We've published the second in our Trust one‑pager series — a concise, exec-ready overview of how Atlassian finds, prioritises, and fixes security vulnerabilities across 29,000+ repositories and every layer of our cloud infrastructure.
If you missed the first one, check out our New "Data Residency at Atlassian" one‑pager for your Security and Compliance.
What it covers:
-
Multi-layer scanning (SAST, SCA, DAST, cloud posture, bug bounty)
-
Our 4-step process: Detect → Assess → Remediate → Verify
-
Published SLA tiers (Critical: 10 days → Low: 175 days)
-
Independent validation (SOC 2 Type II, ISO 27001, third-party pen tests)
-
How to report a vulnerability
When it's useful:
-
Security/compliance reviews and vendor assessments
-
CISO or board pre-reads
-
Procurement & due-diligence packs
-
Customer calls where vuln management is a top concern
📄 Download the One-Pager
Feedback welcome — what should wave 3 cover?
— Jo, Trust Engagement