Rovo security, privacy, and data use
How does Rovo address my security and compliance requirements?
Rovo is thoughtfully designed to ensure your data is protected and your compliance needs are met, so you can stay in control.
Large language models (LLMs)
Atlassian uses a diverse range of open models, including models from the Gemma series, GPT-oss series, Llama series and Nemotron series, alongside third-party hosted LLMs from OpenAI's GPT series of models, Anthropic's Claude series of models, and Google's Gemini series of models, to deliver the best outcomes for customers. Our AI features use dynamic routing to select the appropriate mix of models that can deliver the best experience and accuracy for each scenario.
The third-party LLM providers Atlassian uses do not retain your inputs and outputs, or use them to improve their services.
Please refer to our list of data sub-processors for more information on our third-party hosted LLM providers. You can also learn more about how each feature uses LLMs on our transparency page.
Security and regulatory compliance
Rovo is designed responsibly to address your organization’s evolving security and compliance requirements.
Rovo has completed the external assessment and compliance certifications for ISO42001, ISO27001, and SOC 2.
Rovo can be used in a HIPAA-compliant manner. See our HIPAA Implementation Guide for more information.
As we do today for all of our apps, we process and transmit data for Rovo in accordance with our Privacy Policy, Data Processing Addendum, and GDPR commitment.
How to get started with data residency
Rovo supports data residency by allowing customers to pin their data to specific geographical regions, ensuring compliance with local data protection laws. You can currently pin your Rovo data to the same region as your Jira or Confluence data.
How to access the audit log
Rovo activities are now tracked in the audit log. Admins can see Rovo admin and user actions, including but not limited to the following:
Chat started
Agent created, updated, or deleted
Bookmark created, updated, or deleted
Definition created
Third-party connector created, updated, or deleted
To access the audit log:
Go to Atlassian Administration.
Select your organization if you have more than one.
Select Insights > Audit log.
Filter by App > Rovo.
Note
Rovo admin actions are accessible to Guard Standard and Premium customers. Rovo user actions are available to Guard Premium customers.
How to sync your org chart with Rovo
Integrating your org chart with Rovo improves collaboration and personalized recommendations by enabling teams to get more relevant, and precise answers by connecting projects, people, and goals. Syncing your org chart enables teams to:
See a user’s manager and direct reports on their profiles.
Filter projects and goals by reporting lines.