Report a security problem
Found a security problem? Tell us privately at security@boundedsignal.com.
Do not email passwords, access tokens, customer Jira content, personal information, or instructions that could be used to attack the app. Ask us for a safe transfer method if sensitive evidence is needed.
What to include
- The app version and affected area.
- What could go wrong and how serious it may be.
- Short steps using your own test site or made-up data.
- Whether anyone may already be affected.
Response targets
- Acknowledge a report that appears to describe a real security problem within 24 calendar hours.
- Assess the report within three business days.
- Send an update at least every five business days while a confirmed report is open.
These are response targets, not a guaranteed service level, legal protection for testing, reward program, or promise of payment.
How the app is limited
The current app runs on Atlassian's managed app platform, called Forge. It has two permissions that allow reading but not changing Jira data, asks Jira for information as the signed-in user, stores no Jira content, and sends no Jira data to an external service. We will check these facts again for the exact release version.