Last updated: June 20, 2026

Security Incident Response

Suspected security issues should be reported to Mederak Apps Service Desk. Include "Security report" in the request summary when possible.

What to include

Internal handling process

  1. Acknowledge the report.
  2. Open an internal security ticket and assign an owner.
  3. Triage severity based on exploitability, data impact, customer impact and availability impact.
  4. Contain the issue if active exploitation or data exposure is suspected.
  5. Develop and test a fix or mitigation.
  6. Release the fix through the Atlassian Marketplace and Forge deployment process.
  7. Notify affected customers and Atlassian when required.
  8. Complete a post-incident review for material incidents.

Customer notification

If a confirmed security incident affects customer data, we will notify affected customers without undue delay and provide information that is reasonably available, including the nature of the incident, affected data categories, mitigation steps and customer actions where needed.