Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Atlassian Commercial Cloud vs. AGC vs. Isolated Cloud: Comparison

[WWW] ITSM - blog (1).jpg

 

Atlassian gives you three ways to run Jira, Confluence, Atlassian Guard, and Jira Service Management in the cloud, and they are not interchangeable. Atlassian Commercial Cloud is the default: multi-tenant, fast-moving, first in line for new features. Atlassian Government Cloud (AGC) is the FedRAMP Moderate option built for US public-sector customers. Atlassian Isolated Cloud (AIC) is the dedicated Virtual Private Cloud (VPC) option for enterprises that cannot share infrastructure with anyone, full stop. 

Which one you need comes down to your industry, your data residency obligations, and how much network isolation your auditors will actually sign off on.

Moving mission-critical workloads from Atlassian Data Center to cloud infrastructure forces teams to weigh network isolation, identity boundaries, data residency, and outbound traffic (egress). In regulated or IP-sensitive industries, like banking, cybersecurity, healthcare, critical infrastructure, and automotive R&D, compliance mandates leave zero room for security compromises, even when business leaders demand faster delivery.

Key Takeaways 

  • Deployment Models: Atlassian offers Commercial Cloud (multi-tenant), Government Cloud (FedRAMP Moderate), and Isolated Cloud (single-customer dedicated VPC), which reached General Availability on June 29, 2026. 
  • Data Plane and Egress Control: Isolated Cloud isolates customer data and blocks outbound network traffic by default. Approved outbound requests route through an Isolated Context Gateway proxy that redacts PII. 
  • Target Audience: Isolated Cloud targets enterprise Data Center accounts (15,000 to 50,000+ seats) facing strict zerosharing or compliance restrictions. 
  • App Ecosystem Requirements: Legacy Connect apps, including Connect-on-Forge hybrid applications, fail in Isolated Cloud due to network blocks. Applications must be built on Atlassian Forge to comply with Isolated Cloud architecture.
  • Government Cloud Capability: Third-party app availability on AGC is restricted by federal reviews. Only a fraction (currently 162) of the 4,000+ apps on the commercial Marketplace have been rebuilt and approved for AGC so far.

Appsvio supports AGC deployments through apps like Issue Templates Agent, while expanding its portfolio with solutions like Custom Fields Suite: currently the only app on the Marketplace providing multilevel select custom fields for AGC tenants.

Atlassian Cloud Deployment Models Compared: Commercial vs. Government vs. Isolated Cloud

Choosing the right deployment comes down to how each environment handles compute, storage, identity, and AI boundaries, plus how much of that you're willing to hand over to Atlassian versus keep walled off.

Isolation increases predictably across the three tiers. Commercial Cloud sits at the entry level with multi-tenant logical separation, shared AWS clusters, and open egress. Atlassian Government Cloud (AGC) adds a middle layer, running on dedicated AWS GovCloud (US) hardware restricted to US government entities under FedRAMP Moderate controls.

At the top end, Atlassian Isolated Cloud (AIC) switches to a single-customer model using dedicated VPCs, AWS Nitro hardware isolation, separate identity directories, and default egress blocking.

Atlassian Cloud (1).png

Atlassian Commercial Cloud

Commercial Cloud is Atlassian's standard, multi-tenant SaaS offering, the default deployment for most organizations. It runs on Amazon Web Services (AWS), with data isolation handled logically at the application and database tiers using tenant IDs and access control lists.

  • Feature Availability: Receives continuous updates and instant access to new platform capabilities, including Atlassian Rovo AI and new Marketplace offerings. 
  • Data Residency: In-scope primary data (Jira issues, Confluence pages, attachments) can be pinned to specific geographic regions, such as the EU, US, Germany, Australia, and Japan (currently it’s 12 locations). 
  • Forge Platform Integration: Forge apps inherit Data Residency controls directly from the underlying Atlassian platform, so app vendors don't need to build separate multi-region storage pipelines.

Atlassian Government Cloud (AGC)

AGC runs under a FedRAMP Moderate authorization: a dedicated multi-tenant environment hosted in AWS GovCloud (US) regions, entirely siloed from commercial workloads. It serves US federal, state, and local agencies, as well as defense contractors storing Controlled Unclassified Information (CUI).

  • Compliance Scope: Operates under a FedRAMP Moderate authorization and aligns with ITAR and FISMA mandates. 
  • Personnel Security: Administrative access and infrastructure maintenance are strictly limited to screened US citizens on US soil (US Persons). This covers federal, state, and local agencies plus defense contractors handling CUI. 
  • Release Cadence: Independent security reviews delay feature rollouts, system updates, and third-party marketplace app availability compared to Commercial Cloud.

Atlassian Isolated Cloud (AIC)

Atlassian Isolated Cloud reached General Availability at the end of June 2026. It is built for global enterprises that need physical isolation to satisfy zero-sharing policies, protect core IP, or meet tough regulatory rules.

  • Single-Customer Architecture: AIC uses a single-customer boundary. A single enterprise can spin up multiple internal tenants (such as distinct business units or regional subsidiaries) within its assigned isolated environment. 
  • Data Plane Isolation: Provisions dedicated compute, storage, virtual networks, app containers, domain endpoints, and firewalls inside an isolated AWS VPC. Everything handling User Generated Content (UGC), PII, or credentials runs strictly inside this boundary. 
  • Shared Control Plane: To keep SaaS maintenance manageable, Atlassian runs a shared control plane across AIC deployments. This layer manages platform orchestration, billing, internal usage metrics, software upgrades, and support diagnostics without reading or exposing customer data. 
  • Hardware Isolation: Runs on dedicated Amazon Aurora database instances and compute environments powered by the AWS Nitro System. This hardware-level separation ensures CPU, memory, and persistent storage are never shared with other organizations. 
  • Directory Isolation: Operates as a distinct identity realm. User accounts, SCIM provisioning, and SAML SSO connections do not sync with an enterprise's commercial Atlassian Organization. This isolates identity management and prevents credential leaks across environments. 
  • Security Controls and Bundling: Bundles all Atlassian Cloud Enterprise tier features, Atlassian Guard Premium (centralized threat detection and automated response), and Customer Managed Keys (CMK). 
  • Feature Rollout: Atlassian Analytics and Rovo AI weren't part of the GA launch; Atlassian has said both are coming to Isolated Cloud in phases over the following quarters, so check current product availability before committing to a migration timeline.

Target Profile and Migration Scope

Running dedicated infrastructure raises operating costs, making AIC a specialized tier focused on large-scale Enterprise Data Center migrations. 

  • Target Deployment Scale: Enterprise accounts with 15,000 to 50,000+ seats. 
  • Primary Industries: Financial services (banking, insurance, fintech), technology (cybersecurity, networking, IP-sensitive software development), healthcare, and critical national infrastructure. 
  • Supported Core Products: Supports Jira, Confluence, and Jira Service Management at General Availability (GA). 
  • Migration Pathways: GA supports direct Data Center to Isolated Cloud migrations for Jira Data Center, Confluence DC, and JSM DC.

Technical Specifications Breakdown

The table below summarizes how the three deployment models differ across infrastructure, network controls, and governance. These are the core criteria enterprise architects evaluate first.

Criteria Commercial Cloud Atlassian Government Cloud (AGC) Atlassian Isolated Cloud (AIC)
Infrastructure & Isolation Multi-tenant AWS infrastructure using shared compute clusters and logical database separation. Multi-tenant AWS GovCloud (US) environment, physically separated from commercial AWS regions. Dedicated single-customer AWS VPC using Amazon Aurora database instances and AWS Nitro System hypervisors. Isolated data plane with a shared management control plane.
Network Traffic & Egress Unrestricted outbound network access by default for direct webhooks and external SaaS tools. Restricted and monitored network egress aligned with FedRAMP Moderate controls. Outbound traffic blocked by default. Permitted calls route through the Isolated Context Gateway (ICG), which scans payloads and redacts PII automatically.
Governance, Auditing & Compliance SOC 2 (Type II), ISO/IEC 27001, ISO/IEC 27018, and HIPAA compliance (via BAAs). FedRAMP Moderate certified. Complies with ITAR, EAR, and DoD Impact Level 2 standards. Built for strict internal zero-sharing policies, complex banking audits (DORA in the EU, KNF guidelines), and automotive IP protection rules (TISAX).
Relative Cost* $ $$ $$$

* Atlassian doesn't publish list pricing for AGC or Isolated Cloud; both are custom-quoted. This ranking reflects relative infrastructure cost (Atlassian itself positions Commercial Cloud as its "lowest cost, highest scale" tier), not confirmed dollar figures.

Which Atlassian Cloud Model Should You Choose?

Use this as a gut-check before you bring in the architects for a formal review:

If your organization… Recommended model
Runs standard commercial workloads, wants continuous feature releases, no US-federal or zero-sharing mandate Commercial Cloud
Is a US federal, state, or local agency, or a defense contractor handling CUI Atlassian Government Cloud (AGC)
Is a large enterprise (15,000+ seats) under zero-sharing policy, DORA, TISAX, or similarly strict data-isolation rules, migrating from Data Center Atlassian Isolated Cloud (AIC)

* Directional starting point only - actual fit depends on exact seat count, specific regulatory obligations, and your current Data Center footprint. Confirm with Atlassian or Appsvio before finalizing an architecture decision.

Third-Party App Architecture: Atlassian Connect vs. "Runs on Atlassian" Forge

Adding third-party apps to Jira or Jira Service Management requires checking how an app's architecture interacts with tenant network controls, a question sharpened by the Atlassian Connect sunset (full end-of-support by Q4 2026).

Legacy Atlassian Connect apps rely on an open-boundary setup where REST API requests exit the Atlassian cloud tenant to hit vendor-hosted servers. In Atlassian Isolated Cloud, default egress blocking stops Connect apps from resolving external domains, breaking compatibility.

The "Runs on Atlassian" Specification for Forge

The Atlassian Forge platform runs app code directly inside Atlassian's managed AWS environment.

  • Native Platform Execution: Built entirely on Forge; Connect apps are excluded. 
  • No Remote Compute or Storage: Apps cannot use Forge remotes to run compute off-platform or store data in vendor-managed databases. 
  • Data Residency Alignment: Uses native Forge storage that adheres to Atlassian Data Residency region rules. 
  • Restricted Telemetry Egress: Outbound connections are limited strictly to basic operational logs and analytics. Admins retain full control to turn off this telemetry egress.

Appsvio Native Architecture for Regulated Deployments

At Appsvio, we build Atlassian Marketplace apps specifically for Jira-native and Forge execution models, allowing enterprises to extend workflows without creating egress risks.

  • Appsvio Test Management (ATM) for Jira: Handles test case creation, cycle execution, and Requirements Traceability Matrices (RTM) inside Jira. Built on Forge using a Zero-Egress design, ATM keeps all test steps, execution logs, and bug associations entirely inside the customer's tenant boundary. 
  • Issue Templates Agent (ITA) for Jira: Automates complex issue trees and standard operational tasks. Using granular field permissions and predefined templates, ITA enforces process consistency across auditing, compliance, and onboarding pipelines. ITA is also approved for Atlassian Government Cloud. 
  • Feature Bundle for JSM (FBC): Extends Jira Service Management customer portal features, with security verification and availability for Atlassian Government Cloud planned for late 2026.
  • Custom Fields Suite (CFS) for Jira: Expands custom field management capabilities across Jira and Jira Service Management. Custom Fields Suite has completed security verification for Atlassian Government Cloud (AGC) and remains the only app on the Atlassian Marketplace offering multilevel select custom fields for AGC tenants.

Migration and Next Steps

Deciding on an Atlassian cloud model comes down to matching regulatory duties, risk thresholds, and day-to-day workflow needs. Data Center transition timeline: new Data Center licenses stop selling on March 30, 2026. Existing customers can still renew after that, but lose the ability to expand user tiers or add Marketplace apps on March 30, 2028. Full Data Center end-of-life lands on March 28, 2029, when licenses switch to read-only.

Planning your move to AGC or Isolated Cloud?

Browse Appsvio's full portfolio of Forge-native, Government Cloud-ready apps built for regulated Jira environments.

Go to Atlassian Marketplace

For licensing details, formal Data Center-to-Isolated Cloud migration pathways, or AGC onboarding, reach Atlassian directly through the Atlassian Migration Options Form.

0 comments

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events