Last updated: June 20, 2026

Security Practices

Project Overview & Status Hub for Jira is designed as an Atlassian Forge app for Jira Cloud, with permission-aware access and human review of generated project context.

Architecture

The app uses Forge Custom UI, Forge resolvers, Forge app storage, Forge permissions and Atlassian-hosted Forge LLM capabilities. The app does not require Forge Remote and does not store project overview content in a vendor-managed database outside Atlassian Forge.

Authentication and authorization

Least privilege scopes

External egress

The app manifest allows backend fetch egress to Google Analytics for product analytics. The manifest marks this egress as analytics and not in scope for Atlassian End User Data. Product analytics payloads are sanitized and restricted to an allowlist of event names and simple parameters.

AI processing

AI-assisted text is generated through Atlassian-hosted Forge LLM capabilities. The app does not call a vendor-hosted AI provider. AI output is shown as a suggestion or summary and should be reviewed by users.

Logging

Logs should avoid personally identifiable information, credentials, Jira issue text, saved overview text and sensitive customer content. Analytics debug logging, if enabled for troubleshooting, logs compact sanitized analytics payload information only.

Vulnerability reporting

Security issues can be reported to Mederak Apps Service Desk. Please include reproduction steps, impact, affected tenant context and screenshots where appropriate. Do not include secrets, credentials or unnecessary customer data.

Incident response

Security incidents are handled according to the Security Incident Response page.