Yes
Atlassian uses TLS 1.2 and perfect forward secrecy to protect external data.
Yes
Atlassian meets the recommended cryptographic profiles for TLS as published by the NCSC. In addition, the Atlassian Jira domain currently gets an ‘A’ rating from Qualys SSL Labs. Note that this was performed on their top level domain, and not all subdomains that may be used for API calls.
Yes
In Atlassian’s Consensus Assessment Initiative Questionnaire (CAIQ), they state that the Atlassian Cloud Platform uses SSH for data and images transported between networks.
Unknown
At this time, it is unknown whether Atlassian protects external data in transit using correctly configured certificates.
Yes
Jira offers basic authentication, OAauth and JWTs to protect its external REST API.
Yes
Yes
Does the SaaS provider collect logs of events?
Types of log may include security logs and resource logs
Yes
Unknown
Does the SaaS provider have a clear incident response and patching system in place to remedy any publicly reported issues in their service, or libraries that the service makes use of?
The provider’s previous track record on this is a good metric to see how they’ll cope with a new issue occurring.
Yes
Source: NCSC