Marketplace trust center

Security Practices

Excel to Jira Importer & Updater is designed as an Atlassian Forge app for Jira Cloud, with data minimization and user-controlled import flow at the center of the product.

Architecture

The app uses Forge Custom UI for the browser experience and Forge resolvers for Jira REST API operations. Excel parsing is designed to happen client-side where practical. Structured import data is then sent to Forge backend resolvers for validation and Jira issue creation within Atlassian-hosted infrastructure.

Atlassian Forge security posture

Atlassian describes Forge as a serverless app development platform where compute and storage can be hosted on Atlassian infrastructure. Atlassian also states that Forge apps run with tenancy isolation and manifest-controlled external egress. The app is designed to use this Forge model and not send workbook data to a separate vendor backend.

Vendor access to workbook data

The app creator does not receive customer workbook files, imported rows or Jira task content on an external product server. Operational access is limited to what Atlassian Forge and Jira make available according to installed app scopes, logs and customer support interactions.

Access control

Jira administrators can grant the app permission to selected groups. Users must still have Jira permissions required to browse projects, create issues, edit issues and set parent-child relationships where those actions are part of the import.

Data storage

Value cleanup safety

Value cleanup supports bounded regex extraction for mapped fields. The app is designed to block invalid regex patterns, overly long patterns, overly long inputs, invalid result templates and simple nested-quantifier patterns that are commonly risky for import performance.

Logging

The app should avoid logging sensitive workbook content. Technical logs should focus on operational status and error diagnosis.

When product analytics is configured, the app may record sanitized product events for workflow usage, reliability monitoring and quality improvement. These events may include workflow actions, step names, result labels, status labels and aggregate counts such as rows, columns, created issues, updated issues and errors. Analytics and diagnostic data should not include workbook cell values, column names, Jira issue text, issue keys, project names, user display names, email addresses, customer links, support messages or API tokens.

Vulnerability reporting

Security issues can be reported to Mederak Apps Service Desk. Please include reproduction steps, impact, affected tenant context and screenshots where appropriate.

Atlassian Marketplace alignment

The app is prepared with Marketplace security expectations in mind, including least-privilege thinking, privacy documentation, customer terms, support contact and transparency about data handling.