Security and privacy
Last updated 2026-09-30
- Runs on Atlassian. Built on Atlassian Forge; runs entirely inside Atlassian's infrastructure. No external network access is declared; nothing is sent to Mortise Apps or any third party.
- No data storage. The app stores nothing. Macro settings (link type, scope, Hide Done, height, title) are saved by Confluence inside the page, like any macro parameter.
- No backend. No server-side functions. Jira is read from the page as the viewing user.
- Permissions respected. The graph only contains issues the viewer can browse in Jira.
- Scopes
| Scope | Used for |
|---|---|
read:jira-work | Read issues, issue links, projects and link types for the graph. |
- Read-only. No write scopes. The app cannot change Jira issues, links, Confluence pages or settings.
- PNG export is generated in the browser; the image is never uploaded anywhere.
- Vulnerability reports: email support@mortiseapps.com with "security" in the subject.
Was this page helpful? Email support@mortiseapps.com.