Would be super interested in a technical writeup on how they do this.
Would be super interested in a technical writeup on how they do this.
In previous companies I have worked for, we did instant soft-delete, then hard anonymisation after 15-30days and then hard delete after a year. That means the data was not recoverable for customer but could still be recovered for legal purpose.
A simple technical solution is to store all data with per user encryption keys, and then just delete the key. This obviously doesn't let you prove to anyone else that you've deleted all copies of the key, but you can use it as a way to have higher confidence you don't inadvertently leak it.
Of course, this means trusting Atlassian to actually delete the key on request, but there's not much reason for them not to.