Skip to the content.

Security Policy

DataForte AB · Tant Gröns väg 54, 147 60 Uttran, Sweden Security contact: hello@dataforteab.com (put “SECURITY” in the subject) Last updated: 24 August 2026

This is the security policy for Statusdesk for Jira (“the app”). It sits alongside the Privacy Policy, which describes what data the app handles; this page describes how that data is protected.

Architecture and hosting

The app is an Atlassian Forge app. It runs on Atlassian’s own infrastructure inside the customer’s cloud site — DataForte AB operates no servers, no database and no network endpoints of its own for this product.

The app makes no external calls. Its manifest declares no egress permissions, which Atlassian enforces at the platform level: a request to any third-party host would be blocked by Forge, not merely discouraged by us. This is what qualifies the app for Atlassian’s Runs on Atlassian programme.

Data protection

Access control

Secure development

Vulnerability reporting

Report a suspected vulnerability to hello@dataforteab.com with “SECURITY” in the subject. Please include the affected app, a description, and steps to reproduce.

We do not run a paid bug bounty, and we will not take legal action against researchers who report in good faith, avoid privacy violations and give us reasonable time to fix an issue.

Incident response

DataForte AB maintains a written incident response plan. In summary:

  1. Detect and triage — an alert, a customer report or a researcher report opens an incident; severity is assigned within one business day.
  2. Contain — the affected app version is rolled back or disabled through the Forge developer console. Because the app holds no data outside Atlassian, containment does not depend on us securing external infrastructure.
  3. Notify — affected customers are contacted at the email on their Marketplace subscription. Where a personal data breach is involved, notification follows GDPR Article 33: the relevant supervisory authority within 72 hours of becoming aware.
  4. Remediate and review — a fix is deployed, root cause is written up, and the resulting change is added to the test suite so the same fault cannot return silently.

Business continuity

The app’s availability is Atlassian’s platform availability; there is no separate DataForte AB service that can fail. Source code and deployment history are retained so any released version can be rebuilt and redeployed.

Compliance posture