Hi All,
Our team is looking to leverage Compass in our organization but there are a few concerns from our InfoSec team.
1. Compass is a beta product and typically beta products are not fully supported. Moreover, having that connected to prod systems raises concerns for them. There is a concern there and a question around when it will go into GA (I know no date as of yet has been mentioned).
2. More importantly, they want clarification on what data is actually stored in Compass. Their primary concern is around development code and similar data being stored in Compass. My understanding is that Compass merely connects to the repos and does not store any code itself, however they do want a clarification from Atlassian.
Let me know if this is the right spot to ask these questions!
Thanks!
Can someone from Atlassian answer this?
Hey Robert, Compass doesn't store your source code. We process webhooks from Bitbucket, GitHub, GitLab and store the related events and metrics detailed here in our docs https://developer.atlassian.com/cloud/compass/integrations/integrate-Compass-with-GitHub/. If you use the config as code feature, we look for a `compass.yaml` file in the repository. And of course, we'll store the link to the repository itself. But no source code!
Look for official announcement on general availability very soon :)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.