Hi,
Our initial questions for before we can consider your cloud option are as follows:
About access:
- Is it possible to enforce IP restriction for your cloud option?
- or, is it possible to enforce geo restriction for your cloud option?
About storage:
- How do you store attachments? if on disk, how do you protect them from access of Atlassian employees? Moreover, how do you make sure AWS employees does not have access to data?
- How do you make sure that no Atlassian employee can access to attachments or data any given time?
About Encryption:
- How do you protect encryption keys?
- How does your application consumes encryption keys?
- What happens if a key or key container is compromised?
- Does any Atlassian employee has access to customer keys?
- What happens if a key or key container is lost (by you or by customer)? how do you backup them, and how do you protect the backup? Who has access to backup? what is your procedure to restore the backup?
- What is the mode of AES-256 disk encryption?
About sensitive data:
- What is the main reason why customers cannot put sensitive data on your cloud option?
- for bitbucket: how do you make sure the source code of a application is accessible only by your customer?
Data classification:
- how do you enforce data classification?
About data residence:
- How do you make sure the of the customer data stays always in the required geo location?
- What is the recovery plan if the pinned DC is not accessible or has a disaster situation?
Once we have answer for our initial questions, we might ask further questions.
Kind Regards