Docs🔒 Privacy and SecurityData Storage and Security

Data Storage and Security

WorkHub is built on Atlassian Forge — a serverless platform that runs entirely within Atlassian's infrastructure. This has important implications for your data security.

Where your data lives

All WorkHub data is stored using the Forge Storage API — a managed key-value store provided by Atlassian as part of the Forge platform.

What is storedStorage locationWho can access it
Sheet content (grids, notes, checklists, discussions)Forge Storage (Atlassian-hosted)Only your Jira instance
Sheet metadata (names, types, privacy settings)Forge Storage (Atlassian-hosted)Only your Jira instance
Jira Account IDs (for assignees and authors)Forge Storage (Atlassian-hosted)Only your Jira instance

No external servers

WorkHub has zero external services. There is no WorkHub backend server, no third-party database, no analytics pipeline. Every computation runs inside Atlassian's Forge runtime.

This means:

  • Your data is subject to Atlassian's security standards and certifications (SOC 2 Type II, ISO 27001)
  • No data crosses to any external party
  • WorkHub cannot access your data outside of the context of your Jira instance

Atlassian's security posture

Since WorkHub runs on Forge, it inherits Atlassian's security infrastructure:

  • Encryption at rest: Forge Storage data is encrypted at rest
  • Encryption in transit: All communication is over HTTPS/TLS
  • Access controls: Data is scoped to your Atlassian cloud site — other sites cannot access it
  • Audit logs: Forge logs all resolver invocations for your instance

For Atlassian's full security documentation, visit trust.atlassian.com.

Data residency

WorkHub uses Atlassian's standard Forge Storage, which supports Atlassian's data residency program. If your Atlassian organisation has data residency configured for a specific region, WorkHub data will be stored in that region.

What WorkHub does NOT collect

  • No analytics or telemetry are sent to any external service
  • No user behaviour tracking
  • No content scanning or indexing outside your instance
  • No marketing profiling