Security and privacy
Last updated 2026-09-30
- Runs on Atlassian. Built on Atlassian Forge and runs entirely inside Atlassian's infrastructure. No external network access is declared; nothing is sent to Mortise Apps or any third party.
- No data storage. The app stores nothing. Macro settings (scope, report, teams, layout) are saved by Confluence inside the page, like any other macro parameter.
- No backend. The app has no server-side functions. Jira is read from the page as the viewing user.
- Permissions respected. Every report is computed with the viewer's own Jira permissions, so nobody sees issues they could not already open in Jira.
- Scopes
| Scope | Used for |
|---|---|
read:jira-work | Read issues, fields, projects and issue link types for the reports. |
- Read-only. No write scopes. The app cannot change Jira issues, teams, Confluence pages or settings.
- Data residency. Follows the data residency of your Atlassian site; the app holds no data of its own.
- Vulnerability reports: email support@mortiseapps.com with "security" in the subject.
Was this page helpful? Email support@mortiseapps.com.