Security Policy

Gherkin for Jira

This app runs entirely inside Atlassian. It has no outbound network access, no server of ours, and no database of ours. There is no infrastructure on our side for an attacker to reach, because there is none at all — everything the app stores lives in Atlassian's own storage, inside your site's region.

That shapes everything below. The realistic risk here is not a breached server; it is the app showing someone data they should not see, or storing more than it needs.

Reporting a vulnerability

Write to support@avakode.com with “security” in the subject. Please include what you found, how to reproduce it, and what an attacker could do with it. Send it to us before publishing, and give us a chance to fix it.

We do not run a paid bug bounty and we do not hold a security certification such as SOC 2 or ISO 27001. Saying otherwise would be easy and untrue.

If something goes wrong

An incident here means one of two things: the app exposed data to someone who should not have seen it, or the app lost data it was holding.

Access control

Data protection

Monitoring

How the app is built

Questions

If your security team needs something this page does not answer, write to support@avakode.com. We would rather answer a questionnaire than lose you to silence.