We've published the second in our Trust one‑pager series — a concise, exec-ready overview of how Atlassian finds, prioritises, and fixes security vulnerabilities across 29,000+ repositories and every layer of our cloud infrastructure.
If you missed the first one, check out our New "Data Residency at Atlassian" one‑pager for your Security and Compliance.
What it covers:
Multi-layer scanning (SAST, SCA, DAST, cloud posture, bug bounty)
Our 4-step process: Detect → Assess → Remediate → Verify
Published SLA tiers (Critical: 10 days → Low: 175 days)
Independent validation (SOC 2 Type II, ISO 27001, third-party pen tests)
How to report a vulnerability
When it's useful:
Security/compliance reviews and vendor assessments
CISO or board pre-reads
Procurement & due-diligence packs
Customer calls where vuln management is a top concern
Feedback welcome — what should wave 3 cover?
— Jo, Trust Engagement
Joanna Milewska
4 comments