Security
Platform
All our apps are built on Atlassian Forge and run inside Atlassian's infrastructure. We do not operate servers, databases, or third-party hosting. Atlassian's Trust Center describes the controls that infrastructure inherits.
Data egress
Our apps declare no external permissions in their Forge manifest, which means the platform itself prevents them from making network calls outside Atlassian. This is enforced by Forge, not just by policy.
Permissions
Each app requests the minimum OAuth scopes needed and documents every scope on its documentation page. None of our apps grant, modify, or remove permissions in your Jira or Confluence site.
Data storage
Where an app stores configuration, it uses Forge hosted storage, scoped to your site and stored in your site's data residency region. Storage is deleted by Atlassian when the app is uninstalled.
Vulnerability reporting
Report suspected vulnerabilities to [email protected]. We acknowledge reports within 2 business days and follow Atlassian's Security Bug Fix Policy for remediation timelines.
Marketplace programs
Participation in Atlassian's Cloud Fortified and Bug Bounty programs will be listed here as apps qualify.