Security & Trust Center

Security information you can verify.

This page describes the currently verified Handoff Pulse architecture. No invented certifications and no blanket privacy claims.

Current verified state

Forge app, Forge KVS, Jira read scopes, Forge licensing and no external data egress declared in the current manifest.

Security overview

Handoff Pulse uses Atlassian Forge for execution, authentication and app storage. Security remains a shared responsibility between Atlassian, the app vendor and the customer.

Forge architecture

The current release is a Jira global page with a Forge function and stores structured app data through @forge/kvs.

Data handling

Stored data includes handover content, Jira issue keys, ownership and workflow metadata. Jira summary, status, priority and other issue context are read for display; Jira remains the source of truth.

Permissions

The verified release requests only these scopes:

storage:appread:jira-workread:jira-user

No Jira issue write scope is requested for the core workflow.

Privacy

The current release declares no external egress and no vendor-operated remote backend. This statement applies only to the verified release and is reviewed when the architecture changes.

Atlassian Marketplace security

Marketplace installation, licence provisioning and Atlassian platform controls are governed by Atlassian’s current terms and documentation. No Atlassian endorsement is claimed.

Responsible disclosure

Report vulnerabilities confidentially.

Include the affected product and version, impact, safe reproduction steps and available evidence. Do not access other users’ data, alter data or disrupt availability.

We ask security researchers to

  • act in good faith and within applicable law
  • perform only the minimum testing needed
  • avoid downloading or sharing data
  • allow reasonable time for investigation and remediation

Subprocessors

Document platform dependencies.

The current disclosure separates vendor subprocessors from Atlassian’s platform role and avoids invented providers.

View the list

Contact

Security is an ongoing process.

Product or security questions: security@vireltix.com

No SOC 2, ISO 27001 or GDPR certification is claimed.