SOFTCOMPLY TRUST CENTER
This Trust Center provides information about our security practices, privacy controls, compliance programmes and infrastructure to help customers complete vendor due diligence with confidence.
🥈 ATLASSIAN SILVER PARTNER | ☁ CLOUD FORTIFIED | 🐞 BUG BOUNTY | 🔄 ISO 27001 IN PROGRESS
TRUST AT A GLANCE
🛡
Security
Security practices built for
regulated environments
- Infrastructure & Hosting
- Application Security
- Access Control & Identity
- Vulnerability Management
📄
Compliance
Summary of current certifications, programs, and regulatory support
- ISO 27001
- Atlassian Cloud Fortified
- Atlassian Security Bug Bounty Programme
🔒
Data Protection & Privacy
Overview of our (and our apps) data handling policy
- Data residency
- Data retention & deletion
- Data encryption
🚨
Incident Response
IRP overview, response process, notification SLAs, responsible disclosure and post-incident review
🔗
Subprocessors
Full list of our third-party subprocessors, their purpose, location and how they handle data
📩
Security Contact & Requests
🏢 About SoftComply
SoftComply is an Atlassian Silver Marketplace Partner specializing in compliant risk and document management software for the most demanding regulated environments: medical devices, digital health, GRC, cybersecurity and artificial intelligence. Our applications run inside Jira and Confluence — the platforms that tens of thousands of regulated-industry teams already rely on — and are purpose-built to help organizations meet the requirements of ISO 27001, ISO 14971, ISO 13485, FDA 21 CFR 820 and 21 CFR 11, EU MDR/IVDR, NIST and ISO 42001. We do not build generic project management tools – every feature we ship is designed for teams that are accountable to auditors, regulators and patients.
🛡 Security by Design
Our flagship applications carry Atlassian’s Cloud Fortified badge – the highest trust designation available on the Atlassian Marketplace – and are built on Forge, Atlassian’s secure, serverless app runtime. By building on Atlassian’s cloud infrastructure, our Forge-based applications inherit the security, resilience and operational maturity of one of the world’s leading enterprise collaboration platforms. Customer data remains within Atlassian’s infrastructure, reducing supplier attack surface, eliminating vendor-managed servers and simplifying security assessments for enterprise customers.
📋 Security & Compliance
We are currently pursuing ISO 27001 certification. Our Information Security Management System (ISMS) has been formally established with policies, risk assessments, internal audit processes and management reviews all in place. The controls we operate today already align with the ISO 27001:2022 Annex A requirements. We are actively working through the formal audit process with a target certification date in the first half of 2027.
🌐 Transparency
This Trust Center is how we share our security posture with you. Whether you are a security engineer conducting vendor due diligence, a procurement team completing a supplier assessment, or a Quality or Compliance officer evaluating SoftComply for your regulated environment, you will find the information you need here. We have chosen to publish this information openly rather than gating it behind an NDA or a questionnaire process because we believe transparency is foundational to trust.