Security, Trust & Atlassian Programs: Dependency Manager for Jira Cloud
Key Takeaways
Dependency Manager for Jira Cloud participates in Atlassian's Runs on Atlassian program as an auto-verified Forge app, so its compute and storage run entirely on Atlassian Forge with no Divim-operated server.
The app sends no customer data to Divim and uses no third-party subprocessors, so there is no analytics SDK, external error reporter, or vendor-side copy of your dependency data.
Because Dependency Manager runs on Atlassian Forge, it inherits Atlassian's SOC 2 and ISO 27001 posture, TLS in transit, encryption at rest, and tenant isolation, with authentication managed by Atlassian and no vendor-held credentials.
Persisted dependency data follows the data-residency region of your host Jira Cloud site, so residency commitments are honored automatically.
Divim acknowledges reported vulnerabilities for Dependency Manager within 5 business days, and the trust posture is reviewed at least annually.
Map and resolve cross-release dependencies, with nothing leaving Atlassian. Dependency Manager gives you drag-and-drop dependency management across releases. Every link, graph, and change is processed and stored inside your own Atlassian tenant: no Divim-operated server, no third-party hosting, and no customer data transmitted outside Atlassian's cloud.
▶ Try it free on the Atlassian Marketplace · Read the Divim Trust Center →
What "Runs on Atlassian" means for your buyers
No data egress. No analytics SDK, no external error reporter, no vendor-side copy of your dependency data.
Atlassian-hosted, end to end. Compute and storage run on Atlassian Forge, inheriting Atlassian's SOC 2, ISO 27001 and tenant-isolation posture.
Your data residency, honored. Persisted data follows the data-residency region of your host Jira Cloud site.
Procurement-ready from day one. A brand-new app, but built on the same Forge-native, zero-egress foundation as the rest of the Divim suite.
Trust at a glance
Attribute | Dependency Manager for Jira Cloud |
|---|---|
Atlassian program | Runs on Atlassian (auto-verified Forge app) |
Platform | Atlassian Forge, fully serverless |
Customer data sent to Divim | None |
Third-party subprocessors | None (Atlassian is the sole infrastructure provider) |
Data residency | Follows your Jira Cloud site |
Encryption | TLS in transit · encrypted at rest (Atlassian-managed) |
Authentication | Managed by Atlassian, no vendor-held credentials |
Vulnerability response | Acknowledged within 5 business days |
Why enterprise teams choose it with confidence
Cross-team dependencies are where releases quietly slip, and where security teams worry about yet another integration phoning home. Dependency Manager does neither. You get the visibility to catch a blocker before it slips a release, on an architecture where nothing leaves Atlassian.
Documentation & resources
Security Policy: security architecture and controls
Privacy Policy: data handling, residency, and retention
User Guide: mapping dependencies and reading the critical path
Divim Trust Center: company-wide security, privacy & compliance
Trust-program participation verified on the Atlassian Marketplace. Reviewed at least annually. Security questions: support@divim.io.