Security Policy

Team Workload Visualizer for Jira · Last updated: 28 June 2026

Overview

Team Workload Visualizer for Jira ("the app") is built entirely on Atlassian Forge and runs exclusively inside Atlassian's cloud infrastructure. It has no external servers and declares zero external egress, so a large part of the app's security posture is inherited from, and enforced by, the Atlassian Forge platform. This policy describes how Clearwork Apps handles security issues, manages vulnerabilities, and what controls are in place.

Reporting a security issue

If you discover a security vulnerability or suspect a security incident, please email security@clearworkapps.de. Where possible, include:

We ask reporters to practise responsible disclosure: please give us a reasonable opportunity to investigate and remediate before any public disclosure. We will not pursue legal action against good-faith security research conducted in line with this policy.

Handling security issues and incidents

On receiving a report, we follow a defined process:

  1. Acknowledge — we confirm receipt of the report within 2 business days.
  2. Triage & assess — we reproduce the issue and assess its severity and impact (using CVSS-style reasoning) within 5 business days.
  3. Remediate — we develop, test and deploy a fix via the Forge platform. Target timelines by severity: critical/high within 7 days, medium within 30 days, low at the next scheduled release.
  4. Notify — where an incident affects customer environments, we notify affected customers and, where the platform is involved, coordinate with Atlassian. Platform-level incidents are handled under Atlassian's own incident management process.

Vulnerability management

Key security controls

Access control. The app has no accounts or passwords of its own. All authentication and authorisation is handled by Atlassian. The app operates on the user's behalf and respects existing Jira permissions — users only ever see projects and issues they are already allowed to see. It requests least-privilege, read-only scopes (read:jira-work, read:jira-user) plus storage:app for its own settings, and cannot modify Jira data. Team-wide settings are restricted to Jira administrators.

Data protection. The app stores no issue data, names or emails — only its own configuration in Forge Storage, within your Atlassian product's data boundary. Data is encrypted in transit and at rest by the Atlassian platform. The app declares zero external egress in its Forge manifest, which Atlassian enforces technically: the app cannot transmit data to any non-Atlassian system. See the Privacy Policy for full detail.

Monitoring & logging. The app runs in Atlassian's managed Forge runtime, which provides runtime logging and audit capabilities. We review Forge application logs when investigating issues, and Atlassian monitors the underlying platform on a 24/7 basis.

Secure development. Source code is kept in version control, changes are reviewed before release, and deployments go through Forge's staged environments. The minimal dependency footprint reduces supply-chain risk.

Platform security. Because the app runs on Atlassian Forge, it inherits Atlassian Cloud's certified security controls (including SOC 2 and ISO 27001) and runs inside Forge's hardened, isolated runtime. Details are available at the Atlassian Trust Center.

Contact

For security issues: security@clearworkapps.de
For general support: support@clearworkapps.de
Clearwork Apps

Changes to this policy

This page is updated when our security practices change. The current version is always available at this URL.