jira-analyzer-projects

Security — Config Analyzer & Migration Helper for Jira Cloud

Last updated: 24 August 2026

This page describes the security practices of the app. See also the privacy policy and the documentation.

Architecture

The app is built entirely on Atlassian Forge. It has no servers, no databases and no infrastructure of its own. All compute and storage are hosted and operated by Atlassian.

The app is part of the Runs on Atlassian program: it uses only Atlassian-hosted compute and storage, supports the data residency of the host product, and performs no data egress. Its manifest declares no external permissions, so it is technically unable to send data to any external host.

Data handling

Read-only access. The app requests read scopes only. It holds no write or administrative scopes and is therefore unable to modify Jira configuration.

No data at rest. Configuration read from Jira is processed for the duration of a single request, only to produce the document the user asked for, and is then discarded. The app operates no store of its own. The only value persisted locally in the user’s browser is the chosen interface language.

Data Center exports. Workflow XML files are selected by the user and parsed locally in the browser. They are never uploaded to any server and are discarded when the page is closed. The app never connects to a Data Center instance.

Generated documents. Word, Excel and CSV files are produced in the user’s browser and downloaded to their device. They are not transmitted to the developer or to any third party.

Encryption

All communication with Atlassian APIs uses TLS, enforced by the Forge platform. Data at rest is not applicable, as the app stores no data.

Authentication and authorisation

The app authenticates through the Forge platform using the permissions granted by the site administrator at installation time. It never asks users for credentials, API tokens, personal access tokens or any other shared secret, and never handles them.

Access is bound by the scopes declared in the manifest, all of which are read-only. The app cannot access products, projects or data outside what those scopes allow.

Vulnerability management

Dependencies are limited to a small set of well-known open-source libraries used for document generation and XML parsing. They are reviewed and updated when security advisories affect them.

The app runs on the Forge platform, which is maintained and patched by Atlassian, including the underlying runtime and infrastructure.

Reporting a vulnerability

If you believe you have found a security issue in this app, please report it to the security contact listed on the app’s Marketplace listing. Reports are acknowledged and investigated; please allow reasonable time for a fix before public disclosure.

Certifications

The app holds no independent compliance certifications (such as ISO 27001 or SOC 2). It inherits the security posture of the Atlassian Forge platform, on which it runs exclusively.

Third parties

The app shares no data with any third party. It contains no analytics, no tracking and no advertising.


Config Analyzer & Migration Helper for Jira Cloud is an independent app and is not created by, affiliated with, or endorsed by Atlassian.