Security Incident Response
Report a suspected vulnerability or security incident through Mederak Apps Service Desk and put Security report in the summary.
Safe reporting
In the initial ticket, provide a safe description, affected App version/site, potential impact, reproduction outline and contact details. Do not include credentials, access tokens, private customer content or exploit material that could expose another user. We will arrange a safer channel for sensitive evidence if needed.
Coordinated disclosure
- Test only systems and tenants you own or have written permission to assess.
- Do not access, change, retain or disclose another person's data.
- Avoid service disruption, automated high-volume testing, social engineering and privacy-control circumvention.
- Give Mederak Apps reasonable time to investigate and remediate before public disclosure.
- Comply with Atlassian's applicable testing and Marketplace rules.
Handling process
- Acknowledge and protect evidence: record a safe case identifier, reporter contact and available technical context.
- Triage: assess exploitability, scope, confidentiality, integrity, availability, tenant isolation and customer impact.
- Contain: disable or constrain a feature, configuration or version where necessary to reduce active risk.
- Investigate: reproduce safely, identify affected revisions/tenants/data categories and determine the root cause.
- Remediate: develop, review and test a fix or mitigation and follow the required Forge/Marketplace release process.
- Notify: inform Atlassian, regulators and affected customers where required by contract, Marketplace policy or law.
- Review: document lessons, control improvements and follow-up verification for a material incident.
Severity and remediation
Severity considers realistic exploitability and impact to customer data, authorization, tenant isolation and service availability. Confirmed vulnerabilities are prioritized according to applicable Atlassian Marketplace security requirements and security bug-fix timelines. A report may be reclassified as evidence develops.
Customer notification
If a confirmed incident affects customer data or materially affects security, Mederak Apps will notify affected customers without undue delay and as required by applicable law or contract. Notice will include the nature of the incident, affected data or features, mitigation, customer actions and contact details to the extent reasonably known and safe to disclose.
Atlassian platform incidents
Because the App runs on Atlassian Forge, some incidents may originate in Jira, JSM, Forge, Marketplace or Atlassian-managed services. Mederak Apps will coordinate with Atlassian where appropriate and communicate the confirmed App-specific impact. Atlassian platform restoration remains under Atlassian's control.
No bug bounty promise
Mederak Apps does not currently advertise a public paid bug bounty or claim enrollment in Atlassian's Marketplace Security Bug Bounty program for this App. Any recognition or reward requires a separate written agreement.