Security, Trust & Atlassian Programs: Dependency Manager for Jira Cloud

Security, Trust & Atlassian Programs: Dependency Manager for Jira Cloud

Key Takeaways

  • Dependency Manager for Jira Cloud participates in Atlassian's Runs on Atlassian program as an auto-verified Forge app, so its compute and storage run entirely on Atlassian Forge with no Divim-operated server.

  • The app sends no customer data to Divim and uses no third-party subprocessors, so there is no analytics SDK, external error reporter, or vendor-side copy of your dependency data.

  • Because Dependency Manager runs on Atlassian Forge, it inherits Atlassian's SOC 2 and ISO 27001 posture, TLS in transit, encryption at rest, and tenant isolation, with authentication managed by Atlassian and no vendor-held credentials.

  • Persisted dependency data follows the data-residency region of your host Jira Cloud site, so residency commitments are honored automatically.

  • Divim acknowledges reported vulnerabilities for Dependency Manager within 5 business days, and the trust posture is reviewed at least annually.

Map and resolve cross-release dependencies, with nothing leaving Atlassian. Dependency Manager gives you drag-and-drop dependency management across releases. Every link, graph, and change is processed and stored inside your own Atlassian tenant: no Divim-operated server, no third-party hosting, and no customer data transmitted outside Atlassian's cloud.

▶ Try it free on the Atlassian Marketplace · Read the Divim Trust Center →


What "Runs on Atlassian" means for your buyers

  • No data egress. No analytics SDK, no external error reporter, no vendor-side copy of your dependency data.

  • Atlassian-hosted, end to end. Compute and storage run on Atlassian Forge, inheriting Atlassian's SOC 2, ISO 27001 and tenant-isolation posture.

  • Your data residency, honored. Persisted data follows the data-residency region of your host Jira Cloud site.

  • Procurement-ready from day one. A brand-new app, but built on the same Forge-native, zero-egress foundation as the rest of the Divim suite.

Trust at a glance

Attribute

Dependency Manager for Jira Cloud

Attribute

Dependency Manager for Jira Cloud

Atlassian program

Runs on Atlassian (auto-verified Forge app)

Platform

Atlassian Forge, fully serverless

Customer data sent to Divim

None

Third-party subprocessors

None (Atlassian is the sole infrastructure provider)

Data residency

Follows your Jira Cloud site

Encryption

TLS in transit · encrypted at rest (Atlassian-managed)

Authentication

Managed by Atlassian, no vendor-held credentials

Vulnerability response

Acknowledged within 5 business days

Why enterprise teams choose it with confidence

Cross-team dependencies are where releases quietly slip, and where security teams worry about yet another integration phoning home. Dependency Manager does neither. You get the visibility to catch a blocker before it slips a release, on an architecture where nothing leaves Atlassian.

Documentation & resources

Trust-program participation verified on the Atlassian Marketplace. Reviewed at least annually. Security questions: support@divim.io.