Before launching your app on the Atlassian Marketplace, you’ll need to prepare your business for customer expectations and questions around trust. The checklist below gives you some helpful initial pre-launch steps, for example how to:
This will make it easier for you to show customers that you’re serious about protecting their data. While you may not be ready to go for your SOC 2 or ISO 27001 audit today, these steps will set your company up for success if you want to pursue certifications later.
To attract customers in cloud, you need to give your customers confidence in your app’s security, privacy, and compliance.
This is especially important if you’d like to support larger customers (enterprise), or customers from regulated regions or industries.
Reduce risks and fix weaknesses by building your app with "secure by design" principles. These include:
Our serverless app development platform, Forge, helps you build “secure by design” apps from the start.
Understand how your app and business handles data. Ensure you can answer the following questions:
Which subprocessors do you use?
Which employees have access to what data?
Where, geographically, does your data reside?
Under GDPR and most other privacy laws, customers have a right to:
Make sure you have a process in place to handle these requests. For guidance, check out:
Build a strong privacy policy that reflects how your business and app actually handles data. You can view Atlassian’s privacy policy as an example.
To prepare for potential customer or auditor requests, document any security controls you have in place to prevent, detect, or correct threats to data. These include:
These records will also make any future audits much easier (for example, SOC 2 or ISO 27001).
If this is your first Marketplace app, navigating the legal obligations can feel daunting.
To prepare for privacy questions, have an email address or contact information available on your Atlassian Marketplace listing, website, or privacy policy.
To prevent answering many of the same questions again, communicate as much privacy information as possible via the Privacy & Security tab, your trust center, or other documentation.
Rate this page: