We are Jira and Confluence cloud users and are evaluating migrating from an on-premise Git hosting solution to BitBucket cloud. Atlassian's Security practices page states "Bitbucket does not offer encryption at rest for repositories at this time." Competing platforms github.com and gitlab.com have both added encryption at rest to their platforms within the past two years.
We could be fine with no encryption at rest provided there are compensating controls to assure the confidentiality and integrity of our data. Can anyone provide specific information about compensating controls that Atlassian follows to ensure that:
- our repositories are not accessible to other tenants on the platform
- our repositories are not accessible to Atlassian staff other than those authorized to access it for support and operational purposes
- backups of the unencrypted repositories are managed to prevent disclosure
Thanks for your help with our evaluation.