Atlassian Government Cloud - Data Egress?

I am looking into the requirements to make an app compatible with Atlassian Government Cloud.

The compatibility page says: “The Runs on Atlassian (RoA) signal guarantees that an app’s data is hosted exclusively on secure Atlassian cloud infrastructure.” But it then says “This signal also indicates that customers retain control over an app’s data egress.”

If the data is hosted exclusively on Atlassian’s infrastructure, how can there be data egress?

My real question is whether a marketplace app on AGC can still egress data? For example, could it store some metadata on other infrastructure.

ref: Why AGC

Hey @craig.schwarze

Thanks for your question. A Runs on Atlassian app must use Atlassian-hosted compute and storage and must not egress data, except for analytics egress where no in-scope End-User Data is included. In other words, an app cannot send customer or other in-scope app data to external infrastructure and still qualify for the Runs on Atlassian signal.

The reference to “This signal also indicates that customers retain control over an app’s data egress” relates to the administrative controls available for permitted external connections, such as analytics and logs e.g. an administrator can turn these off. It should not be interpreted as meaning that a Runs on Atlassian app can freely send app data to an external service.

From a customer perspective, the preferred options are generally:

  1. Runs on Atlassian, where the app keeps in-scope data within Atlassian-hosted infrastructure
  2. Other external egress, where the customer is comfortable with the data flow, destination and associated security controls

AGC customers may be able to use Forge apps that egress data, but most will prefer Runs on Atlassian apps, but it is ultimately up to the customer’s security posture and risk profile.

Technical compatibility does not necessarily mean the architecture will be acceptable to every AGC customer. App developers should clearly document what data is egressed, for what purpose, and where it is stored.

Thank you Phillip, that seems clear.

Let me confirm. If my app happens to egress data, I can still publish it on AGC, it’s just that some potential customers will not find that acceptable, and will hence not use it.

Yes, that is correct.

I would be very surprised if a customer that chose to be in AGC also chose an app that egressed data (to, I’m going to assume) a non-Fedramp location. I’d love to hear if there have been occasions when this has happened.