Atlassian Cloud shifts responsibility for operating and patching the service to Atlassian; Data Center customers run their own deployments and must install product fixes and secure the underlying infrastructure. Neither option removes customer security work: organizations remain responsible for decisions such as user access, data handling, trusted Marketplace apps, and their own compliance obligations. The practical difference is who operates the platform—and who must act when it needs a patch.
Who is responsible for security in Atlassian Cloud?
Atlassian describes Cloud security as a shared-responsibility model. Atlassian operates and secures the applications, systems, and hosting environment. Customers manage the data within their accounts, the users and accounts that can access it, which Marketplace apps they install and trust, and their own compliance obligations. Atlassian’s Cloud shared-responsibility overview puts the customer’s role plainly: customers “manage the data within your accounts, the users and user accounts accessing your data, and control which Marketplace Apps (formerly called ‘add-ons’) you install and trust.”
Because Atlassian operates the service, customers generally do not install the Cloud application or hosting-system patches themselves. That reduces infrastructure patching work; it does not transfer customer account, access, data-handling, or app-trust decisions to Atlassian. The precise division of controls can vary by product, plan, contract, and configuration, so use the relevant product documentation for a specific compliance or deployment decision.
Who patches Atlassian Data Center?
Data Center runs on customer-managed systems. Atlassian supplies product releases and application-level security fixes, but the customer’s administrators must apply those fixes to their installation and operate the environment around it. Atlassian’s Data Center security checklist says it “doesn’t take responsibility for self-managed hardware infrastructure.” Atlassian still provides product-level security releases and guidance; operating the customer-managed deployment remains the customer’s job.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
That work includes keeping the operating system and dependencies secure, hardening systems, configuring access controls and other security settings, implementing encryption according to organizational policy, and maintaining backups. Customers also need to evaluate the apps and dependencies used in their environment and manage access to the product.
What Atlassian’s patch timelines mean
Atlassian’s Security Bug Fix Policy sets product remediation targets of 90 days for verified Critical, High, and Medium vulnerabilities, and 180 days for verified Low vulnerabilities. These are Atlassian’s targets for fixing vulnerabilities in its products. They are not a universal deadline for a customer to patch a Data Center installation, nor do they mean a fix has already been installed on each customer-managed instance.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
- There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
- Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
- Reorder SKU: LOG-100-M3CW-PP(Security-Report)
- Cloud: Atlassian operates the service and its product environment, so customers generally do not deploy application or hosting patches themselves.
- Data Center: Atlassian provides product fixes, while the customer must deploy them. Atlassian advises customers to upgrade promptly, but its checklist does not establish a universal number of days for each customer’s rollout.
For Data Center, the time between an Atlassian fix becoming available and its installation depends on the customer’s deployment and operating procedures. The 90- and 180-day policy targets should not be treated as a customer patching SLA.
Why Data Center support status matters to patch planning
Patching is not only a matter of applying an individual fix; it also means staying on a supported release. Atlassian says feature and Long Term Support (LTS) releases receive support for two years after their initial release. Releases that reach end of support no longer receive support. See Atlassian’s End of Support Policy and Data Center bug-fix and end-of-support policy for the current rules. Release dates differ, so check the relevant product lifecycle page before deciding whether a particular version is still supported; Atlassian recommends upgrading to the latest feature or LTS release.
Security responsibilities at a glance
| Responsibility | Atlassian Cloud | Atlassian Data Center |
|---|---|---|
| Hosting and underlying systems | Atlassian operates the hosting environment and systems. (Atlassian Cloud shared responsibility) | The customer operates the self-managed infrastructure and hardware. (Data Center security checklist) |
| Product security fixes | Atlassian operates the Cloud applications and platform. (Atlassian Cloud shared responsibility) | Atlassian supplies product releases and application-level fixes; the customer installs them. (Data Center security checklist) |
| Operating system and dependencies | Atlassian is responsible for the underlying service systems at the general shared-responsibility level; confirm product-specific boundaries in the applicable documentation. (Atlassian Cloud shared responsibility) | The customer applies operating-system updates, hardens systems, and maintains secure dependencies. (Data Center security checklist) |
| Data, users, and access | The customer manages account data, user accounts, and access decisions. (Atlassian Cloud shared responsibility) | The customer configures the product securely and manages access controls. (Data Center security checklist) |
| Marketplace apps | The customer decides which Marketplace apps to install and trust. (Atlassian Cloud shared responsibility) | The customer evaluates apps and dependencies as part of operating the self-managed environment. (Data Center security checklist) |
| Encryption and backups | Customers retain responsibility for their data and compliance decisions; confirm particular Cloud features and contractual controls in product-specific materials. (Atlassian Cloud shared responsibility) | The customer implements encryption according to policy and performs regular backups. (Data Center security checklist) |
| Business continuity | Atlassian manages Cloud infrastructure, product, and service reliability and recoverability; customers still plan for their own continuity needs. (Atlassian Cloud resilience overview) | The customer plans and operates recovery for the self-managed environment. (Data Center security checklist) |
How to choose between Cloud and Data Center for security operations
The choice is less about one model being inherently safer and more about which responsibilities your organization can reliably operate. Actual security depends on controls, configuration, customer practices, and the applicable product and environment.
Quick Recap
Best Value
Rank #4
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11"
- Reorder SKU: LOG-100-7CW-PP(Watch-Log)
- Patch operations: Cloud suits organizations that prefer Atlassian to operate the service. Data Center requires a team and process to install product fixes and operating-system updates.
- Infrastructure ownership: Decide whether your organization needs to operate its own infrastructure or prefers Atlassian to run the hosted environment.
- Identity and configuration: Both models require attention to users and access. Atlassian’s Data Center checklist specifically covers access controls, MFA/SSO options, encryption, and secure settings.
- Release lifecycle: A Data Center deployment needs an owner who tracks support status and upgrades within the support window.
- Compliance and continuity: Separate Atlassian’s platform responsibilities from your organization’s compliance program, recovery planning, and continuity requirements. Verify the exact obligations for your product, plan, contract, and regulatory context.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




