Policy
1. Data Security
All data managed through Secure Vault for Jira is securely handled within the Atlassian ecosystem.
No data is stored, transmitted, or processed outside of Jira or Atlassian infrastructure.
The app does not send data to any external servers.
The app does not collect or process personally identifiable information (PII) unless explicitly entered by the user.
All data remains within the boundaries of Atlassian’s secure cloud environment.
Data handling strictly follows Atlassian’s security, privacy, and hosting standards.
2. Application Scope & Secret Handling
Secure Vault for Jira enables controlled access to sensitive or restricted information within Jira issues and dashboards.
To maintain security and integrity:
Secret data is stored as part of Jira issue panel or dashboard gadget configuration.
The app does not encrypt or transform data externally; it relies on Atlassian platform security.
Content is displayed only to authorized users, groups, project roles, or field-based access configurations defined in the setup.
The app does not execute scripts, HTML, or embedded code.
All content is treated strictly as static data and rendered safely.
Any malformed or unsupported configuration may result in display limitations.
3. Authentication & Permissions
The app operates strictly within Atlassian’s authentication and permission framework.
All actions are performed as the currently logged-in Jira user.
The app respects Jira’s native permission model at all times.
It does not access or expose data beyond what the user is authorized to view.
No privilege escalation or background access occurs.
4. Access Control
Access to secret data is governed by both Jira permissions and app-level configuration.
Only users explicitly selected (or part of selected groups or project roles) can view the protected content.
Field-based access can dynamically control visibility using Jira user fields.
Unauthorized users will not be able to see protected data.
Only users with edit permissions can configure or modify access settings.
View-only users cannot change configurations.
Group-, role-, and field-based access is validated dynamically based on Jira data.
5. Security Best Practices
To ensure secure usage of the app:
Share sensitive data only with trusted users, groups, or project roles.
Avoid storing highly confidential information unless necessary and authorized.
Regularly review and update user/group/role access configurations.
Remove access for users who no longer require it.
Follow your organization’s internal data security policies when using this app.
6. License & Usage Enforcement
The app includes license validation to ensure authorized usage.
Features may be restricted if the license is inactive or invalid.
The app may prevent access to configuration or data when license validation fails.
License checks follow Atlassian Marketplace standards.
7. Vulnerability Reporting
We support responsible disclosure of security issues.
If you discover a potential vulnerability, please report it to: