Policy

Policy

1. Data Security

All data managed through Secure Vault for Jira is securely handled within the Atlassian ecosystem.

  • No data is stored, transmitted, or processed outside of Jira or Atlassian infrastructure.

  • The app does not send data to any external servers.

  • The app does not collect or process personally identifiable information (PII) unless explicitly entered by the user.

  • All data remains within the boundaries of Atlassian’s secure cloud environment.

  • Data handling strictly follows Atlassian’s security, privacy, and hosting standards.

2. Application Scope & Secret Handling

Secure Vault for Jira enables controlled access to sensitive or restricted information within Jira issues and dashboards.

To maintain security and integrity:

  • Secret data is stored as part of Jira issue panel or dashboard gadget configuration.

  • The app does not encrypt or transform data externally; it relies on Atlassian platform security.

  • Content is displayed only to authorized users, groups, project roles, or field-based access configurations defined in the setup.

  • The app does not execute scripts, HTML, or embedded code.

  • All content is treated strictly as static data and rendered safely.

  • Any malformed or unsupported configuration may result in display limitations.

3. Authentication & Permissions

The app operates strictly within Atlassian’s authentication and permission framework.

  • All actions are performed as the currently logged-in Jira user.

  • The app respects Jira’s native permission model at all times.

  • It does not access or expose data beyond what the user is authorized to view.

  • No privilege escalation or background access occurs.

4. Access Control

Access to secret data is governed by both Jira permissions and app-level configuration.

  • Only users explicitly selected (or part of selected groups or project roles) can view the protected content.

  • Field-based access can dynamically control visibility using Jira user fields.

  • Unauthorized users will not be able to see protected data.

  • Only users with edit permissions can configure or modify access settings.

  • View-only users cannot change configurations.

  • Group-, role-, and field-based access is validated dynamically based on Jira data.

5. Security Best Practices

To ensure secure usage of the app:

  • Share sensitive data only with trusted users, groups, or project roles.

  • Avoid storing highly confidential information unless necessary and authorized.

  • Regularly review and update user/group/role access configurations.

  • Remove access for users who no longer require it.

  • Follow your organization’s internal data security policies when using this app.

6. License & Usage Enforcement

The app includes license validation to ensure authorized usage.

  • Features may be restricted if the license is inactive or invalid.

  • The app may prevent access to configuration or data when license validation fails.

  • License checks follow Atlassian Marketplace standards.

7. Vulnerability Reporting

We support responsible disclosure of security issues.

If you discover a potential vulnerability, please report it to:

📧 developer@alvanium.com