← Back to Jira Bulk Edit

Security Policy

Jira Bulk Edit · Effective Date: July 24, 2026 · Developer: Appcento (David Day)

Overview

This Security Policy describes the secure design and operational practices for Jira Bulk Edit, a Jira Cloud bulk-editing app built on the Atlassian Forge platform.

Hosting & Infrastructure

Jira Bulk Edit is built on the Atlassian Forge platform and runs entirely within Atlassian's infrastructure. There are no external servers, databases, or third-party backends hosted by Appcento. All compute resources are provided by Atlassian as part of the Forge runtime.

Data Access & Permissions

The App uses Atlassian's OAuth mechanism to access Jira data. Only the minimum required API scopes are requested:

Scope Purpose
read:jira-work Read issue metadata and field values for selection display and bulk update preview
write:jira-work Write field values to issues during bulk update operations

These are the minimum scopes required for the App to function. No additional permissions are requested.

Data Storage & Processing

All data processing occurs within your Jira Cloud instance via Atlassian Forge:

  • No external storage: The App does not store any issue data, field values, or user information on external servers.
  • In-memory processing: All data is processed in memory during the session and is not persisted after the operation completes.
  • No caching: The App does not cache issue data, scan results, or update history between sessions.

Network Security

The App makes no network calls to external third-party services.

  • All API communication is with Jira's REST API through Forge's secure runtime and OAuth mechanism.
  • Data in transit is encrypted via TLS as enforced by Atlassian's infrastructure.
  • There is no egress from Atlassian's Forge runtime to external endpoints outside Atlassian unless explicitly added and approved in the app manifest.

Vulnerability Management

Appcento follows these vulnerability management practices:

  • Dependency updates: Dependencies are reviewed and updated regularly to address known vulnerabilities.
  • Automated scanning: Code is scanned for security issues as part of the development workflow.
  • Atlassian platform security: The App relies on Atlassian's platform security for underlying infrastructure, runtime patching, and vulnerability management.

Incident Response

In the event of a security incident or vulnerability discovery:

  • Appcento will coordinate with affected customers and Atlassian as required.
  • Notifications will be sent to impacted contacts via the support email channel.
  • Patches and mitigations will be applied as quickly as possible through the Forge deployment pipeline.
  • For security issues, contact: support@appcento.com

Compliance

Jira Bulk Edit complies with the following standards and frameworks:

  • Atlassian Marketplace compliance: The App has passed Atlassian's security review and listing requirements.
  • GDPR: As the App processes no personal data outside of Jira Cloud and makes no external data transfers, it is designed to support GDPR compliance for installed instances.
  • Atlassian Trust Center: The App inherits Atlassian's platform-level security controls and certifications. Refer to:

Third-Party Services

The App does not use third-party analytics, monitoring, or telemetry services. No customer data is sent to external vendors.

Changes to This Policy

We may update this Security Policy from time to time. Any changes will be reflected by updating the "Effective Date" at the top of this document.

Contact

For security questions or to report a vulnerability, contact:

Email: support@appcento.com
Website: https://appcento.com