Hi, according to https://www.atlassian.com/trust/ai/transparency, prompts are not stored or used for training by 3rd. party LLM providers. But according to https://www.atlassian.com/legal/sub-processors#atlassian-group-sub-processors, data that may not count as prompt data is sent to those providers.
Is there some clear documentation that describes what data is and is not sent to 3rd. party LLM providers, or a human contact we can ask about the same?
(https://support.atlassian.com are not willing to answer me about this)
I’m also interested in this topic.
We haven’t enabled Rovo yet because our internal policies require that not only data residency, but also data transit and processing remain within specific regions. At the moment it’s not clear to us whether any data is sent to third‑party AI providers (for example ChatGPT) in other countries, or processed outside the data residency location.
Public, detailed documentation about what data is (and is not) shared with third parties, where it is processed, and under which conditions would be very helpful for our assessment.
Have not enabled Rovo for this same reason. Would be great to have some concrete information that covers this.
Hi @andre / @Alexander Ruetzler / @Luke Towers,
Am watching this closely, especially as the tie-ups with foundation model providers grow. In the case of OpenAI models, they do provide a little more detail in their Help Center pages here. Here there is some choice about CPU / GPU processing locations over which you perhaps cannot yet get control through Rovo (?).As for planning / costing an effective production deployment (at enterprise scale), there's still some unanswered questions.Agreed a little more forward guidance would help here.Justin
Hi,
excellent topic, we've had the same question.
Apparently Atlassian Intelligence sends data to OpenAI in USA to generate the answers, but otherwise the data residency is where you set it to be. Many of our customers do not approve even this bit of data leaving EU, so no Atlassian Intelligence until data doesn't leave EU at all.
Your prompts (inputs) and responses (outputs):
Are not sent to any third party LLM provider other than OpenAI or Google.
Not sure about othe 3rd parties, but Atlassian Support has assured me Atlassian Intelligence is safe.
BR,
Antti
Hi @Justin Townsend Rovo’s data residency only guarantees where certain data is stored at rest (for example, chat logs, configs, bookmarks, indexed content) in your chosen region, as described on the Atlassian AI / Rovo Trust Page and the Rovo data residency announcement it references.When Rovo uses third‑party LLMs like OpenAI, Atlassian explicitly states on the same trust page that data is sent outside your current site/region for AI processing.OpenAI offers EU data and inference residency for ChatGPT Enterprise/Edu, as documented in the OpenAI data residency and inference residency article, but Atlassian does not state in its Rovo documentation that Rovo uses OpenAI’s EU inference residency.You can avoid sending data to third‑party LLMs only by restricting Rovo to Atlassian‑hosted models, as noted on the Atlassian AI / Rovo Trust Page, which keeps inference within the Atlassian cloud boundary but without a specific guaranteed GPU region.TL;DR
Best Alex
The other issue is that even if Atlassian Intelligence is "safe" we cannot enable it without also enabling Rovo.
Hi @Alexander Ruetzler,
At the risk of this turning into a "back and forth", duly aware of these documents. Thank you though for pointing them out here :-).
It begs the question for other readers of this thread, that certain kinds of clients may wish to hold off for processing guarantees where residency / region is of primary concern.
...but without a specific guaranteed GPU region. Datacentre feature build out to support guarantees may be a constraining factor for deployment. In other words, beyond the practicality of deploying Rovo internally, your (AI) programme may need to factor in this constraint.
Apologies, if I hadn't made this more obvious in my initial note.
Thanks,
Justin
@Luke Towers To my knowledge, Rovo is forced to be active these days, but Atlassian Intelligence is still optional. Without AI the Rovo is kind of useless, though.
Hi Andre,The discrepancy between these two links you mentioned is that the sub‑processors page describes, at a broad, product‑agnostic level, the categories of data a vendor may process across Atlassian products, while the AI Transparency page is specific to Rovo/Atlassian AI and accurately describes what prompt and context data is actually sent to third‑party LLMs. However, for Rovo, under Atlassian’s zero‑data‑retention and enterprise agreements with our LLM partners, that prompt/context data is only used to fulfill the request and is not stored by the providers, and is never used to train their models. Please see below, I've broken it down hopefully in a more digestible format!
What Is Sent to Third-Party LLM Providers (e.g., OpenAI, Google, Anthropic)
What Is NOT Sent or Used
I hope this helps! - Christine (Sr. Atlassian SE)
@Luke Towers @Antti Salo, please see @Christine's breakdown below, 'hope that helps clarify some of your questions! 💙
It looks like you're new here. Sign in or register to get started.