1. Home
  2. Atlassian
  3. What Atlassian Isolated Cloud Means for Marketplace Vendors

What Atlassian Isolated Cloud Means for Marketplace Vendors

By Shin Nagasada, CEO of DevSamurai, Atlassian Marketplace Partner


We joined the Atlassian ecosystem seven years ago, which means we arrived after the interesting argument was already over. Atlassian had made its cloud-first intentions clear; we built accordingly, and we have spent our entire existence selling to cloud customers. We do not have a large Data Center business. We were never going to have one.

For most of those seven years, that felt like straightforward good sense. It also meant an entire category of customer was simply invisible to us.

You know the ones. Big bank, thirty thousand seats, a Data Center instance older than some of the people administering it, and a security policy containing a sentence roughly like: our data does not sit on infrastructure shared with anyone else. Those organisations weren’t slow-moving or badly run. They were structurally unreachable. No amount of product quality was going to move them, because the blocker wasn’t the product. It was the tenancy model underneath it, and we didn’t sell one of those.

Then on 29 June 2026, Atlassian Isolated Cloud went generally available, and the sentence stopped working.

Here’s the argument I want to make, and I’ll be upfront that I have an interest in it being true: Isolated Cloud isn’t a quiet compliance SKU parked at the edge of the roadmap. It’s the door through which the last and most app-hungry group of Data Center estates finally walks. And unusually, it’s a door where being an incumbent counts for much less than you’d expect.

The clock nobody in the ecosystem gets to ignore

The Data Center end-of-life timeline is public and no longer comfortably distant:

  • 30 March 2026. New customers could no longer buy Data Center products or Data Center Marketplace app licences. Already happened.
  • 30 March 2028. Existing customers lose the ability to buy Data Center licences, expansions, or app licences.
  • 28 March 2029. End of life. Subscriptions and their associated Marketplace apps expire, and environments go read-only.

That last bullet is doing enormous work. It isn’t only Jira that stops. The Marketplace apps stop too. Which means somewhere between now and 2029, a very large number of organisations have to rebuild their app estate on a new deployment model, deliberately, with a budget and a programme plan and a person whose name is on it.

What was missing until this summer was a destination for the genuinely hard accounts. Commercial Cloud is multi-tenant, which for a real slice of the enterprise base is a policy wall rather than a preference. Government Cloud handled U.S. federal agencies and their partners.

Therefore, Isolated Cloud is the answer for everyone else carrying a zero-sharing mandate: a dedicated single-customer environment with its own compute, storage, networking and databases inside a virtual private cloud, egress blocked by default, customer-managed encryption keys, Cloud Enterprise features and Guard Premium included.

It’s priced at a premium, and Atlassian has been candid about why: dedicated infrastructure per customer costs what it costs. But the objection that held these organisations still for a decade now has a documented answer. When the objection dies, the migration starts.

Why this cohort is worth caring about, even from the outside

Three reasons, and they stack.

They are the app-heaviest estates in the ecosystem, by some distance. Organisations stayed on Data Center precisely because they customised. A long-lived instance accumulates apps the way an old house accumulates wiring: workflow extensions, test management, asset and CMDB tooling, document control, reporting, audit trails nobody dares touch. A 30,000-seat regulated instance does not migrate with three apps. It migrates with thirty, each a named line item that somebody has to own.

They can’t build their way out. Their platform teams are already consumed by the migration itself. Nobody in a regulated bank is hand-rolling a compliant test management layer in the same twelve months they’re moving Jira. Many will need to buy rather than build, and they’ll buy from whoever has already done the security homework, because they are certainly not doing it on our behalf.

They buy slowly, and then they stay. The cycle is gruelling. Questionnaires, architecture review, data-flow diagrams, legal, then legal again. But an app that survives all that and ends up embedded in a regulated workflow does not get cancelled because someone was tidying up SaaS spend on a Tuesday afternoon.

The part that makes this interesting for a younger vendor

Normally, when a market this attractive opens up, the answer to “who wins it?” is “whoever already had the relationship.” Incumbency compounds. That’s usually the end of the story for a company our age.

Isolated Cloud is a strange exception, and the reason sits in Atlassian’s developer documentation rather than its launch announcement.

Isolated Cloud only runs apps built on Forge, Atlassian’s modern app platform, where the app runs inside Atlassian’s own infrastructure. Apps built on the older framework, which still accounts for a great deal of Marketplace revenue, are not eligible. Not “eligible with conditions.” Not eligible, until the vendor rebuilds them, a project many have been postponing for years. There are a handful of further hoops beyond that, all of them a nuisance and none of them a surprise.

The practical effect is that the qualification for this market isn’t a decade of Data Center relationships. It’s being built the modern way, keeping customer data inside Atlassian’s walls, and being willing to do a great deal of unglamorous security documentation. Those happen to be the three things a company that arrived in 2019, and never accumulated a legacy estate to unwind, is naturally good at.

I don’t want to overstate it. Relationships still matter enormously, and we’re starting further back than the incumbents on that front. But it is rare to get a moment where the entry requirement genuinely resets the field, and this is one.

The egress question, or: how to lose the room with one API call

One nuance that gets misreported constantly. There are no platform-enforced egress restrictions specific to Isolated Cloud apps. Whether to install an app that calls out is the customer’s decision, made against their own policy.

That sounds permissive. In practice it’s the opposite, because it shifts the decision from a technical gate you can engineer around to a procurement gate you have to earn. These customers chose this environment specifically because they believe their data stays inside the boundary. An app that quietly ships user-generated content to a vendor-run backend somewhere will be asked to explain itself in a room full of people whose entire professional purpose is saying no.

The design principle is therefore refreshingly simple: keep the data inside the walls. Store it and process it on Atlassian’s own infrastructure, under the Runs on Atlassian standard, and send nothing outside unless a specific customer has explicitly approved that specific flow.

And where an app can do less in this environment than it does elsewhere, because some outside integration can’t follow it in, say so plainly on the listing. This audience trusts a stated limitation far more than a claimed parity. Honestly, so do I.

What we’re doing about it

It would be easy to describe a market and stop there, so let me put our position on the table, including the parts that aren’t flattering.

1. We’re going all-in on Forge

It’s the entry requirement, and being a younger, cloud-native company means we’re carrying far less legacy than most. Anything in our portfolio not yet built that way is on a fixed retirement schedule rather than a hopeful one, sequenced by which apps matter most to a regulated enterprise.

2. We’re designing for the boundary rather than around it

Every place our software reaches outside Atlassian’s walls is being catalogued and made to justify itself. Where it exists for convenience, it goes. Where it earns its keep, it becomes a switch the customer controls, off by default.

And we’re maintaining one product across both environments rather than a stripped-down variant. As a result, an Isolated Cloud customer gets the same software on the same release schedule, minus only what genuinely can’t cross the line.

3. We’re investing in the security itself

This is the part where a younger company is most tempted to write a good document and hope nobody looks behind it, and we’d rather do the opposite. In other words, we take independent penetration testing on a regular cycle rather than once before a big deal.

We also take a bug bounty programme with real money attached, because the vulnerabilities we find ourselves are the cheap ones. Meanwhile, SOC2 Type II, reviewed as our footprint in security, grows rather than being framed and forgotten.

DevSamurai Achieves SOC 2 Type II Compliance - Atlassian Marketplace

It would mean asking for the narrowest permissions our software can function with, and periodically going back to see whether we still need the ones we have. And this leads to an incident response process we’ve actually rehearsed, on the assumption that we’ll need it one day.

The disclosures follow from that work rather than substituting for it. We don’t have twenty years of enterprise references to lean on, so the security posture has to be the argument, and we’d rather be judged on what we’ve built than on how long we’ve been around.

4. We’re working through the people who already have the relationships

We’re not going to pretend we have a decade of history inside these organisations. Solution Partners running these migration programmes do, and being genuinely easy to work with, meaning clear docs, fast answers and no surprises in a security review, is how a younger vendor gets into a shortlist it hasn’t earned by tenure.

5. And we’re staffing the long cycle deliberately

Questionnaires, architecture reviews and legal are the real gate in this segment, and they don’t fit around someone’s existing job. We’re treating it as a permanent function rather than a recurring fire drill.

We’re spending ahead of the revenue on purpose. We don’t have a Data Center book to protect, which means we have no reason to hedge and nothing to cannibalise. The entire opportunity is upside, and the window where being early actually counts is short.

The honest caveats

A post with no counterweight is just a brochure, so here’s what could make me wrong.

The absolute customer count will be small. This is built for the largest and most constrained enterprises, not the mid-market, and premium pricing will slow deals down. Some organisations will argue that a U.S.-headquartered provider can’t deliver true sovereignty no matter how isolated the tenancy. That argument isn’t frivolous, and it will win some accounts outright. Atlassian has also signalled willingness to extend Data Center maintenance by exception for certain customers, so the largest holdouts may move later than 2029 implies.

And the one that applies specifically to us: enterprises with this risk profile are not famous for taking chances on seven-year-old vendors. Being technically eligible is not the same as being trusted, and closing that gap is a slower, less controllable project than shipping code. We know we’re the ones who have to prove something here.

But the direction isn’t in doubt. The self-hosted option has an expiry date. The one deployment model that answers the objection that kept these customers self-hosted has now shipped. And what it takes to serve these customers, meaning modern architecture, data that stays where it’s put and documentation that survives scrutiny, happens to describe exactly the kind of company we set out to be seven years ago, back when that looked like a slightly boring choice.

Sometimes the door you were never going to get through just opens. You may as well walk in.

If you’re planning an Isolated Cloud migration and want to talk about the app layer, get in touch. We’d genuinely enjoy the conversation. Even the security questionnaire part.

Related content

Menu