Skip to main content

Atlassian Marketplace App Selection Criteria for Enterprise

· 7 min read
Quick Answer

Enterprise teams evaluating Atlassian Marketplace apps should check ten criteria: Cloud Fortified status, Forge vs Connect framework, OAuth scopes, privacy disclosure, Bug Bounty participation, data residency, vendor viability, support SLA, adoption signals, and release cadence. This guide walks through each so your security and procurement teams can make confident decisions.

What you'll learn
  1. The 10 criteria every enterprise should check before approving an app
  2. How to assess vendor viability and long-term risk
  3. What documentation to request from vendors during procurement
  4. A scoring rubric you can apply to any app in under 10 minutes

Installing a Marketplace app in an enterprise Atlassian environment is not the same as installing a browser extension. The app gains access to your Jira issues, Confluence pages, and potentially your entire collaboration surface — so the evaluation process needs to be rigorous. This guide covers the ten criteria that security, procurement, and IT teams should check before approving any app for enterprise deployment.

Why enterprise app selection matters

In a small team, installing a risky app is a recoverable mistake — you uninstall it and move on. In an enterprise, the stakes are higher:

  • Data exposure — an app with broad scopes can read sensitive issues, compliance data, and customer information.
  • Compliance liability — apps that store data off-platform or share it with subprocessors can violate GDPR, HIPAA, or SOC 2 commitments.
  • Operational risk — an unmaintained app can break during Atlassian platform updates, disrupting workflows for thousands of users.
  • Audit trail — enterprises need to justify every app installation to auditors and security reviewers.

A structured evaluation process turns "is this app okay?" from a gut-feeling decision into a repeatable, defensible assessment.

The 10 enterprise evaluation criteria

1. Cloud Fortified status

Cloud Fortified is Atlassian's trust tier. Apps that earn it have completed the Privacy and Security disclosure tab, participate in the Bug Bounty Program, and meet reliability and support requirements. As of 2026, new Cloud Fortified designations require Forge. If an app has this badge, a substantial part of your security review is already done.

2. Forge vs Connect

The framework determines where the app runs and who controls your data. Forge apps run on Atlassian infrastructure with platform-enforced permissions — your data never leaves the Atlassian tenant. Connect apps run on vendor-hosted servers, where the vendor is responsible for encryption, patching, and breach response. For enterprise deployment, prefer Forge. For a deeper treatment, see our Forge vs Connect guide.

3. OAuth scopes and permissions

Review the scopes the app requests at install time. The principle is least privilege: the app should request only the scopes it needs for its function. A diagraming app requesting only read:confluence-content and write:confluence-content is well-scoped. The same app requesting admin-level scopes or user management access is a red flag. Reject apps whose scopes exceed their stated purpose.

4. Privacy and data handling disclosure

The Privacy and Security tab on the Marketplace listing is where the vendor declares what data the app collects, where it is stored, how long it is retained, and whether it is shared with third parties. Check:

  • Storage location — Atlassian (Forge) vs vendor infrastructure (Connect) vs third-party subprocessor
  • Data retention — does the vendor delete data on uninstall?
  • Third-party sharing — analytics, AI, or advertising subprocessors must be named

5. Bug Bounty participation

Apps in the Marketplace Security Bug Bounty Program (hosted on Bugcrowd) are externally tested by security researchers. The vendor pays rewards for valid vulnerability findings. This is an active, ongoing security practice — not a one-time certification. Look for the green checkmark on the listing.

6. Data residency

For regulated industries and government customers, data residency is non-negotiable. Confirm where the app stores and processes data:

  • Forge apps store data on Atlassian infrastructure in the region your tenant is provisioned in
  • Connect apps may store data anywhere the vendor operates — check the privacy disclosure
  • Apps that transmit data to third countries may require additional Data Processing Agreements

7. Vendor viability

An app is only as reliable as the company behind it. Assess:

  • Company size and funding — a vendor with 2 employees and no funding is a higher risk than an established company
  • Years in business — how long has the vendor been on the Marketplace?
  • Response to reviews — does the vendor actively respond to support tickets and negative reviews?
  • Release cadence — check the versions tab; a healthy app ships updates regularly
  • Multiple apps — vendors with several successful apps demonstrate sustained commitment

8. Support SLA

Enterprise teams need guaranteed response times. Check:

  • Does the vendor publish an SLA?
  • What is the response time for paid vs free tiers?
  • Is there a dedicated enterprise support channel?
  • How does the vendor handle severity-1 incidents?

9. Adoption signals

Real-world adoption is a strong indicator of reliability:

  • Install count — thousands of installs means the app has been stress-tested
  • Star rating — look at the distribution, not just the average; read negative reviews for failure modes
  • Enterprise customers — does the vendor reference enterprise or government customers?
  • Active user base — is the app growing or declining?

10. Release cadence and maintenance

Check the versions tab on the Marketplace listing:

  • Recent updates — has the app been updated in the last 6 months?
  • Atlassian platform compatibility — does it support the latest Cloud version?
  • Changelog quality — does the vendor document what changed in each release?
  • Bug fix responsiveness — are reported issues addressed in subsequent releases?

An app that has not been updated in over a year is a maintenance risk — it may break on the next Atlassian platform update with no fix coming.

A scoring rubric

Apply this simple scoring to any app:

CriterionPass (2)Partial (1)Fail (0)
Cloud FortifiedYesOn trackNo
FrameworkForgeConnect, scopedConnect, broad scopes
ScopesMinimal, justifiedModerateExcessive
Privacy disclosureCompletePartialMissing
Bug BountyYesNo
Data residencyMatches requirementsDoes not match
Vendor viabilityEstablished, activeSmall but responsiveUnknown, inactive
Support SLAPublished, enterpriseEmail onlyNone
Adoption1,000+ installs, 4+ stars100+ installsUnder 100 installs
Release cadenceUpdated under 3 months agoUnder 12 monthsOver 12 months

Score 16-20: Low risk — approve with standard review. Score 10-15: Moderate risk — require vendor questionnaire. Score under 10: High risk — require executive sign-off or reject.

Documentation to request from vendors

For moderate-to-high risk apps, send this questionnaire:

  1. Where is our data stored, and who controls the infrastructure?
  2. What subprocessors do you use, and for what purpose?
  3. What is your incident response SLA?
  4. Do you retain data after uninstall, and for how long?
  5. Can you justify each OAuth scope the app requests?
  6. Are you Cloud Fortified, and if not, what is your timeline?
  7. Do you have SOC 2, ISO 27001, or equivalent certifications?
  8. How do you handle data residency for our region?

Explore enterprise-ready apps

All NGPILOT apps are built exclusively on Forge, store data on Atlassian infrastructure, and request only the scopes they need. Browse the full catalog or explore solutions by scenario to find apps that meet enterprise requirements. Our Trust Center has the full security, privacy, and compliance details.

Frequently Asked Questions

How long should an enterprise app evaluation take?

With the scoring rubric above, a preliminary assessment takes under 10 minutes. A full vendor review with questionnaire responses typically takes 1-2 weeks, depending on vendor responsiveness. High-risk apps may require an additional security architecture review.

Can we automate app evaluation?

Partially. Atlassian's Marketplace API exposes app metadata (install counts, ratings, Cloud Fortified status, scopes) that can be pulled programmatically. The qualitative criteria (privacy disclosure quality, vendor viability) still require human review. Some enterprises build internal app catalogs that pre-screen apps before they reach the evaluation stage.

What if we need an app that fails several criteria?

Document the risk explicitly and require a compensating control: a data processing agreement, a stricter scope review, or a trial period in a sandbox environment. Sometimes the best option is to ask the vendor to address the gaps (e.g., pursue Cloud Fortified) before approval.


NGPILOT apps are built exclusively on Forge. Browse the app catalog, explore solutions, or read our Trust Center for enterprise security details.