I am trying to get answers to the following security questions for JIRA Cloud / OnDemand
- How will our service be segregated from other customers?
- Is our data encrypted at rest? I know it is in transit.
- Does Atlassian scan your internet application(s), if so how frequently?
- Does Atlassian perform attack and penetration security testing on their perimeter, if so how frequently?
- Is attack and penetration testing incorporated into the release schedule when new application changes are released? (we are looking to understand what formal process an internet application goes through when changes are introduced and if vulnerabilities are found are they remediated before the website is allowed to launch the new changes to the internet.)
I can't seem to get anyone from Atlassian to answer these. I know some of this is on the website, but not all.