Security
This page describes the security practices used by Bulk Participants for JSM.
Hosting and architecture
Bulk Participants for JSM runs entirely on Atlassian Forge. The app uses Forge-hosted runtime and persistent storage and does not use an external application backend, external database, remote service, advertising platform, or third-party analytics service.
Authentication and authorization
The app uses the identity and permissions of the signed-in Atlassian user. Jira Service Management operations are performed only within the permissions available to that user.
The app does not require customers to provide Atlassian Personal Access Tokens, passwords, shared secrets, or customer-managed API credentials.
Least-privilege access
Bulk Participants for JSM uses only the Atlassian scopes required for its Request Participant, storage, licensing, and privacy functions. It does not use app-level Jira mutation access or external remotes.
Data handling
The app may store limited operational data including:
- Atlassian account IDs
- Jira issue keys
- Operation type
- Timestamps
- Limited operation and result metadata
The app does not intentionally store:
- Email addresses
- Display names in Forge storage
- Jira request descriptions
- Comments
- Attachments
- Passwords
- API tokens
- Raw Jira API payloads
Retention and deletion
Preflight data used for Preview and Apply has a maximum usable lifetime of 15 minutes and is removed when consumed, expired, or cleaned up.
Operation history is retained for up to 30 days. Privacy-related account references are removed when no longer needed, and uninstall cleanup removes retained app storage.
Privacy lifecycle
The app uses Atlassian's Personal Data Reporting API and internal erasure mechanisms to support applicable account update and deletion requirements.
Logging
The app does not intentionally log Jira request content or personal data. Diagnostic information is limited to what is necessary to operate and troubleshoot the app.
Vulnerability management
Application dependencies and production builds are reviewed using automated dependency and build checks. Known production dependency vulnerabilities are addressed before release where practical.
The app does not currently claim independent security certifications such as SOC 2, ISO 27001, HIPAA, or PCI DSS.
Security incidents
Confirmed security issues involving app-controlled data are investigated and affected customers are notified when required by applicable law or contractual obligation.
Report a security issue
Security concerns may be reported to support@getreadycheck.com.