Data Storage and Security
WorkHub is built on Atlassian Forge — a serverless platform that runs entirely within Atlassian's infrastructure. This has important implications for your data security.
Where your data lives
All WorkHub data is stored using the Forge Storage API — a managed key-value store provided by Atlassian as part of the Forge platform.
| What is stored | Storage location | Who can access it |
|---|---|---|
| Sheet content (grids, notes, checklists, discussions) | Forge Storage (Atlassian-hosted) | Only your Jira instance |
| Sheet metadata (names, types, privacy settings) | Forge Storage (Atlassian-hosted) | Only your Jira instance |
| Jira Account IDs (for assignees and authors) | Forge Storage (Atlassian-hosted) | Only your Jira instance |
No external servers
WorkHub has zero external services. There is no WorkHub backend server, no third-party database, no analytics pipeline. Every computation runs inside Atlassian's Forge runtime.
This means:
- Your data is subject to Atlassian's security standards and certifications (SOC 2 Type II, ISO 27001)
- No data crosses to any external party
- WorkHub cannot access your data outside of the context of your Jira instance
Atlassian's security posture
Since WorkHub runs on Forge, it inherits Atlassian's security infrastructure:
- Encryption at rest: Forge Storage data is encrypted at rest
- Encryption in transit: All communication is over HTTPS/TLS
- Access controls: Data is scoped to your Atlassian cloud site — other sites cannot access it
- Audit logs: Forge logs all resolver invocations for your instance
For Atlassian's full security documentation, visit trust.atlassian.com.
Data residency
WorkHub uses Atlassian's standard Forge Storage, which supports Atlassian's data residency program. If your Atlassian organisation has data residency configured for a specific region, WorkHub data will be stored in that region.
What WorkHub does NOT collect
- No analytics or telemetry are sent to any external service
- No user behaviour tracking
- No content scanning or indexing outside your instance
- No marketing profiling