Security Policy
Last updated 2026-10-05. Applies to every Mortise Apps product: TeamLens and LinkLens for Jira, TeamLens and LinkLens for Confluence, LinkLens Dependency Map for monday.com and AgentLens for Jira.
How the apps are built
The Atlassian apps are built on Atlassian Forge and run on Atlassian's infrastructure ("Runs on Atlassian"): we operate no servers of our own and the apps send no data outside Atlassian. The monday.com app runs on monday.com's app platform. The apps read data as the person using them, so the platform's own permissions always apply, and each app requests only the scopes it needs.
Data the apps store
The reporting and graph apps store only settings (and TeamLens a directory of team ids and names). AgentLens stores an audit log of AI agent calls, approval requests and monitor events in Forge storage on Atlassian's infrastructure, with retention chosen by the site admin (30 to 365 days) and values masked by its detectors before they are stored. Apps that store Atlassian account ids report them through Atlassian's Personal Data Reporting API and erase the data of closed accounts. Details for each app are in its security and privacy page under Docs; see also our Privacy Policy.
Access control
Our developer, source-control, hosting and email accounts are protected with multi-factor authentication and a password manager. Access to the Forge developer space is limited to the people who build the apps. API tokens, deploy keys and connected apps are reviewed every quarter, unused ones are removed, and tokens are rotated at least quarterly and immediately after any suspected exposure.
Secure development
Source code is kept in private repositories. Before every production release we run the Forge linter, the Forge Security Requirements Tester (FSRT) static analysis that Atlassian uses for Marketplace apps, and npm audit, and we test the release on a separate development site. Authorization checks are applied to every app function that users can call. Operating systems and browsers used for development stay on supported versions with automatic updates.
Vulnerability management
We fix security vulnerabilities within the timelines of the Atlassian Marketplace Security Bug Fix Policy (for Cloud apps, critical issues within 10 days and high within 4 weeks) and aim to fix critical issues within 48 hours.
Incident response
We follow a written incident response plan: triage within one business day, containment (credential rotation, session revocation, deployment review), fix and verify, then notification to Atlassian through its partner security channel and to affected customers. Each incident ends with a written review and a regression check. The plan is reviewed after every incident and at least once a year.
AI tools
We use AI coding assistants during development; no customer data is ever given to them. AgentLens itself calls no AI model: it only governs the AI agents that customers connect to it.
Reporting a vulnerability
Email support@mortiseapps.com with the subject "Security" and the details needed to reproduce the issue. We acknowledge reports within one business day and keep reporters informed until the issue is fixed. We do not run a paid bug bounty programme at present.