Compliance

Table of Contents

SoftComply develops risk, compliance and document-management applications for organisations operating in regulated and safety-critical environments. Our security and compliance programme is designed to support the protection, reliability and responsible handling of information across our products and business operations.

SoftComply applications can help customers implement and maintain their own governance, risk and compliance processes within Jira and Confluence. However, using a SoftComply application does not, by itself, make an organisation compliant with a particular law, regulation or standard. Customers remain responsible for configuring and validating their systems appropriately and for determining which regulatory requirements apply to their organisation.

This page distinguishes between SoftComply’s own compliance status, the independent assurance applicable to the underlying Atlassian platform, and the frameworks that SoftComply products can help customers manage.

SoftComply Compliance Programme

SoftComply maintains an information security management programme developed with reference to ISO/IEC 27001:2022. The programme includes policies, assigned responsibilities and operational processes covering areas such as:

  • Information security risk management

  • Access control and identity management

  • Secure software development

  • Vulnerability management

  • Data protection and privacy

  • Supplier and service-provider management

  • Security awareness and personnel responsibilities

  • Internal review and continual improvement

SoftComply is currently preparing for ISO/IEC 27001 certification, with the first-stage certification audit planned for 2027. Until the certification process has been successfully completed, SoftComply does not claim to be ISO 27001 certified.

SoftComply does not currently hold an independent SOC 2 report. Atlassian’s ISO and SOC certifications apply to Atlassian’s audited cloud services and infrastructure and should not be interpreted as certifications independently held by SoftComply.


Atlassian Cloud Assurance

Most SoftComply Cloud applications, including Risk Manager Plus Cloud, are built on Atlassian Forge. Atlassian operates the underlying cloud infrastructure, Forge runtime, physical facilities, network controls and platform-level security and availability measures.

Atlassian maintains an independently audited compliance programme covering applicable cloud products and services. Depending on the service and scope, Atlassian’s assurance documentation includes certifications and reports such as:

  • ISO/IEC 27001

  • ISO/IEC 27018

  • SOC 1 Type II

  • SOC 2 Type II

  • Cloud Security Alliance assessments and related assurance information

  • Other regional or service-specific certifications described in the Atlassian Trust Center

The precise scope of each certification or assurance report should be confirmed against Atlassian’s current documentation. A certification held by Atlassian applies only to the Atlassian products, services and controls included within its audited scope.

Under the shared-responsibility model, Atlassian is responsible for the security and compliance of its underlying cloud and Forge platform. SoftComply remains responsible for its application code, requested permissions, application configuration, development practices and the controls operated within SoftComply. Customers remain responsible for their users, content, configurations, permissions and use of the applications.

Further information:


Atlassian Marketplace Security Programmes

SoftComply participates in applicable Atlassian Marketplace security and reliability programmes. Participation and status may vary by application and hosting model and should be verified through the current Atlassian Marketplace listing for the relevant product.

Cloud Fortified

All SoftComply apps hold Atlassian Cloud Fortified status. Cloud Fortified is an Atlassian Marketplace programme for eligible Cloud applications that meet defined security, reliability and support requirements.

Cloud Fortified status is not an independent security certification and does not mean that SoftComply itself is ISO 27001 or SOC 2 certified. It provides additional assurance that the application satisfies the applicable Atlassian programme requirements while the status remains active.

Marketplace Security Bug Bounty Program

SoftComply participates in the Atlassian Marketplace Security Bug Bounty Program. The programme enables independent security researchers to report potential vulnerabilities through an established vulnerability-disclosure process.

Reported findings are assessed and addressed in accordance with their severity, the applicable Atlassian Marketplace security requirements and SoftComply’s vulnerability-management procedures. Participation in a bug bounty programme complements secure development and internal security review.

Marketplace security requirements

SoftComply Cloud applications are subject to applicable Atlassian Marketplace security requirements. These may include vulnerability-management expectations, security scanning and remediation requirements appropriate to the application’s programme participation.

Customers should consult the applicable Marketplace listing for the most current product-specific badges and programme information.

Further information:


Data Protection and GDPR

SoftComply is established in Estonia (member state of the European Union) and processes personal data in accordance with the EU General Data Protection Regulation and other applicable data-protection requirements.

SoftComply’s role under data-protection law depends on the processing activity. SoftComply generally acts as a controller for personal data used to manage its own customer relationships, licensing, support, procurement, marketing and business administration.

SoftComply uses appropriate contractual and legal safeguards where personal data is transferred outside the European Economic Area.

Product architecture and data handling vary between Forge-based Cloud applications, SoftComply Document Manager and Data Center applications. Customers should review the Data Protection & Privacy page and the applicable product’s Marketplace Privacy & Security information for product-specific details.

Further information:


Regulatory and Standards Support

SoftComply applications provide configurable capabilities that can help customers establish, operate and document processes associated with a range of regulatory frameworks and management-system standards. Depending on the product and customer configuration, these capabilities may include:

  • Risk identification, assessment, control and monitoring

  • Traceability between risks, controls, requirements, assets and evidence

  • Controlled document workflows

  • Review and approval processes

  • Electronic records and signatures

  • Version and lifecycle management

  • Audit trails and change history

  • Dashboards and compliance reporting

SoftComply products may be used to support customer processes relating to frameworks such as:

  • ISO 14971 and medical-device risk management

  • ISO 13485 quality management

  • ISO/IEC 27001 information security management

  • ISO 31000 risk management

  • ISO/IEC 42001 AI management systems

  • NIST Cybersecurity Framework and NIST AI Risk Management Framework

  • SOC 2 control and evidence management

  • EU AI Act governance and risk-management activities

  • 21 CFR Part 11 electronic-record and electronic-signature requirements

  • Other industry-specific quality, safety, security and risk-management frameworks

References to these frameworks describe the processes and use cases that the products are designed to support. They do not represent certification, regulatory approval or a guarantee that a customer’s implementation will comply with every applicable requirement.

The suitability of a particular configuration depends on the customer’s intended use, procedures, technical environment and regulatory obligations. Customers should perform their own assessment and obtain qualified legal, regulatory or quality advice where appropriate.


21 CFR Part 11 and Validated Use

Certain SoftComply products provide functionality intended to support controlled-document and electronic-approval processes in regulated environments. Depending on the product and configuration, this may include electronic signatures, approval records, version control, timestamps, user attribution and audit history.

Compliance with 21 CFR Part 11 depends on the complete system and its intended use—not on an individual application feature alone. Relevant considerations include the customer’s Atlassian configuration, identity-management controls, permissions, operating procedures, training, validation activities and record-retention arrangements.

SoftComply can provide available product documentation and validation-support materials to assist customers with their assessment. Customers remain responsible for validating their configured system and determining whether it satisfies their applicable regulatory requirements.


Data Center Deployments

SoftComply Data Center applications operate within an Atlassian environment hosted and administered by the customer. Compliance responsibilities for the underlying infrastructure—including physical security, network controls, operating systems, databases, backups, disaster recovery, identity management and data residency—remain with the customer or its hosting provider.

SoftComply is responsible for the application code it supplies and for maintaining product documentation and addressing identified application vulnerabilities in accordance with applicable support and maintenance arrangements.

Atlassian Cloud or Forge certifications do not apply to a customer-operated Data Center environment. Customers should assess their own infrastructure and Atlassian deployment against the compliance requirements applicable to them.


Customer Responsibilities

Compliance is a shared responsibility. Customers are responsible for determining the legal, regulatory and contractual requirements applicable to their use of SoftComply products. Depending on the deployment and intended use, customer responsibilities may include:

  • Selecting and configuring the appropriate Atlassian and SoftComply products

  • Managing users, permissions, authentication and access reviews

  • Defining approval authorities and workflow responsibilities

  • Maintaining policies, procedures and training records

  • Determining appropriate retention and deletion periods

  • Reviewing application permissions and integrations

  • Validating regulated configurations where required

  • Maintaining appropriate backups for customer-operated environments

  • Monitoring changes that could affect a validated or regulated system

  • Confirming that the overall implementation meets applicable requirements

SoftComply provides application functionality and supporting information, but does not assume responsibility for the customer’s wider compliance programme or the regulatory suitability of a specific customer configuration.


Compliance Documentation

SoftComply supports customer security, compliance and procurement assessments by providing available documentation appropriate to the product and request. Depending on availability and confidentiality requirements, this may include:

  • Completed security and compliance questionnaires

  • Product architecture and data-flow information

  • Security and privacy policy summaries

  • Data Processing Agreements

  • Business continuity and incident-response information

  • Data-retention information

  • Evidence of applicable Atlassian Marketplace programme participation

  • References to Atlassian certifications and assurance reports

  • Product documentation and available validation-support materials

Certain documents may contain confidential or security-sensitive information and may be provided only under an appropriate non-disclosure agreement. Atlassian audit reports and certificates may also be subject to Atlassian’s access conditions.

Enterprise procurement and risk teams may contact info@softcomply.com to discuss their documentation requirements. Security questionnaires and technical security inquiries may be submitted to security@softcomply.com.


Compliance Status

Compliance claims and programme participation may change as products, standards and assurance programmes evolve. SoftComply reviews this page periodically and updates material status information where appropriate.

Last updated: July 2026