1. Scope
This policy applies to Dashboard Announcements for Jira, a Jira dashboard gadget delivered on Atlassian Forge. It also covers this public product and security website.
2. Architecture and hosting
The app is hosted on Atlassian Forge and uses Forge app storage.
- There is no vendor-operated application backend.
- The app does not use Forge Remote, external data egress, or web triggers.
- The app's declared permission scope is limited to
storage:app. - This website is static and does not include forms, analytics, or behavioral tracking.
3. Data handling
The app stores the content and operational metadata needed to show the current announcement for a gadget. This may include the notice title and body, update time, updater account identifier, and gadget association or stored version information.
Dashboard Announcements for Jira does not collect Atlassian account passwords, API tokens, or third-party service credentials.
App data remains within the Atlassian Forge environment used by the app. The vendor does not receive the announcement content through a separate backend.
4. Security controls
- Inputs are normalized before storage and display.
- Supported formatting and link protocols are controlled.
- Rendered output is escaped to reduce injection risk.
- Access is governed by the Jira and Atlassian Forge context in which the gadget runs.
- Changes are reviewed and the app is tested and built before release.
5. Dependency management
Third-party dependencies are reviewed as part of release maintenance. Known vulnerabilities are assessed, relevant packages are updated, and automated tests and production builds are run before a release is prepared.
6. Security incidents and vulnerabilities
Report suspected vulnerabilities or security incidents to the email address below. Please include the affected app area, steps to reproduce, potential impact, and any supporting evidence that can be shared safely.
Reports are reviewed to validate the issue, assess impact, contain or remediate the problem, and communicate relevant updates. Response and remediation are prioritized according to severity and user impact.
7. Security contact
Use the following address for security reports, privacy questions, or product support.