:
·We use specialist security services companies to complete penetration tests of our products and other systems. In addition to this, we have an internal Security Testing team who works in collaboration with third-party consultants to provide technical security assurance of high-priority projects - for example, a new product feature (e.g. Confluence Whiteboards), new infrastructure setup (e.g. our FedRAMP environment), or re-architecture (e.g. new Forge runtime).
·Our approach to penetration testing in these cases is targeted and focused. Such tests will be:
·We leverage authorized Artificial Intelligence (AI) models to support our internal team in performing deep code auditing and security research activities during testing engagements.
·We post Letters of Attestation (LoAs) from our Penetration Testing partners available for external consumption at the bottom of this page. Due to the extensive internal information made available to the testers in conducting these assessments, we don't provide full reports. The majority of these systems and products will be included in our public bug bounty program, providing ongoing external assurance. Any findings from these assessments will be triaged and remediated according to our Public Security Vulnerability SLO.
·Our bug bounty program is hosted by Bugcrowd. This program ensures that our products are constantly tested for security vulnerabilities.
·We believe the crowd of independent security researchers participating in our bug bounty contribute to an effective external security testing process because:
·More than 30 of our products or environments - across our Artificial Intelligence products, Cloud products, Data Center products, and mobile apps - are in-scope for our bug bounty program. Details of the number of vulnerabilities reported, our average response time, and our average payout are all included on the Bugcrowd site, with more than 3,700 researchers having participated our program.
·Vulnerabilities we seek to be identified through our bug bounty program include common types captured in the Open Web Application Security Project (OWASP) and Web Application Security Consortium (WASC) threat lists.
·As part of our initiative to be open and transparent, we invite anyone to visit our bug bounty program page, sign up for the program, and test us.
·First-party Atlassian-built apps are covered by the Atlassian Built Apps Bug Bounty Program.
·Third-party apps published on the Atlassian Marketplace are covered under our shared responsibility model, with the underlying security of the apps being the responsibility of the third-party developer. Marketplace partners can also opt-in to our managed penetration testing program for additional assurance.
·We allow customer-initiated testing in line with our Terms of Use for our cloud products. We are committed to being open and will continue to publish statistics from our bug bounty program regularly, as well as LoAs.
·While we believe our approach provides comprehensive assurance of our products and services, we understand that you might want to test the security on your own. We allow for security assessments (penetration tests or vulnerability assessments) to be performed by customers, and we ask that you follow a few rules to keep all of us safe.
·If you find an issue you would like to report to Atlassian, please refer to our instructions on reporting a vulnerability.
·At Atlassian, one of our values is Open Company, No Bullshit, and we believe that vulnerability disclosure is a part of that value. We aim to fix security vulnerabilities within the relevant service level objectives (SLOs). We accept disclosure requests through our bug bounty programs after an issue has been resolved and released in production. However, the request will be rejected if the report contains any customer data. If you plan to disclose outside of our bug bounty programs, we ask that you give us reasonable notice and wait until the associated SLO has passed.
·Just as we are open and clear about the testing we do, we are also open and clear about the testing we don't do ourselves or don't currently support. Certain low-risk vulnerability types, such as enumeration and information gathering, are generally not considered significant risks.
·Our security bug fix policy specifies Service Level Objective (SLO) timeframes for remediating vulnerabilities based on severity and product. When assessing vulnerabilities, we use the Common Vulnerability Scoring System, which helps communicate the severity of vulnerabilities to our customers.
·Atlassian's crowd-sourced bug bounty program, external security consultancies, and our internal Security Testing team form a comprehensive, mature, and transparent model. This ensures our products and platforms are constantly being tested and secured, providing continuous assurance to customers.
·We've referred to quite a few other documents and resources in this brief paper, and we encourage you to dig into them to understand more about our approach to security testing. Atlassian Trust Center Atlassian Security Practices Atlassian's CSA STAR Atlassian's Bug-fix Policy
·Any security vulnerabilities identified in the reports below are tracked in our internal Jira as they come through the Bug Bounty intake process. Any findings from the Bug Bounty will be triaged and remediated according to our Public Security Vulnerability SLO.
·Any security vulnerabilities identified in the reports below are tracked in our internal Jira as they come through the penetration test report process. Any findings from these assessments will be triaged and remediated according to our Public Security Vulnerability SLO.
·All Letters of Attestation per product can be downloaded via the Documents folder within Atlassian's Customer Trust Portal.