Compliance Resource Center
Search Atlassian’s industry leading security, third party audits and certifications, documentations, and legal commitments help support your compliance.

ACSC - Cloud Computing Security
This document is designed to assist assessors validating the security posture of a cloud service in order to provide organisations with independent assurance of security claims made by Cloud Service Providers (CSPs).
Learn more
ACSC - Essential 8 Maturity Model
The Australian Cyber Security Centre (ACSC) has developed prioritised mitigation strategies, in the form of the Strategies to Mitigate Cyber Security Incidents, to help organisations mitigate cyber security incidents caused by various cyber threats.
Learn more
APRA 234
Atlassian abides by the APRA Prudential Standard CPS 234 Information Security ("Prudential Standard CPS 234")
Learn more
Australia Privacy Act
The Australia Privacy Act to protect the privacy of individuals and to govern how certain federal Australian Governmental agencies and organizations...
Learn more
BaFin
BaFin, also known as the Federal Financial Supervisory Authority, is an autonomous public-law institution formed to ensure the proper functioning, stability, and integrity of the German financial system.
Learn more
California Consumer Privacy Act
Atlassian is committed to abiding by the California Consumer Privacy Act (CCPA) to ensure California consumers with a number of privacy protections
Learn more
Cloud Security Alliance
The Cloud Security Alliance (CSA) is a non-profit organization whose mission is to "promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing."
Learn more
EBA
The European Banking Authority (EBA) is an independent EU authority tasked with implementing a standard set of rules to regulate and supervise banking across all EU countries.
Learn more
ENISA
The European Union Agency for Cybersecurity (ENISA) is an EU organization dedicated to promoting a high level of cybersecurity standards across Europe.
Learn more
FINMA
The Swiss Financial Market Supervisory Authority (FINMA) oversees a number of financial institutions including banks, insurance companies, superannuation.
Learn more
Good Clinical, Laboratory, and Manufacturing Practices - GxP
This report is intended solely to provide information and guidance to Atlassian’s cloud customers on how we align with GxP.
Learn more
HECVAT
The higher education information security community, EDUCAUSE, Internet2, and the Research & Education Networks Information Sharing & Analysis Center (REN-ISAC) created the Higher Education Cloud Vendor Assessment Toolkit (HECVAT), a self-assessment that attempts to standardize higher education information security and data protection requirements in the Unites States around cloud service providers.
Learn more
HIPAA
Atlassian has implemented the physical, technical, and administrative safeguards required by HIPAA to support our role as a business associate.
Learn more
HKMA
The Hong Kong Monetary Authority (HKMA) functions as the central bank of Hong Kong and has the role of overseeing authorized institutions (AIs).
Learn more
ISO/IEC 27001:2013
The International Organization for Standardization (ISO) is an independent, non-governmental international organization with an international membership of 163 national standards bodies.
Learn more
Lei Geral de Proteção de Dados (LGPD)
Lei Geral de Proteção de Dados (LGPD) regulates the collection, use, processing, storage, and transfer of personal data of Brazil data subjects
Learn more
MAS
The Monetary Authority of Singapore (MAS), serves as the bank regulator and central bank in Singapore, has issued Guidelines on Outsourcing Risk Management
Learn more
NCSC
The National Cyber Security Centre (NCSC) is a United Kingdom governmental organization…
Learn more
nFADP
The nFADP stands for the New Federal Act on Data Protection, which will come into effect on the 1st of September 2023.
Learn more
PCI-DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard administered by the PCI Security Standards Council.
Learn more
SOC 2
System and Organization Controls (SOC) 2 reports are independent third-party examination reports that demonstrate how an organization achieves key compliance controls and objectives.
Learn more
TISAX
The Trusted Information Security Assessment Exchange (TISAX) is managed and overseen by the German Association of the Automotive Industry (VDA).
Learn more
UKPRA
The Prudential Regulation Authority (PRA) has the critical role of overseeing the prudential supervision of approximately 1,500 financial institutions, which encompass banks, insurance companies, building societies, credit unions, and specific large investment firms.
Learn more
Web Content Accessibility Guidelines - WCAG
The Web Content Accessibility Guidelines (WCAG) are the internationally recognized set of requirements for making software, websites, and content accessible to people living with disabilities.
Learn more