Bulk Participants for JSM

Security

This page describes the security practices used by Bulk Participants for JSM.

Hosting and architecture

Bulk Participants for JSM runs entirely on Atlassian Forge. The app uses Forge-hosted runtime and persistent storage and does not use an external application backend, external database, remote service, advertising platform, or third-party analytics service.

Authentication and authorization

The app uses the identity and permissions of the signed-in Atlassian user. Jira Service Management operations are performed only within the permissions available to that user.

The app does not require customers to provide Atlassian Personal Access Tokens, passwords, shared secrets, or customer-managed API credentials.

Least-privilege access

Bulk Participants for JSM uses only the Atlassian scopes required for its Request Participant, storage, licensing, and privacy functions. It does not use app-level Jira mutation access or external remotes.

Data handling

The app may store limited operational data including:

The app does not intentionally store:

Retention and deletion

Preflight data used for Preview and Apply has a maximum usable lifetime of 15 minutes and is removed when consumed, expired, or cleaned up.

Operation history is retained for up to 30 days. Privacy-related account references are removed when no longer needed, and uninstall cleanup removes retained app storage.

Privacy lifecycle

The app uses Atlassian's Personal Data Reporting API and internal erasure mechanisms to support applicable account update and deletion requirements.

Logging

The app does not intentionally log Jira request content or personal data. Diagnostic information is limited to what is necessary to operate and troubleshoot the app.

Vulnerability management

Application dependencies and production builds are reviewed using automated dependency and build checks. Known production dependency vulnerabilities are addressed before release where practical.

The app does not currently claim independent security certifications such as SOC 2, ISO 27001, HIPAA, or PCI DSS.

Security incidents

Confirmed security issues involving app-controlled data are investigated and affected customers are notified when required by applicable law or contractual obligation.

Report a security issue

Security concerns may be reported to support@getreadycheck.com.