In partnership with Vanta, Atlassian conducted an analysis to determine how we can make it easier for developers to meet SOC 2 requirements. Our Forge platform is SOC 2 certified, and apps built on the Forge developer platform can benefit from inheriting controls to meet 30% of SOC 2 requirements. These controls can help you achieve compliance across the following domains:
SOC 2 control inheritance only applies to data that resides within the Forge boundary.
It is important to note that you should consider the Forge platform as a defined boundary. While data resides within this boundary, it inherits the controls specified above. However, once any data exits this boundary, the inheritance of those controls ceases for that data, and you become responsible for establishing your own controls for the data that has left the boundary.
An example
If you build an app that uses Forge's runtime, hosted storage and has no data egress, you can rely on the SOC 2 control inheritance outlined above.
Let’s say you now update your app to make a call to a third-party API. The SOC 2 control inheritance ends for any data that leaves the Forge platform boundary and is sent to the third-party API. You now become responsible for implementing SOC 2 controls for the data that has left the boundary.
The control domains above are only a subset of the requirements for SOC 2 compliance. Many of the other requirements are based on operations and process needs that are outside the scope of the Forge platform.
Additionally, some control domains include shared responsibilities—for example, while Forge manages the data stored on behalf of your Forge applications, Marketplace Partners are responsible for backing up the code they deploy for the Forge application itself.
Please review the Shared responsibility model for a full list of detailed responsibilities that Marketplace Partners and Atlassian share when using the Forge platform.
Read more about SOC 2 compliance: SOC 2® - SOC for Service Organizations: Trust Services Criteria
Rate this page: